<?xml version="1.0"?>
<cve xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
     xmlns="http://cve.mitre.org/cve/downloads"
     xsi:noNamespaceSchemaLocation="http://cve.mitre.org/schema/cve/cve_1.0.xsd">
<item type="CVE" name="CVE-1999-0002" seq="1999-0002">
<status>Entry</status>
<desc>Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I">19981006-01-I</ref>
<ref source="CERT">CA-98.12.mountd</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-006.shtml">J-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/121">121</ref>
<ref source="XF">linux-mountd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0003" seq="1999-0003">
<status>Entry</status>
<desc>Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</desc>
<refs>
<ref source="NAI">NAI-29</ref>
<ref source="CERT">CA-98.11.tooltalk</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A">19981101-01-A</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX">19981101-01-PX</ref>
<ref source="XF">aix-ttdbserver</ref>
<ref source="XF">tooltalk</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/122">122</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0005" seq="1999-0005">
<status>Entry</status>
<desc>Arbitrary command execution via IMAP buffer overflow in authenticate command.</desc>
<refs>
<ref source="CERT">CA-98.09.imapd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177">00177</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/130">130</ref>
<ref source="XF">imap-authenticate-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0006" seq="1999-0006">
<status>Entry</status>
<desc>Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.</desc>
<refs>
<ref source="CERT">CA-98.08.qpopper_vul</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I">19980801-01-I</ref>
<ref source="AUSCERT">AA-98.01</ref>
<ref source="XF">qpopper-pass-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/133">133</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0007" seq="1999-0007">
<status>Entry</status>
<desc>Information from SSL-encrypted sessions via PKCS #1.</desc>
<refs>
<ref source="CERT">CA-98.07.PKCS</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx">MS98-002</ref>
<ref source="XF">nt-ssl-fix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0008" seq="1999-0008">
<status>Entry</status>
<desc>Buffer overflow in NIS+, in Sun's rpc.nisd program.</desc>
<refs>
<ref source="CERT">CA-98.06.nisd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170">00170</ref>
<ref source="ISS">June10,1998</ref>
<ref source="XF">nisd-bo-check</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0009" seq="1999-0009">
<status>Entry</status>
<desc>Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="XF">bind-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/134">134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0010" seq="1999-0010">
<status>Entry</status>
<desc>Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="XF">bind-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0011" seq="1999-0011">
<status>Entry</status>
<desc>Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="XF">bind-axfr-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0012" seq="1999-0012">
<status>Entry</status>
<desc>Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</desc>
<refs>
<ref source="CERT">CA-98.04.Win32.WebServers</ref>
<ref source="XF">nt-web8.3</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0013" seq="1999-0013">
<status>Entry</status>
<desc>Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</desc>
<refs>
<ref source="CERT">CA-98.03.ssh-agent</ref>
<ref source="NAI">NAI-24</ref>
<ref source="XF">ssh-agent</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0014" seq="1999-0014">
<status>Entry</status>
<desc>Unauthorized privileged access or denial of service via dtappgather program in CDE.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075">HPSBUX9801-075</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185">00185</ref>
<ref source="CERT">CA-98.02.CDE</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0016" seq="1999-0016">
<status>Entry</status>
<desc>Land IP denial of service.</desc>
<refs>
<ref source="CERT">CA-97.28.Teardrop_Land</ref>
<ref source="FREEBSD">FreeBSD-SA-98:01</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076">HPSBUX9801-076</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/land-pub.shtml</ref>
<ref source="XF">cisco-land</ref>
<ref source="XF">land</ref>
<ref source="XF">95-verv-tcp</ref>
<ref source="XF">land-patch</ref>
<ref source="XF">ver-tcpip-sys</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0017" seq="1999-0017">
<status>Entry</status>
<desc>FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</desc>
<refs>
<ref source="CERT">CA-97.27.FTP_bounce</ref>
<ref source="XF">ftp-bounce</ref>
<ref source="XF">ftp-privileged-port</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0018" seq="1999-0018">
<status>Entry</status>
<desc>Buffer overflow in statd allows root privileges.</desc>
<refs>
<ref source="CERT">CA-97.26.statd</ref>
<ref source="AUSCERT">AA-97.29</ref>
<ref source="XF">statd</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/127">127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0019" seq="1999-0019">
<status>Entry</status>
<desc>Delete or create a file via rpc.statd, due to invalid information.</desc>
<refs>
<ref source="CERT">CA-96.09.rpc.statd</ref>
<ref source="XF">rpc-stat</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0021" seq="1999-0021">
<status>Entry</status>
<desc>Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</desc>
<refs>
<ref source="BUGTRAQ">19971010 Security flaw in Count.cgi (wwwcount)</ref>
<ref source="CERT">CA-97.24.Count_cgi</ref>
<ref source="XF">http-cgi-count</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/128">128</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0022" seq="1999-0022">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via expstr() function.</desc>
<refs>
<ref source="CERT">CA-97.23.rdist</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</ref>
<ref source="XF">rdist-bo3</ref>
<ref source="XF">rdist-sept97</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0023" seq="1999-0023">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via lookup() function.</desc>
<refs>
<ref source="CERT">CA-96.14.rdist_vul</ref>
<ref source="XF">rdist-bo</ref>
<ref source="XF">rdist-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0024" seq="1999-0024">
<status>Entry</status>
<desc>DNS cache poisoning via BIND, by predictable query IDs.</desc>
<refs>
<ref source="CERT">CA-97.22.bind</ref>
<ref source="XF">bind</ref>
<ref source="NAI">NAI-11</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0025" seq="1999-0025">
<status>Entry</status>
<desc>root privileges via buffer overflow in df command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CA-1997-21</ref>
<ref source="AUSCERT">AA-97.19.IRIX.df.buffer.overflow.vul</ref>
<ref source="SGI">SGI:19970505-01-A</ref>
<ref source="SGI">SGI:19970505-02-PX</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/20851">VU#20851</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/346">346</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/440">df-bo(440)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0026" seq="1999-0026">
<status>Entry</status>
<desc>root privileges via buffer overflow in pset command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.20.IRIX.pset.buffer.overflow.vul</ref>
<ref source="XF">pset-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0027" seq="1999-0027">
<status>Entry</status>
<desc>root privileges via buffer overflow in eject command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.21.IRIX.eject.buffer.overflow.vul</ref>
<ref source="XF">eject-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0028" seq="1999-0028">
<status>Entry</status>
<desc>root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.22.IRIX.login.scheme.buffer.overflow.vul</ref>
<ref source="XF">sgi-schemebo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0029" seq="1999-0029">
<status>Entry</status>
<desc>root privileges via buffer overflow in ordist command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.23-IRIX.ordist.buffer.overflow.vul</ref>
<ref source="XF">ordist-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0031" seq="1999-0031">
<status>Entry</status>
<desc>JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.</desc>
<refs>
<ref source="CERT">CA-97.20.javascript</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html">HPSBUX9707-065</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0032" seq="1999-0032">
<status>Entry</status>
<desc>Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</desc>
<refs>
<ref source="BUGTRAQ">19960813 Possible bufferoverflow condition in lpr, xterm and xload</ref>
<ref source="BUGTRAQ">19961025 Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[freebsd-security] 19961025 Vadim Kolontsov: BoS: Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[linux-security] 19961122 LSF Update#14: Vulnerability of the lpr program.</ref>
<ref source="CERT">CA-97.19.bsdlp</ref>
<ref source="AUSCERT">AA-96.12</ref>
<ref source="CIAC">H-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/707">707</ref>
<ref source="XF">bsd-lprbo2</ref>
<ref source="XF">bsd-lprbo</ref>
<ref source="XF">lpr-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0034" seq="1999-0034">
<status>Entry</status>
<desc>Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</desc>
<refs>
<ref source="CERT">CA-97.17.sperl</ref>
<ref source="XF">perl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0035" seq="1999-0035">
<status>Entry</status>
<desc>Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</desc>
<refs>
<ref source="XF">ftp-ftpd</ref>
<ref source="CERT">CA-97.16.ftpd</ref>
<ref source="AUSCERT">AA-97.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0036" seq="1999-0036">
<status>Entry</status>
<desc>IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</desc>
<refs>
<ref source="CERT">CA-97.15.sgi_login</ref>
<ref source="AUSCERT">AA-97.12</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-106.shtml">H-106</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX">19970508-02-PX</ref>
<ref source="OSVDB" url="http://www.osvdb.org/990">990</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/557">sgi-lockout(557)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0037" seq="1999-0037">
<status>Entry</status>
<desc>Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.</desc>
<refs>
<ref source="CERT">CA-97.14.metamail</ref>
<ref source="XF">metamail-header-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0038" seq="1999-0038">
<status>Entry</status>
<desc>Buffer overflow in xlock program allows local users to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-97.13.xlock</ref>
<ref source="XF">xlock-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0039" seq="1999-0039">
<status>Entry</status>
<desc>webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</desc>
<refs>
<ref source="BUGTRAQ">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in</ref>
<ref source="BUGTRAQ">19970507 Re: SGI Advisory: webdist.cgi</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-12.html">CA-1997-12</ref>
<ref source="AUSCERT">AA-97.14</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/374">374</ref>
<ref source="OSVDB" url="http://www.osvdb.org/235">235</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/333">http-sgi-webdist(333)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0040" seq="1999-0040">
<status>Entry</status>
<desc>Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.11.libXt</ref>
<ref source="XF">libXt-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0041" seq="1999-0041">
<status>Entry</status>
<desc>Buffer overflow in NLS (Natural Language Service).</desc>
<refs>
<ref source="CERT">CA-97.10.nls</ref>
<ref source="XF">nls-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0042" seq="1999-0042">
<status>Entry</status>
<desc>Buffer overflow in University of Washington's implementation of IMAP and POP servers.</desc>
<refs>
<ref source="NAI">NAI-21</ref>
<ref source="CERT">CA-97.09.imap_pop</ref>
<ref source="XF">popimap-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0043" seq="1999-0043">
<status>Entry</status>
<desc>Command execution via shell metachars in INN daemon (innd) 1.5 using &quot;newgroup&quot; and &quot;rmgroup&quot; control messages, and others.</desc>
<refs>
<ref source="CERT">CA-97.08.innd</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0044" seq="1999-0044">
<status>Entry</status>
<desc>fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</ref>
<ref source="XF">sgi-fsdump</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0045" seq="1999-0045">
<status>Entry</status>
<desc>List of arbitrary files on Web host via nph-test-cgi script.</desc>
<refs>
<ref source="CERT">CA-97.07.nph-test-cgi_script</ref>
<ref source="XF">http-cgi-nph</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0046" seq="1999-0046">
<status>Entry</status>
<desc>Buffer overflow of rlogin program using TERM environmental variable.</desc>
<refs>
<ref source="CERT">CA-97.06.rlogin-term</ref>
<ref source="XF">rlogin-termbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0047" seq="1999-0047">
<status>Entry</status>
<desc>MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</desc>
<refs>
<ref source="CERT">CA-97.05.sendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/685">685</ref>
<ref source="XF">sendmail-mime-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0048" seq="1999-0048">
<status>Entry</status>
<desc>Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.04.talkd</ref>
<ref source="FREEBSD">FreeBSD-SA-96:21</ref>
<ref source="AUSCERT">AA-97.01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147">00147</ref>
<ref source="XF">talkd-bo</ref>
<ref source="XF">netkit-talkd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0049" seq="1999-0049">
<status>Entry</status>
<desc>Csetup under IRIX allows arbitrary file creation or overwriting.</desc>
<refs>
<ref source="XF">sgi-csetup</ref>
<ref source="CERT">CA-97.03.csetup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0050" seq="1999-0050">
<status>Entry</status>
<desc>Buffer overflow in HP-UX newgrp program.</desc>
<refs>
<ref source="CERT">CA-97.02.hp_newgrp</ref>
<ref source="AUSCERT">AA-96.16.HP-UX.newgrp.Buffer.Overrun.Vulnerability</ref>
<ref source="XF">hp-newgrpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0051" seq="1999-0051">
<status>Entry</status>
<desc>Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</desc>
<refs>
<ref source="XF">sgi-licensemanager</ref>
<ref source="CERT">CA-97.01.flex_lm</ref>
<ref source="AUSCERT">AA-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0052" seq="1999-0052">
<status>Entry</status>
<desc>IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:08</ref>
<ref source="OSVDB" url="http://www.osvdb.org/908">908</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1389">freebsd-ip-frag-dos(1389)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0053" seq="1999-0053">
<status>Entry</status>
<desc>TCP RST denial of service in FreeBSD.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:07</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6094">6094</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0054" seq="1999-0054">
<status>Entry</status>
<desc>Sun's ftpd daemon can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171">00171</ref>
<ref source="XF">sun-ftpd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0055" seq="1999-0055">
<status>Entry</status>
<desc>Buffer overflows in Sun libnsl allow root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172">00172</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only">IX80543</ref>
<ref source="RSI">RSI.0005.05-14-98.SUN.LIBNSL</ref>
<ref source="XF">sun-libnsl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0056" seq="1999-0056">
<status>Entry</status>
<desc>Buffer overflow in Sun's ping program can give root access to local users.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174">00174</ref>
<ref source="XF">sun-ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0057" seq="1999-0057">
<status>Entry</status>
<desc>Vacation program allows command execution by remote users through a sendmail command.</desc>
<refs>
<ref source="NAI">NAI-19</ref>
<ref source="XF">vacation</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087">HPSBUX9811-087</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0058" seq="1999-0058">
<status>Entry</status>
<desc>Buffer overflow in PHP cgi program, php.cgi allows shell access.</desc>
<refs>
<ref source="NAI">NAI-12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/712">712</ref>
<ref source="XF">http-cgi-phpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0059" seq="1999-0059">
<status>Entry</status>
<desc>IRIX fam service allows an attacker to obtain a list of all files on the server.</desc>
<refs>
<ref source="NAI">NAI-16</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/353">353</ref>
<ref source="OSVDB" url="http://www.osvdb.org/164">164</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/325">irix-fam(325)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0060" seq="1999-0060">
<status>Entry</status>
<desc>Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</desc>
<refs>
<ref source="NAI">NAI-26</ref>
<ref source="XF">ascend-config-kill</ref>
<ref source="ASCEND">http://www.ascend.com/2695.html</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0062" seq="1999-0062">
<status>Entry</status>
<desc>The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</desc>
<refs>
<ref source="XF">openbsd-chpass</ref>
<ref source="NAI">NAI-28</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7559">7559</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0063" seq="1999-0063">
<status>Entry</status>
<desc>Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</desc>
<refs>
<ref source="AUSCERT">ESB-98.197</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/iossyslog-pub.shtml</ref>
<ref source="XF">cisco-syslog-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0064" seq="1999-0064">
<status>Entry</status>
<desc>Buffer overflow in AIX lquerylv program gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">May28,1997</ref>
<ref source="XF">lquerylv-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0065" seq="1999-0065">
<status>Entry</status>
<desc>Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181">00181</ref>
<ref source="XF">hp-dtmail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0066" seq="1999-0066">
<status>Entry</status>
<desc>AnyForm CGI remote execution.</desc>
<refs>
<ref source="BUGTRAQ">19950731 SECURITY HOLE: &quot;AnyForm&quot; CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/719">719</ref>
<ref source="XF">http-cgi-anyform</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0067" seq="1999-0067">
<status>Entry</status>
<desc>phf CGI program allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19960923 PHF Attacks - Fun and games for the whole family</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</ref>
<ref source="AUSCERT">AA-96.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/629">629</ref>
<ref source="OSVDB" url="http://www.osvdb.org/136">136</ref>
<ref source="XF">http-cgi-phf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0068" seq="1999-0068">
<status>Entry</status>
<desc>CGI PHP mylog script allows an attacker to read any file on the target server.</desc>
<refs>
<ref source="BUGTRAQ">19971019 Vulnerability in PHP Example Logging Scripts</ref>
<ref source="XF">http-cgi-php-mylog</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3396">3396</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0069" seq="1999-0069">
<status>Entry</status>
<desc>Solaris ufsrestore buffer overflow.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169">00169</ref>
<ref source="XF">sun-ufsrestore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8158">8158</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0070" seq="1999-0070">
<status>Entry</status>
<desc>test-cgi program allows an attacker to list files on the server.</desc>
<refs>
<ref source="XF">http-cgi-test</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0071" seq="1999-0071">
<status>Entry</status>
<desc>Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</desc>
<refs>
<ref source="XF">http-apache-cookie</ref>
<ref source="NAI">NAI-2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0072" seq="1999-0072">
<status>Entry</status>
<desc>Buffer overflow in AIX xdat gives root access to local users.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:004.1</ref>
<ref source="XF">ibm-xdat</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0073" seq="1999-0073">
<status>Entry</status>
<desc>Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</desc>
<refs>
<ref source="CERT">CA-95:14.Telnetd_Environment_Vulnerability</ref>
<ref source="XF">linkerbug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0074" seq="1999-0074">
<status>Entry</status>
<desc>Listening TCP ports are sequentially allocated, allowing spoofing attacks.</desc>
<refs>
<ref source="XF">seqport</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0075" seq="1999-0075">
<status>Entry</status>
<desc>PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</desc>
<refs>
<ref source="BUGTRAQ">19961016 Re: ftpd bug? Was: bin/1805: Bug in ftpd</ref>
<ref source="XF">ftp-pasvcore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5742">5742</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0077" seq="1999-0077">
<status>Entry</status>
<desc>Predictable TCP sequence numbers allow spoofing.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/static/139.php">tcp-seq-predict(139)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0079" seq="1999-0079">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</desc>
<refs>
<ref source="XF">ftp-pasv-dos</ref>
<ref source="XF">ftp-pasvdos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0080" seq="1999-0080">
<status>Entry</status>
<desc>Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the &quot;site exec&quot; command.</desc>
<refs>
<ref source="BUGTRAQ">19950531 SECURITY: problem with some wu-ftpd-2.4 binaries (fwd)</ref>
<ref source="CERT">CA-95:16.wu-ftpd.vul</ref>
<ref source="XF">ftp-execdotdot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0081" seq="1999-0081">
<status>Entry</status>
<desc>wu-ftp allows files to be overwritten via the rnfr command.</desc>
<refs>
<ref source="XF">ftp-rnfr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0082" seq="1999-0082">
<status>Entry</status>
<desc>CWD ~root command in ftpd allows root access.</desc>
<refs>
<ref source="XF">ftp-cwd</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0083" seq="1999-0083">
<status>Entry</status>
<desc>getcwd() file descriptor leak in FTP.</desc>
<refs>
<ref source="XF">cwdleak</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0084" seq="1999-0084">
<status>Entry</status>
<desc>Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/78">nfs-mknod(78)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0085" seq="1999-0085">
<status>Entry</status>
<desc>Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</desc>
<refs>
<ref source="BUGTRAQ">19960821 rwhod buffer overflow</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/119">rwhod(119)</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/118">rwhod-vuln(118)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0087" seq="1999-0087">
<status>Entry</status>
<desc>Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</desc>
<refs>
<ref source="XF">ibm-telnetdos</ref>
<ref source="ERS">ERS-SVA-E01-1998:003.1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7992">7992</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0090" seq="1999-0090">
<status>Entry</status>
<desc>Buffer overflow in AIX rcp command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-rcp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0091" seq="1999-0091">
<status>Entry</status>
<desc>Buffer overflow in AIX writesrv command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-writesrv</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0093" seq="1999-0093">
<status>Entry</status>
<desc>AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:008.1</ref>
<ref source="XF">ibm-nslookup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0094" seq="1999-0094">
<status>Entry</status>
<desc>AIX piodmgrsu command allows local users to gain additional group privileges.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:007.1</ref>
<ref source="XF">ibm-piodmgrsu</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0095" seq="1999-0095">
<status>Entry</status>
<desc>The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-88.01</ref>
<ref source="CERT">CA-93.14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1">1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/195">195</ref>
<ref source="XF">smtp-debug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0096" seq="1999-0096">
<status>Entry</status>
<desc>Sendmail decode alias can be used to overwrite sensitive files.</desc>
<refs>
<ref source="CERT">CA-93.16</ref>
<ref source="CERT">CA-95.05</ref>
<ref source="CIAC">A-13</ref>
<ref source="CIAC">A-14</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
<ref source="XF">smtp-dcod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0097" seq="1999-0097">
<status>Entry</status>
<desc>The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:009.1</ref>
<ref source="XF">ibm-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0099" seq="1999-0099">
<status>Entry</status>
<desc>Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-95.13.syslog.vul</ref>
<ref source="XF">smtp-syslog</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0100" seq="1999-0100">
<status>Entry</status>
<desc>Remote access in AIX innd 1.5.1, using control messages.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:002.1</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0101" seq="1999-0101">
<status>Entry</status>
<desc>Buffer overflow in AIX and Solaris &quot;gethostbyname&quot; library call allows root access through corrupt DNS host names.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:001.1</ref>
<ref source="ERS">ERS-SVA-E01-1996:007.1</ref>
<ref source="SUN">00137a</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13</ref>
<ref source="NAI">NAI-1</ref>
<ref source="XF">ghbn-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0102" seq="1999-0102">
<status>Entry</status>
<desc>Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</desc>
<refs>
<ref source="XF">slmail-fromheader-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0103" seq="1999-0103">
<status>Entry</status>
<desc>Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</desc>
<refs>
<ref source="CERT">CA-96.01.UDP_service_denial</ref>
<ref source="XF">echo</ref>
<ref source="XF">chargen</ref>
<ref source="XF">chargen-patch</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0108" seq="1999-0108">
<status>Entry</status>
<desc>The printers program in IRIX has a buffer overflow that gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">another day, another buffer overflow...</ref>
<ref source="XF">printers-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0109" seq="1999-0109">
<status>Entry</status>
<desc>Buffer overflow in ffbconfig in Solaris 2.5.1.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140">00140</ref>
<ref source="AUSCERT">AA-97.06</ref>
<ref source="XF">ffbconfig-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0111" seq="1999-0111">
<status>Entry</status>
<desc>RIP v1 is susceptible to spoofing.</desc>
<refs>
<ref source="XF">rip</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0112" seq="1999-0112">
<status>Entry</status>
<desc>Buffer overflow in AIX dtterm program for the CDE.</desc>
<refs>
<ref source="BUGTRAQ">19970520 AIX 4.2 dtterm exploit</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/878">dtterm-bo(878)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0113" seq="1999-0113">
<status>Entry</status>
<desc>Some implementations of rlogin allow root access if given a -froot parameter.</desc>
<refs>
<ref source="BUGTRAQ">19940729 -froot??? (AIX rlogin bug)</ref>
<ref source="CERT">CA-94.09.bin.login.vulnerability</ref>
<ref source="CIAC">E-26</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/458">458</ref>
<ref source="XF">rlogin-froot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0115" seq="1999-0115">
<status>Entry</status>
<desc>AIX bugfiler program allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ">19970909 AIX bugfiler</ref>
<ref source="XF">ibm-bugfiler</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1800">1800</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0116" seq="1999-0116">
<status>Entry</status>
<desc>Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</desc>
<refs>
<ref source="CERT">CA-96.21.tcp_syn.flooding</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0117" seq="1999-0117">
<status>Entry</status>
<desc>AIX passwd allows local users to gain root access.</desc>
<refs>
<ref source="XF">ibm-passwd</ref>
<ref source="CERT">CA-92:07.AIX.passwd.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0118" seq="1999-0118">
<status>Entry</status>
<desc>AIX infod allows local users to gain root access through an X display.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91158980826979&amp;w=2">19981119 RSI.0011.11-09-98.AIX.INFOD</ref>
<ref source="XF">aix-infod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0120" seq="1999-0120">
<status>Entry</status>
<desc>Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</ref>
<ref source="CERT">CA-94.06.utmp.vulnerability</ref>
<ref source="XF">utmp-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0122" seq="1999-0122">
<status>Entry</status>
<desc>Buffer overflow in AIX lchangelv gives root access.</desc>
<refs>
<ref source="BUGTRAQ">Jul21,1999</ref>
<ref source="XF">lchangelv-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0124" seq="1999-0124">
<status>Entry</status>
<desc>Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</desc>
<refs>
<ref source="CERT">CA-93:11.UMN.UNIX.gopher.vulnerability</ref>
<ref source="XF">gopher-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0125" seq="1999-0125">
<status>Entry</status>
<desc>Buffer overflow in SGI IRIX mailx program.</desc>
<refs>
<ref source="XF">sgi-mailx-bo</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX">19980605-01-PX</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0126" seq="1999-0126">
<status>Entry</status>
<desc>SGI IRIX buffer overflow in xterm and Xaw allows root access.</desc>
<refs>
<ref source="CERT">VB-98.04.xterm.Xaw</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-010.shtml">J-010</ref>
<ref source="XF">xfree86-xterm-xaw</ref>
<ref source="XF">xfree86-xaw</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0128" seq="1999-0128">
<status>Entry</status>
<desc>Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</desc>
<refs>
<ref source="XF">ping-death</ref>
<ref source="CERT">CA-96.26.ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0129" seq="1999-0129">
<status>Entry</status>
<desc>Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</desc>
<refs>
<ref source="CERT">CA-96.25.sendmail_groups</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0130" seq="1999-0130">
<status>Entry</status>
<desc>Local users can start Sendmail in daemon mode and gain root privileges.</desc>
<refs>
<ref source="CERT">CA-96.24.sendmail.daemon.mode</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/716">716</ref>
<ref source="XF">sendmail-daemon-mode</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0131" seq="1999-0131">
<status>Entry</status>
<desc>Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</desc>
<refs>
<ref source="CERT">CA-96.20.sendmail_vul</ref>
<ref source="XF">smtp-875bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/717">717</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0132" seq="1999-0132">
<status>Entry</status>
<desc>Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11723">11723</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/401">expreserve(401)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0133" seq="1999-0133">
<status>Entry</status>
<desc>fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT">CA-96.18.fm_fls</ref>
<ref source="XF">fmaker-logfile</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0134" seq="1999-0134">
<status>Entry</status>
<desc>vold in Solaris 2.x allows local users to gain root access.</desc>
<refs>
<ref source="XF">sol-voldtmp</ref>
<ref source="CERT">CA-96.17.Solaris_vold_vul</ref>
<ref source="AUSCERT">AL-96.04</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8159">8159</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0135" seq="1999-0135">
<status>Entry</status>
<desc>admintool in Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sun-admintool</ref>
<ref source="CERT">CA-96.16.Solaris_admintool_vul</ref>
<ref source="AUSCERT">AL-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0136" seq="1999-0136">
<status>Entry</status>
<desc>Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sol-KCMSvuln</ref>
<ref source="AUSCERT">AL-96.02</ref>
<ref source="CERT">CA-96.15.Solaris_KCMS_vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0137" seq="1999-0137">
<status>Entry</status>
<desc>The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</desc>
<refs>
<ref source="XF">linux-dipbo</ref>
<ref source="CERT">CA-96.13.dip_vul</ref>
<ref source="XF">dip-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0138" seq="1999-0138">
<status>Entry</status>
<desc>The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</desc>
<refs>
<ref source="CERT">CA-96.12.suidperl_vul</ref>
<ref source="XF">sperl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0139" seq="1999-0139">
<status>Entry</status>
<desc>Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</desc>
<refs>
<ref source="XF">sol-mkcookie</ref>
<ref source="RSI">RSI.0012.12-03-98.SOLARIS.MKCOOKIE</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8205">8205</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0141" seq="1999-0141">
<status>Entry</status>
<desc>Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</desc>
<refs>
<ref source="XF">http-java-applet</ref>
<ref source="CERT">CA-96.07.java_bytecode_verifier</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0142" seq="1999-0142">
<status>Entry</status>
<desc>The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</desc>
<refs>
<ref source="CERT">CA-96.05.java_applet_security_mgr</ref>
<ref source="XF">http-java-appletsecmgr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0143" seq="1999-0143">
<status>Entry</status>
<desc>Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</desc>
<refs>
<ref source="CERT">CA-96.03.kerberos_4_key_server</ref>
<ref source="XF">kerberos-bf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0145" seq="1999-0145">
<status>Entry</status>
<desc>Sendmail WIZ command enabled, allowing root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</ref>
<ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0146" seq="1999-0146">
<status>Entry</status>
<desc>The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</desc>
<refs>
<ref source="BUGTRAQ">19970715 Bug CGI campas</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1975">1975</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/298">http-cgi-campas(298)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0147" seq="1999-0147">
<status>Entry</status>
<desc>The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</desc>
<refs>
<ref source="XF">http-cgi-glimpse</ref>
<ref source="AUSCERT">AA-97.28</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0148" seq="1999-0148">
<status>Entry</status>
<desc>The handler CGI program in IRIX allows arbitrary command execution.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/380">380</ref>
<ref source="XF">http-sgi-handler</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0149" seq="1999-0149">
<status>Entry</status>
<desc>The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970420 IRIX 6.x /cgi-bin/wrap bug</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/373">373</ref>
<ref source="OSVDB" url="http://www.osvdb.org/247">247</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/290">http-sgi-wrap(290)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0150" seq="1999-0150">
<status>Entry</status>
<desc>The Perl fingerd program allows arbitrary command execution from remote users.</desc>
<refs>
<ref source="XF">perl-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0151" seq="1999-0151">
<status>Entry</status>
<desc>The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</desc>
<refs>
<ref source="CERT">CA-95.07a.REVISED.satan.vul</ref>
<ref source="CERT">CA-95.06.satan.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0152" seq="1999-0152">
<status>Entry</status>
<desc>The DG/UX finger daemon allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19970811 dgux in.fingerd vulnerability</ref>
<ref source="XF">dgux-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0153" seq="1999-0153">
<status>Entry</status>
<desc>Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</desc>
<refs>
<ref source="XF">win-oob</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1666">1666</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0155" seq="1999-0155">
<status>Entry</status>
<desc>The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</desc>
<refs>
<ref source="XF">gscript-dsafer</ref>
<ref source="CERT">CA-95.10.ghostscript</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0157" seq="1999-0157">
<status>Entry</status>
<desc>Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/nifrag.shtml</ref>
<ref source="XF">cisco-fragmented-attacks</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1097">1097</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0158" seq="1999-0158">
<status>Entry</status>
<desc>Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml">20010913 Cisco PIX Firewall Manager File Exposure</ref>
<ref source="XF">cisco-pix-file-exposure</ref>
<ref source="OSVDB" url="http://www.osvdb.org/685">685</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0159" seq="1999-0159">
<status>Entry</status>
<desc>Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/ioslogin-pub.shtml</ref>
<ref source="XF">cisco-ios-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0160" seq="1999-0160">
<status>Entry</status>
<desc>Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</desc>
<refs>
<ref source="CISCO">19971001 Vulnerabilities in Cisco CHAP Authentication</ref>
<ref source="CIAC">I-002A</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1099">1099</ref>
<ref source="XF">cisco-chap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0161" seq="1999-0161">
<status>Entry</status>
<desc>In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/707/1.html</ref>
<ref source="XF">cisco-acl-tacacs</ref>
<ref source="OSVDB" url="http://www.osvdb.org/797">797</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0162" seq="1999-0162">
<status>Entry</status>
<desc>The &quot;established&quot; keyword in some Cisco IOS software allowed an attacker to bypass filtering.</desc>
<refs>
<ref source="CISCO">19950601 &quot;Established&quot; Keyword May Allow Packets to Bypass Filter</ref>
<ref source="XF">cisco-acl-established</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0164" seq="1999-0164">
<status>Entry</status>
<desc>A race condition in the Solaris ps command allows an attacker to overwrite critical files.</desc>
<refs>
<ref source="XF">sol-pstmprace</ref>
<ref source="AUSCERT">AA-95.07</ref>
<ref source="CERT">CA-95.09.Solaris.ps.vul</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8346">8346</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0166" seq="1999-0166">
<status>Entry</status>
<desc>NFS allows users to use a &quot;cd ..&quot; command to access other directories besides the exported file system.</desc>
<refs>
<ref source="XF">nfs-cd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0167" seq="1999-0167">
<status>Entry</status>
<desc>In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</desc>
<refs>
<ref source="XF">nfs-guess</ref>
<ref source="CERT">CA-91.21.SunOS.NFS.Jumbo.and.fsirand</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0168" seq="1999-0168">
<status>Entry</status>
<desc>The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</desc>
<refs>
<ref source="XF">nfs-portmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0170" seq="1999-0170">
<status>Entry</status>
<desc>Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</desc>
<refs>
<ref source="XF">nfs-ultrix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0172" seq="1999-0172">
<status>Entry</status>
<desc>FormMail CGI program allows remote execution of commands.</desc>
<refs>
<ref source="XF">http-cgi-formmail-exe</ref>
<ref source="BUGTRAQ">Aug02,1995</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0173" seq="1999-0173">
<status>Entry</status>
<desc>FormMail CGI program can be used by web servers other than the host server that the program resides on.</desc>
<refs>
<ref source="XF">http-cgi-formmail-use</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0174" seq="1999-0174">
<status>Entry</status>
<desc>The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970208 view-source</ref>
<ref source="XF">http-cgi-viewsrc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0175" seq="1999-0175">
<status>Entry</status>
<desc>The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</desc>
<refs>
<ref source="XF">http-nov-convert</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0176" seq="1999-0176">
<status>Entry</status>
<desc>The Webgais program allows a remote user to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ">Jul10,1997</ref>
<ref source="XF">http-webgais-query</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0177" seq="1999-0177">
<status>Entry</status>
<desc>The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</desc>
<refs>
<ref source="NTBUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="NTBUGTRAQ">19970905 Re: FW: [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="BUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="XF">http-website-uploader</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0178" seq="1999-0178">
<status>Entry</status>
<desc>Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2078">2078</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8">8</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/295">http-website-winsample(295)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0179" seq="1999-0179">
<status>Entry</status>
<desc>Windows NT crashes or locks up when a Samba client executes a &quot;cd ..&quot; command on a file share.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q140818">Q140818</ref>
<ref source="XF">nt-samba-dotdot</ref>
<ref source="XF">nt-351</ref>
<ref source="XF">nt-35</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0180" seq="1999-0180">
<status>Entry</status>
<desc>in.rshd allows users to login with a NULL username and execute commands.</desc>
<refs>
<ref source="XF">rsh-null</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0181" seq="1999-0181">
<status>Entry</status>
<desc>The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</desc>
<refs>
<ref source="XF">walld</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0182" seq="1999-0182">
<status>Entry</status>
<desc>Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-110.shtml">H-110</ref>
<ref source="CERT">VB-97.10.samba</ref>
<ref source="XF">nt-samba-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0183" seq="1999-0183">
<status>Entry</status>
<desc>Linux implementations of TFTP would allow access to files outside the restricted directory.</desc>
<refs>
<ref source="XF">linux-tftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0184" seq="1999-0184">
<status>Entry</status>
<desc>When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</desc>
<refs>
<ref source="XF">dns-updates</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0185" seq="1999-0185">
<status>Entry</status>
<desc>In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156">00156</ref>
<ref source="XF">sun-ftpd/logind</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0188" seq="1999-0188">
<status>Entry</status>
<desc>The passwd command in Solaris can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182">00182</ref>
<ref source="XF">sun-passwd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0189" seq="1999-0189">
<status>Entry</status>
<desc>Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</desc>
<refs>
<ref source="NAI">NAI-15</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142">00142</ref>
<ref source="XF">rpc-32771</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0190" seq="1999-0190">
<status>Entry</status>
<desc>Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167">00167</ref>
<ref source="XF">sun-rpcbind</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0191" seq="1999-0191">
<status>Entry</status>
<desc>IIS newdsn.exe CGI script allows remote users to overwrite files.</desc>
<refs>
<ref source="XF">http-cgi-newdsn</ref>
<ref source="OSVDB" url="http://www.osvdb.org/275">275</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0192" seq="1999-0192">
<status>Entry</status>
<desc>Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</desc>
<refs>
<ref source="SNI">SNI-20</ref>
<ref source="XF">bsd-tel-tgetent</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0194" seq="1999-0194">
<status>Entry</status>
<desc>Denial of service in in.comsat allows attackers to generate messages.</desc>
<refs>
<ref source="XF">comsat</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0196" seq="1999-0196">
<status>Entry</status>
<desc>websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</desc>
<refs>
<ref source="BUGTRAQ">19970704 Vulnerability in websendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2077">2077</ref>
<ref source="OSVDB" url="http://www.osvdb.org/237">237</ref>
<ref source="XF">http-webgais-smail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0201" seq="1999-0201">
<status>Entry</status>
<desc>A quote cwd command on FTP servers can reveal the full path of the home directory of the &quot;ftp&quot; user.</desc>
<refs>
<ref source="XF">ftp-home</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0202" seq="1999-0202">
<status>Entry</status>
<desc>The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</desc>
<refs>
<ref source="XF">ftp-exectar</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0203" seq="1999-0203">
<status>Entry</status>
<desc>In Sendmail, attackers can gain root privileges via SMTP by specifying an improper &quot;mail from&quot; address and an invalid &quot;rcpt to&quot; address that would cause the mail to bounce to a program.</desc>
<refs>
<ref source="CERT">CA-95.08</ref>
<ref source="CIAC">E-03</ref>
<ref source="XF">smtp-sendmail-version5</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0204" seq="1999-0204">
<status>Entry</status>
<desc>Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</desc>
<refs>
<ref source="XF">ident-bo</ref>
<ref source="CIAC">F-13</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0206" seq="1999-0206">
<status>Entry</status>
<desc>MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</desc>
<refs>
<ref source="XF">sendmail-mime-bo</ref>
<ref source="AUSCERT">AA-96.06a</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0207" seq="1999-0207">
<status>Entry</status>
<desc>Remote attacker can execute commands through Majordomo using the Reply-To field and a &quot;lists&quot; command.</desc>
<refs>
<ref source="XF">majordomo-exe</ref>
<ref source="CERT">CA-94.11.majordomo.vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0208" seq="1999-0208">
<status>Entry</status>
<desc>rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</desc>
<refs>
<ref source="XF">rpc-update</ref>
<ref source="CERT">CA-95.17.rpc.ypupdated.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0209" seq="1999-0209">
<status>Entry</status>
<desc>The SunView (SunTools) selection_svc facility allows remote users to read files.</desc>
<refs>
<ref source="CERT">CA-90.05.sunselection.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/8">8</ref>
<ref source="XF">selsvc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0210" seq="1999-0210">
<status>Entry</status>
<desc>Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88053459921223&amp;w=2">19971126 Solaris 2.5.1 automountd exploit (fwd)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104">HPSBUX9910-104</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/235">235</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0211" seq="1999-0211">
<status>Entry</status>
<desc>Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</desc>
<refs>
<ref source="CERT">CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/24">24</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0212" seq="1999-0212">
<status>Entry</status>
<desc>Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/168">00168</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-048.shtml">I-048</ref>
<ref source="XF">sun-mountd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0214" seq="1999-0214">
<status>Entry</status>
<desc>Denial of service by sending forged ICMP unreachable packets.</desc>
<refs>
<ref source="XF">icmp-unreachable</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0215" seq="1999-0215">
<status>Entry</status>
<desc>Routed allows attackers to append data to files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX">19981004-01-PX</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-012.shtml">J-012</ref>
<ref source="XF">ripapp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0217" seq="1999-0217">
<status>Entry</status>
<desc>Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</desc>
<refs>
<ref source="XF">udp-bomb</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0218" seq="1999-0218">
<status>Entry</status>
<desc>Livingston portmaster machines could be rebooted via a series of commands.</desc>
<refs>
<ref source="XF">portmaster-reboot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0219" seq="1999-0219">
<status>Entry</status>
<desc>Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2">19990503 Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="BUGTRAQ">19990909 Exploit: Serv-U Ver2.5 FTPd Win9x/NT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/269">269</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/205">ftp-servu(205)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0221" seq="1999-0221">
<status>Entry</status>
<desc>Denial of service of Ascend routers through port 150 (remote administration).</desc>
<refs>
<ref source="XF">ascend-150-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0223" seq="1999-0223">
<status>Entry</status>
<desc>Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.</desc>
<refs>
<ref source="BUGTRAQ">19961109 Syslogd and Solaris 2.4</ref>
<ref source="SUNBUG">1249320</ref>
<ref source="CONFIRM" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches">http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches</ref>
<ref source="XF">sol-syslogd-crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1878">1878</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0224" seq="1999-0224">
<status>Entry</status>
<desc>Denial of service in Windows NT messenger service through a long username.</desc>
<refs>
<ref source="XF">nt-messenger</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0225" seq="1999-0225">
<status>Entry</status>
<desc>Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp">19980214 Windows NT Logon Denial of Service</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=180963">Q180963</ref>
<ref source="XF">nt-logondos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0227" seq="1999-0227">
<status>Entry</status>
<desc>Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154087">Q154087</ref>
<ref source="XF">nt-lsass-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0228" seq="1999-0228">
<status>Entry</status>
<desc>Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</desc>
<refs>
<ref source="XF">nt-rpc-ver</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q162567">Q162567</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0230" seq="1999-0230">
<status>Entry</status>
<desc>Buffer overflow in Cisco 7xx routers through the telnet service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/pwbuf-pub.shtml</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1102">1102</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0233" seq="1999-0233">
<status>Entry</status>
<desc>IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q148188">Q148188</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q155056">Q155056</ref>
<ref source="XF">http-iis-cmd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0234" seq="1999-0234">
<status>Entry</status>
<desc>Bash treats any character with a value of 255 as a command separator.</desc>
<refs>
<ref source="XF">bash-cmd</ref>
<ref source="CERT">CA-96.22.bash_vuls</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0236" seq="1999-0236">
<status>Entry</status>
<desc>ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</desc>
<refs>
<ref source="XF">http-scriptalias</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0237" seq="1999-0237">
<status>Entry</status>
<desc>Remote execution of arbitrary commands through Guestbook CGI program.</desc>
<refs>
<ref source="XF">http-cgi-guestbook</ref>
<ref source="CERT">VB-97.02</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0239" seq="1999-0239">
<status>Entry</status>
<desc>Netscape FastTrack Web server lists files when a lowercase &quot;get&quot; command is used instead of an uppercase GET.</desc>
<refs>
<ref source="XF">fastrack-get-directory-list</ref>
<ref source="OSVDB" url="http://www.osvdb.org/122">122</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0244" seq="1999-0244">
<status>Entry</status>
<desc>Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.</desc>
<refs>
<ref source="NAI">NAI-23</ref>
<ref source="XF">radius-accounting-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0245" seq="1999-0245">
<status>Entry</status>
<desc>Some configurations of NIS+ in Linux allowed attackers to log in as the user &quot;+&quot;.</desc>
<refs>
<ref source="BUGTRAQ">19950907 Linux NIS security problem hole and fix</ref>
<ref source="XF">linux-plus</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0247" seq="1999-0247">
<status>Entry</status>
<desc>Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp">19970721 INN news server vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1443">1443</ref>
<ref source="XF">inn-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0248" seq="1999-0248">
<status>Entry</status>
<desc>A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.</desc>
<refs>
<ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html">http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html</ref>
<ref source="CONFIRM" url="http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1">http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0251" seq="1999-0251">
<status>Entry</status>
<desc>Denial of service in talk program allows remote attackers to disrupt a user's display.</desc>
<refs>
<ref source="XF">talkd-flash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0252" seq="1999-0252">
<status>Entry</status>
<desc>Buffer overflow in listserv allows arbitrary command execution.</desc>
<refs>
<ref source="XF">smtp-listserv</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0256" seq="1999-0256">
<status>Entry</status>
<desc>Buffer overflow in War FTP allows remote execution of commands.</desc>
<refs>
<ref source="XF">war-ftpd</ref>
<ref source="OSVDB" url="http://www.osvdb.org/875">875</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0259" seq="1999-0259">
<status>Entry</status>
<desc>cfingerd lists all users on a system via search.**@target.</desc>
<refs>
<ref source="BUGTRAQ">19970523 cfingerd vulnerability</ref>
<ref source="XF">cfinger-user-enumeration</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0260" seq="1999-0260">
<status>Entry</status>
<desc>The jj CGI program allows command execution via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19961224 jj cgi</ref>
<ref source="XF">http-cgi-jj</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0262" seq="1999-0262">
<status>Entry</status>
<desc>Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</desc>
<refs>
<ref source="BUGTRAQ">19980804 remote exploit in faxsurvey cgi-script</ref>
<ref source="BUGTRAQ">19980804 PATCH: faxsurvey</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2056">2056</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1532">http-cgi-faxsurvey(1532)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0263" seq="1999-0263">
<status>Entry</status>
<desc>Solaris SUNWadmap can be exploited to obtain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/173">00173</ref>
<ref source="XF">sun-sunwadmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0264" seq="1999-0264">
<status>Entry</status>
<desc>htmlscript CGI program allows remote read access to files.</desc>
<refs>
<ref source="XF">http-htmlscript-file-access</ref>
<ref source="BUGTRAQ">Jan27,1998</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0265" seq="1999-0265">
<status>Entry</status>
<desc>ICMP redirect messages may crash or lock up a host.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154174">Q154174</ref>
<ref source="ISS">ICMP Redirects Against Embedded Controllers</ref>
<ref source="XF">icmp-redirect</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0266" seq="1999-0266">
<status>Entry</status>
<desc>The info2www CGI script allows remote file access or remote command execution.</desc>
<refs>
<ref source="BUGTRAQ">19980303 Vulnerabilites in some versions of info2www CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1995">1995</ref>
<ref source="XF">http-cgi-info2www</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0267" seq="1999-0267">
<status>Entry</status>
<desc>Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</desc>
<refs>
<ref source="XF">http-port</ref>
<ref source="CERT">CA-95.04.NCSA.http.daemon.for.unix.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0268" seq="1999-0268">
<status>Entry</status>
<desc>MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.</desc>
<refs>
<ref source="BUGTRAQ">19980630 Security vulnerabilities in MetaInfo products</ref>
<ref source="BUGTRAQ">19980703 Followup to MetaInfo vulnerabilities</ref>
<ref source="OSVDB" url="http://www.osvdb.org/110">110</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3969">3969</ref>
<ref source="XF">metaweb-server-dot-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0269" seq="1999-0269">
<status>Entry</status>
<desc>Netscape Enterprise servers may list files through the PageServices query.</desc>
<refs>
<ref source="XF">netscape-server-pageservices</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0270" seq="1999-0270">
<status>Entry</status>
<desc>Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as &quot;pfdisplay&quot;) for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ">19980317 IRIX performer_tools bug</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P">19980401-01-P</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-041.shtml">I-041</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/64">64</ref>
<ref source="OSVDB" url="http://www.osvdb.org/134">134</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/810">sgi-pfdispaly(810)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0272" seq="1999-0272">
<status>Entry</status>
<desc>Denial of service in Slmail v2.5 through the POP3 port.</desc>
<refs>
<ref source="XF">slmail-username-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0273" seq="1999-0273">
<status>Entry</status>
<desc>Denial of service through Solaris 2.5.1 telnet by sending ^D characters.</desc>
<refs>
<ref source="XF">sun-telnet-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0274" seq="1999-0274">
<status>Entry</status>
<desc>Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.</desc>
<refs>
<ref source="NAI">NAI-5</ref>
<ref source="XF">nt-dns-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0275" seq="1999-0275">
<status>Entry</status>
<desc>Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</desc>
<refs>
<ref source="XF">nt-dnscrash</ref>
<ref source="XF">nt-dnsver</ref>
<ref source="MS">Q169461</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0276" seq="1999-0276">
<status>Entry</status>
<desc>mSQL v2.0.1 and below allows remote execution through a buffer overflow.</desc>
<refs>
<ref source="XF">msql-debug-bo</ref>
<ref source="SEKURE">sekure.01-99.msql</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0277" seq="1999-0277">
<status>Entry</status>
<desc>The WorkMan program can be used to overwrite any file to get root access.</desc>
<refs>
<ref source="XF">workman</ref>
<ref source="CERT">CA-96.23.workman_vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0278" seq="1999-0278">
<status>Entry</status>
<desc>In IIS, remote attackers can obtain source code for ASP files by appending &quot;::$DATA&quot; to the URL.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-003.mspx">MS98-003</ref>
<ref source="XF">iis-asp-data-check</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:913">oval:org.mitre.oval:def:913</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0279" seq="1999-0279">
<status>Entry</status>
<desc>Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19971217 CGI security hole in EWS (Excite for Web Servers)</ref>
<ref source="BUGTRAQ">19980115 Excite announcement</ref>
<ref source="CERT">VB-98.01.excite</ref>
<ref source="XF">excite-cgi-search-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0280" seq="1999-0280">
<status>Entry</status>
<desc>Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</desc>
<refs>
<ref source="NTBUGTRAQ">19970317 Internet Explorer Bug #4</ref>
<ref source="CIAC">H-38</ref>
<ref source="XF">http-ie-lnkurl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0281" seq="1999-0281">
<status>Entry</status>
<desc>Denial of service in IIS using long URLs.</desc>
<refs>
<ref source="XF">http-iis-longurl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0288" seq="1999-0288">
<status>Entry</status>
<desc>The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.</desc>
<refs>
<ref source="NTBUGTRAQ">19970801 WINS flooding</ref>
<ref source="BUGTRAQ">19970801 WINS flooding</ref>
<ref source="BUGTRAQ">19970815 Re: WINS flooding</ref>
<ref source="MISC" url="http://safenetworks.com/Windows/wins.html">http://safenetworks.com/Windows/wins.html</ref>
<ref source="MSKB">155701</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1233">nt-winsupd-fix(1233)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0289" seq="1999-0289">
<status>Entry</status>
<desc>The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.</desc>
<refs>
</refs>
</item>

<item type="CVE" name="CVE-1999-0290" seq="1999-0290">
<status>Entry</status>
<desc>The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.</desc>
<refs>
<ref source="BUGTRAQ">19980221 WinGate DoS</ref>
<ref source="BUGTRAQ">19980326 WinGate Intermediary Fix/Update</ref>
<ref source="XF">wingate-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0291" seq="1999-0291">
<status>Entry</status>
<desc>The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.</desc>
<refs>
<ref source="XF">wingate-unpassworded</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0292" seq="1999-0292">
<status>Entry</status>
<desc>Denial of service through Winpopup using large user names.</desc>
<refs>
<ref source="XF">nt-winpopup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0293" seq="1999-0293">
<status>Entry</status>
<desc>AAA authentication on Cisco systems allows attackers to execute commands without authorization.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/aaapair-pub.shtml</ref>
<ref source="XF">cisco-ios-aaa-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0294" seq="1999-0294">
<status>Entry</status>
<desc>All records in a WINS database can be deleted through SNMP for a denial of service.</desc>
<refs>
<ref source="XF">nt-wins-snmp2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0295" seq="1999-0295">
<status>Entry</status>
<desc>Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</desc>
<refs>
<ref source="XF">sun-sysdef</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157">00157</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0296" seq="1999-0296">
<status>Entry</status>
<desc>Solaris volrmmount program allows attackers to read any file.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/162">00162</ref>
<ref source="XF">sun-volrmmount</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0297" seq="1999-0297">
<status>Entry</status>
<desc>Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</desc>
<refs>
<ref source="NAI">NAI-3</ref>
<ref source="AUSCERT">AA-96.21</ref>
<ref source="CIAC">H-17</ref>
<ref source="XF">vixie-cron</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0299" seq="1999-0299">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD lpd through long DNS hostnames.</desc>
<refs>
<ref source="NAI">NAI-9</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6093">6093</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0300" seq="1999-0300">
<status>Entry</status>
<desc>nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155">00155</ref>
<ref source="XF">sun-niscache</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0301" seq="1999-0301">
<status>Entry</status>
<desc>Buffer overflow in SunOS/Solaris ps command.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149">00149</ref>
<ref source="AUSCERT">AUSCERT-97.17</ref>
<ref source="XF">sun-ps2bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0302" seq="1999-0302">
<status>Entry</status>
<desc>SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/176">00176</ref>
<ref source="XF">sun-ftp-server</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0303" seq="1999-0303">
<status>Entry</status>
<desc>Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.</desc>
<refs>
<ref source="XF">bnu-uucpd-bo</ref>
<ref source="RSI">RSI.0002.05-18-98.BNU.UUCPD</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0304" seq="1999-0304">
<status>Entry</status>
<desc>mmap function in BSD allows local attackers in the kmem group to modify memory through devices.</desc>
<refs>
<ref source="XF">bsd-mmap</ref>
<ref source="FREEBSD">FreeBSD-SA-98:02</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0305" seq="1999-0305">
<status>Entry</status>
<desc>The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.</desc>
<refs>
<ref source="OPENBSD">Feb15,1998 &quot;IP Source Routing Problem&quot;</ref>
<ref source="MISC" url="http://www.openbsd.org/advisories/sourceroute.txt">http://www.openbsd.org/advisories/sourceroute.txt</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11502">11502</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/736">bsd-sourceroute(736)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0308" seq="1999-0308">
<status>Entry</status>
<desc>HP-UX gwind program allows users to modify arbitrary files.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018">HPSBUX9410-018</ref>
<ref source="XF">hpux-gwind-overwrite</ref>
<ref source="CIAC">H-03: HP-UX suid Vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0309" seq="1999-0309">
<status>Entry</status>
<desc>HP-UX vgdisplay program gives root access to local users.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056">HPSBUX9702-056</ref>
<ref source="XF">hpux-vgdisplay</ref>
<ref source="CIAC">H-27: HP-UX vgdisplay Buffer Overrun Vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0310" seq="1999-0310">
<status>Entry</status>
<desc>SSH 1.2.25 on HP-UX allows access to new user accounts.</desc>
<refs>
<ref source="XF">ssh-1225</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0311" seq="1999-0311">
<status>Entry</status>
<desc>fpkg2swpk in HP-UX allows local users to gain root access.</desc>
<refs>
<ref source="XF">hpux-fpkg2swpk</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042">HPSBUX9612-042</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0312" seq="1999-0312">
<status>Entry</status>
<desc>HP ypbind allows attackers with root privileges to modify NIS data.</desc>
<refs>
<ref source="XF">nis-ypbind</ref>
<ref source="CERT">CA-93:01.REVISED.HP.NIS.ypbind.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0313" seq="1999-0313">
<status>Entry</status>
<desc>disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</desc>
<refs>
<ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/214">214</ref>
<ref source="OSVDB" url="http://www.osvdb.org/936">936</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1441">sgi-disk-bandwidth(1441)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0314" seq="1999-0314">
<status>Entry</status>
<desc>ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</desc>
<refs>
<ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/213">213</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6788">6788</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1199">sgi-ioconfig(1199)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0315" seq="1999-0315">
<status>Entry</status>
<desc>Buffer overflow in Solaris fdformat command gives root access to local users.</desc>
<refs>
<ref source="XF">fdformat-bo</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138">00138</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0316" seq="1999-0316">
<status>Entry</status>
<desc>Buffer overflow in Linux splitvt command gives root access to local users.</desc>
<refs>
<ref source="XF">linux-splitvt</ref>
<ref source="CIAC">G-08</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0318" seq="1999-0318">
<status>Entry</status>
<desc>Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19961125 Security Problems in XMCD</ref>
<ref source="BUGTRAQ">19961125 XMCD v2.1 released (was: Security Problems in XMCD)</ref>
<ref source="XF">xmcd-envbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0320" seq="1999-0320">
<status>Entry</status>
<desc>SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/166">00166</ref>
<ref source="XF">sun-rpc.cmsd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0321" seq="1999-0321">
<status>Entry</status>
<desc>Buffer overflow in Solaris kcms_configure command allows local users to gain root access.</desc>
<refs>
<ref source="XF">sun-kcms-configure-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0322" seq="1999-0322">
<status>Entry</status>
<desc>The open() function in FreeBSD allows local attackers to write to arbitrary files.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-97:05</ref>
<ref source="XF">freebsd-open</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6092">6092</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0323" seq="1999-0323">
<status>Entry</status>
<desc>FreeBSD mmap function allows users to modify append-only or immutable files.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:04</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc">1998-003</ref>
<ref source="XF">bsd-mmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0324" seq="1999-0324">
<status>Entry</status>
<desc>ppl program in HP-UX allows local users to create root files through symlinks.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053">HPSBUX9702-053</ref>
<ref source="CIAC">H-31</ref>
<ref source="XF">hp-ppllog</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0325" seq="1999-0325">
<status>Entry</status>
<desc>vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</desc>
<refs>
<ref source="XF">hp-vhe</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013">HPSBUX9406-013</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0326" seq="1999-0326">
<status>Entry</status>
<desc>Vulnerability in HP-UX mediainit program.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071">HPSBUX9710-071</ref>
<ref source="XF">hp-mediainit</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0327" seq="1999-0327">
<status>Entry</status>
<desc>SGI syserr program allows local users to corrupt files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
<ref source="XF">sgi-syserr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0328" seq="1999-0328">
<status>Entry</status>
<desc>SGI permissions program allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
<ref source="XF">sgi-permtool</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0329" seq="1999-0329">
<status>Entry</status>
<desc>SGI mediad program allows local users to gain root access.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX">19980602-01-PX</ref>
<ref source="XF">sgi-mediad</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0332" seq="1999-0332">
<status>Entry</status>
<desc>Buffer overflow in NetMeeting allows denial of service and remote command execution.</desc>
<refs>
<ref source="XF">nt-netmeeting</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q184346">Q184346</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0334" seq="1999-0334">
<status>Entry</status>
<desc>In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</desc>
<refs>
<ref source="XF">sol-startup</ref>
<ref source="CERT">CA-93.19.Solaris.Startup.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0335" seq="1999-0335">
<status>Entry</status>
<desc>DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</desc>
<refs>
</refs>
</item>

<item type="CVE" name="CVE-1999-0337" seq="1999-0337">
<status>Entry</status>
<desc>AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</desc>
<refs>
<ref source="CERT">CA-94.10.IBM.AIX.bsh.vulnerability.html</ref>
<ref source="XF">ibm-bsh</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0338" seq="1999-0338">
<status>Entry</status>
<desc>AIX Licensed Program Product performance tools allow local users to gain root access.</desc>
<refs>
<ref source="XF">ibm-perf-tools</ref>
<ref source="CERT">CA-94.03.AIX.performance.tools </ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0339" seq="1999-0339">
<status>Entry</status>
<desc>Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.</desc>
<refs>
<ref source="XF">sol-sun-libauth</ref>
<ref source="RSI">RSI.0007.05-26-98</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0340" seq="1999-0340">
<status>Entry</status>
<desc>Buffer overflow in Linux Slackware crond program allows local users to gain root access.</desc>
<refs>
<ref source="KSRT">005</ref>
<ref source="XF">linux-crond</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0341" seq="1999-0341">
<status>Entry</status>
<desc>Buffer overflow in the Linux mail program &quot;deliver&quot; allows local users to gain root access.</desc>
<refs>
<ref source="KSRT">006</ref>
<ref source="XF">linux-deliver</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0342" seq="1999-0342">
<status>Entry</status>
<desc>Linux PAM modules allow local users to gain root access using temporary files.</desc>
<refs>
<ref source="REDHAT">http://www.redhat.com/corp/support/errata/rh42-errata-general.html#pam</ref>
<ref source="XF">linux-pam-passwd-tmprace</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0343" seq="1999-0343">
<status>Entry</status>
<desc>A malicious Palace server can force a client to execute arbitrary programs.</desc>
<refs>
<ref source="BUGTRAQ">19981002 Announcements from The Palace (fwd)</ref>
<ref source="XF">palace-malicious-servers-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0344" seq="1999-0344">
<status>Entry</status>
<desc>NT users can gain debug-level access on a system process using the Sechole exploit.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-009.mspx">MS98-009</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q190288">Q190288</ref>
<ref source="XF">nt-priv-fix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0346" seq="1999-0346">
<status>Entry</status>
<desc>CGI PHP mlog script allows an attacker to read any file on the target server.</desc>
<refs>
<ref source="BUGTRAQ">19971019 Vulnerability in PHP Example Logging Scripts</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
<ref source="XF">http-cgi-php-mlog</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3397">3397</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0348" seq="1999-0348">
<status>Entry</status>
<desc>IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.</desc>
<refs>
<ref source="NTBUGTRAQ">Jan27,1999</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q197003">Q197003</ref>
<ref source="OSVDB" url="http://www.osvdb.org/930">930</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0349" seq="1999-0349">
<status>Entry</status>
<desc>A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/IIS Remote FTP Exploit/DoS Attack.html">IIS Remote FTP Exploit/DoS Attack</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx">MS99-003</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q188348">Q188348</ref>
<ref source="BUGTRAQ">Jan27,1999</ref>
<ref source="XF">iis-remote-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0350" seq="1999-0350">
<status>Entry</status>
<desc>Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.</desc>
<refs>
<ref source="L0PHT">Feb8,1999</ref>
<ref source="XF">clearcase-temp-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0351" seq="1999-0351">
<status>Entry</status>
<desc>FTP PASV &quot;Pizza Thief&quot; denial of service and unauthorized data access.  Attackers can steal data by connecting to a port that was intended for use by a client.</desc>
<refs>
<ref source="INFOWAR">01</ref>
<ref source="MISC" url="http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt">http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3389">pasv-pizza-thief-dos(3389)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0353" seq="1999-0353">
<status>Entry</status>
<desc>rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091">HPSBUX9902-091</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-026.shtml">J-026</ref>
<ref source="XF">pcnfsd-world-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0355" seq="1999-0355">
<status>Entry</status>
<desc>Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.</desc>
<refs>
<ref source="ISS">Multiple vulnerabilities in ControlIT(tm) (formerly Remotely Possible/32) enterprise management software</ref>
<ref source="XF">controlit-reboot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0357" seq="1999-0357">
<status>Entry</status>
<desc>Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted &quot;oshare&quot; packets, possibly involving invalid fragmentation offsets.</desc>
<refs>
<ref source="BUGTRAQ">19990125 Win98 crash?</ref>
<ref source="XF">win98-oshare-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0358" seq="1999-0358">
<status>Entry</status>
<desc>Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12121">19990125 Digital Unix 4.0 exploitable buffer overflows</ref>
<ref source="COMPAQ">SSRT0583U</ref>
<ref source="XF">du-inc</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-027.shtml">J-027</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0362" seq="1999-0362">
<status>Entry</status>
<desc>WS_FTP server remote denial of service through cwd command.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02021999.html">AD02021999</ref>
<ref source="XF">wsftp-remote-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/217">217</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0363" seq="1999-0363">
<status>Entry</status>
<desc>SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.</desc>
<refs>
<ref source="BUGTRAQ">Feb02,1999</ref>
<ref source="XF">plp-lpc-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/328">328</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0365" seq="1999-0365">
<status>Entry</status>
<desc>The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.</desc>
<refs>
<ref source="BUGTRAQ">Feb04,1999</ref>
<ref source="XF">metamail-header-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0366" seq="1999-0366">
<status>Entry</status>
<desc>In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-004.mspx">MS99-004</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q214840">Q214840</ref>
<ref source="XF">nt-sp4-auth-error</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0367" seq="1999-0367">
<status>Entry</status>
<desc>NetBSD netstat command allows local users to access kernel memory.</desc>
<refs>
<ref source="NETBSD">1999-002</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7571">7571</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0368" seq="1999-0368">
<status>Entry</status>
<desc>Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.</desc>
<refs>
<ref source="NETECT">palmetto.ftpd</ref>
<ref source="CERT">CA-99.03</ref>
<ref source="XF">palmetto-ftpd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0369" seq="1999-0369">
<status>Entry</status>
<desc>The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183">00183</ref>
<ref source="XF">sun-sdtcm-convert-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0371" seq="1999-0371">
<status>Entry</status>
<desc>Lynx allows a local user to overwrite sensitive files through /tmp symlinks.</desc>
<refs>
<ref source="BUGTRAQ">19990211 Lynx /tmp problem</ref>
<ref source="CERT">VB-97.05.lynx</ref>
<ref source="XF">lynx-temp-files-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0372" seq="1999-0372">
<status>Entry</status>
<desc>The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-005.mspx">MS99-005</ref>
<ref source="XF">nt-backoffice-setup</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q217004">Q217004</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0373" seq="1999-0373">
<status>Entry</status>
<desc>Buffer overflow in the &quot;Super&quot; utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.</desc>
<refs>
<ref source="ISS">Buffer Overflow in &quot;Super&quot; package in Debian Linux</ref>
<ref source="XF">linux-super-bo</ref>
<ref source="XF">linux-super-logging-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0374" seq="1999-0374">
<status>Entry</status>
<desc>Debian GNU/Linux cfengine package is susceptible to a symlink attack.</desc>
<refs>
<ref source="DEBIAN">19990215</ref>
<ref source="BUGTRAQ">Feb16,1999</ref>
<ref source="XF">linux-cfengine-symlinks</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0375" seq="1999-0375">
<status>Entry</status>
<desc>Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.</desc>
<refs>
<ref source="NAI">February 16, 1999</ref>
<ref source="BUGTRAQ">Feb16,1999</ref>
<ref source="XF">nfr-webd-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0376" seq="1999-0376">
<status>Entry</status>
<desc>Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-006.mspx">MS99-006</ref>
<ref source="BUGTRAQ">Feb20,1999</ref>
<ref source="L0PHT">Feb18,1999</ref>
<ref source="XF">nt-knowndlls-list</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0377" seq="1999-0377">
<status>Entry</status>
<desc>Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.</desc>
<refs>
<ref source="BUGTRAQ">Feb22,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0378" seq="1999-0378">
<status>Entry</status>
<desc>InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.</desc>
<refs>
<ref source="BUGTRAQ">19990222 BlackHats Advisory -- InterScan VirusWall</ref>
<ref source="BUGTRAQ">19990225 Patch for InterScan VirusWall for Unix now available</ref>
<ref source="XF">viruswall-http-request</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6167">6167</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0379" seq="1999-0379">
<status>Entry</status>
<desc>Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-007.mspx">MS99-007</ref>
<ref source="BUGTRAQ">19990223 Microsoft Security Bulletin (MS99-007)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/498">498</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1019">1019</ref>
<ref source="XF">win-resourcekit-taskpads</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0380" seq="1999-0380">
<status>Entry</status>
<desc>SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91999015212415&amp;w=2">199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91996412724720&amp;w=2">19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92110501504997&amp;w=2">SLmail 3.2 Build 3113 (Web Administration Security Fix)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/497">497</ref>
<ref source="XF" url="http://xforce.iss.net/static/5392.php">slmail-ras-ntfs-bypass(5392)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0382" seq="1999-0382">
<status>Entry</status>
<desc>The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-008.mspx">MS99-008</ref>
<ref source="XF">nt-screen-saver</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0383" seq="1999-0383">
<status>Entry</status>
<desc>ACC Tigris allows public access without a login.</desc>
<refs>
<ref source="BUGTRAQ">19990103 Tigris vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/183">183</ref>
<ref source="OSVDB" url="http://www.osvdb.org/267">267</ref>
<ref source="XF">acc-tigris-login</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0384" seq="1999-0384">
<status>Entry</status>
<desc>The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.</desc>
<refs>
<ref source="XF">forms-vuln-patch</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-001.mspx">MS99-001</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0385" seq="1999-0385">
<status>Entry</status>
<desc>The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-009.mspx">MS99-009</ref>
<ref source="ISS">LDAP Buffer overflow against Microsoft Directory Services</ref>
<ref source="XF">ldap-exchange-overflow</ref>
<ref source="XF">ldap-mds-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0386" seq="1999-0386">
<status>Entry</status>
<desc>Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-010.mspx">MS99-010</ref>
<ref source="XF">pws-file-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/111">111</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0387" seq="1999-0387">
<status>Entry</status>
<desc>A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-052.asp">MS99-052</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q168115">Q168115</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/829">829</ref>
<ref source="XF">9x-plaintext-pwd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0388" seq="1999-0388">
<status>Entry</status>
<desc>DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.</desc>
<refs>
<ref source="XF">datalynx-suguard-relative-paths</ref>
<ref source="L0PHT">Jan3,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3186">3186</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0390" seq="1999-0390">
<status>Entry</status>
<desc>Buffer overflow in Dosemu Slang library in Linux.</desc>
<refs>
<ref source="BUGTRAQ">19990104 Dosemu/S-Lang Overflow + sploit</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt">CSSA-1999-006.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/187">187</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0391" seq="1999-0391">
<status>Entry</status>
<desc>The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.</desc>
<refs>
<ref source="L0PHT">Jan. 5, 1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0392" seq="1999-0392">
<status>Entry</status>
<desc>Buffer overflow in Thomas Boutell's cgic library version up to 1.05.</desc>
<refs>
<ref source="BUGTRAQ">Jan10,1999</ref>
<ref source="XF">http-cgic-library-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0393" seq="1999-0393">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.</desc>
<refs>
<ref source="BUGTRAQ">19981212 ** Sendmail 8.9.2 DoS - exploit ** get what you want!</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91694391227372&amp;w=2">19990121 Sendmail 8.8.x/8.9.x bugware</ref>
<ref source="XF">sendmail-parsing-redirection</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0395" seq="1999-0395">
<status>Entry</status>
<desc>A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise17.php">19990118 Vulnerability in the BackWeb Polite Agent Protocol</ref>
<ref source="XF">backweb-polite-agent-protocol</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0396" seq="1999-0396">
<status>Entry</status>
<desc>A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.</desc>
<refs>
<ref source="NETBSD">1999-001</ref>
<ref source="OPENBSD">Feb17,1999</ref>
<ref source="XF">netbsd-tcp-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0402" seq="1999-0402">
<status>Entry</status>
<desc>wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.</desc>
<refs>
<ref source="BUGTRAQ">Feb2,1999</ref>
<ref source="XF">wget-permissions</ref>
<ref source="DEBIAN">19990220</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0403" seq="1999-0403">
<status>Entry</status>
<desc>A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91821080015725&amp;w=2">19990204 Cyrix bug: freeze in hell, badboy</ref>
<ref source="XF">cyrix-hang</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0404" seq="1999-0404">
<status>Entry</status>
<desc>Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.</desc>
<refs>
<ref source="BUGTRAQ">Feb14,1999</ref>
<ref source="XF">mailmax-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0405" seq="1999-0405">
<status>Entry</status>
<desc>A buffer overflow in lsof allows local users to obtain root privilege.</desc>
<refs>
<ref source="HERT">002</ref>
<ref source="BUGTRAQ">Feb18,1999</ref>
<ref source="DEBIAN">19990220a</ref>
<ref source="XF">lsof-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3163">3163</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0407" seq="1999-0407">
<status>Entry</status>
<desc>By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91983486431506&amp;w=2">19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92000623021036&amp;w=2">19990209 Re: IIS4 allows proxied password attacks over NetBIOS</ref>
<ref source="XF">iis-iisadmpwd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0408" seq="1999-0408">
<status>Entry</status>
<desc>Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.</desc>
<refs>
<ref source="BUGTRAQ">19990225 Cobalt root exploit</ref>
<ref source="XF">cobalt-raq-history-exposure</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/337">337</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0409" seq="1999-0409">
<status>Entry</status>
<desc>Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.</desc>
<refs>
<ref source="BUGTRAQ">19990304 Linux /usr/bin/gnuplot overflow</ref>
<ref source="XF">gnuplot-home-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/319">319</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0410" seq="1999-0410">
<status>Entry</status>
<desc>The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.</desc>
<refs>
<ref source="BUGTRAQ">Mar5,1999</ref>
<ref source="XF">sol-cancel</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/293">293</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0412" seq="1999-0412">
<status>Entry</status>
<desc>In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.</desc>
<refs>
<ref source="BUGTRAQ">Feb19,1999</ref>
<ref source="XF">iis-isapi-execute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/501">501</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0413" seq="1999-0413">
<status>Entry</status>
<desc>A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX">19990301-01-PX</ref>
<ref source="XF">irix-font-path-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0414" seq="1999-0414">
<status>Entry</status>
<desc>In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.</desc>
<refs>
<ref source="NAI">Linux Blind TCP Spoofing</ref>
<ref source="XF">linux-blind-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0415" seq="1999-0415">
<status>Entry</status>
<desc>The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.</desc>
<refs>
<ref source="ISS">19990311 Remote Reconfiguration and Denial of Service Vulnerabilities in Cisco 700 ISDN Routers</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
<ref source="XF">cisco-router-commands</ref>
<ref source="XF">cisco-web-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0416" seq="1999-0416">
<status>Entry</status>
<desc>Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.</desc>
<refs>
<ref source="ISS">19990311 Remote Reconfiguration and Denial of Service Vulnerabilities in Cisco 700 ISDN Routers</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
<ref source="XF">cisco-web-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0417" seq="1999-0417">
<status>Entry</status>
<desc>64 bit Solaris 7 procfs allows local users to perform a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">Mar9,1999</ref>
<ref source="XF">solaris-psinfo-crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/448">448</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1001">1001</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0420" seq="1999-0420">
<status>Entry</status>
<desc>umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.</desc>
<refs>
<ref source="NETBSD">1999-006</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0421" seq="1999-0421">
<status>Entry</status>
<desc>During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</desc>
<refs>
<ref source="ISS">Short-Term High-Risk Vulnerability During Slackware 3.6 Network Installations</ref>
<ref source="XF">linux-slackware-install</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/338">338</ref>
<ref source="OSVDB" url="http://www.osvdb.org/981">981</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0422" seq="1999-0422">
<status>Entry</status>
<desc>In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the &quot;noexec&quot; flag set.</desc>
<refs>
<ref source="NETBSD">1999-007</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0423" seq="1999-0423">
<status>Entry</status>
<desc>Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093">HPSBUX9903-093</ref>
<ref source="XF">hp-hpterm-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0424" seq="1999-0424">
<status>Entry</status>
<desc>talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.</desc>
<refs>
<ref source="SUSE">Mar18,1999</ref>
<ref source="XF">netscape-talkback-overwrite</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0425" seq="1999-0425">
<status>Entry</status>
<desc>talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.</desc>
<refs>
<ref source="SUSE">Mar18,1999</ref>
<ref source="XF">netscape-talkback-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0428" seq="1999-0428">
<status>Entry</status>
<desc>OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.</desc>
<refs>
<ref source="BUGTRAQ">19990322 OpenSSL/SSLeay Security Alert</ref>
<ref source="XF">ssl-session-reuse</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3936">3936</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0429" seq="1999-0429">
<status>Entry</status>
<desc>The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the &quot;Encrypt Saved Mail&quot; preference.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92221437025743&amp;w=2">19990323</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92241547418689&amp;w=2">19990324 Re: LNotes encryption</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92246997917866&amp;w=2">19990326 Lotus Notes Encryption Bug</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92249282302994&amp;w=2">19990326 Re: Lotus Notes security advisory</ref>
<ref source="XF">lotus-client-encryption</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0430" seq="1999-0430">
<status>Entry</status>
<desc>Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.</desc>
<refs>
<ref source="ISS">Remote Denial of Service Vulnerability in Cisco Catalyst Series Ethernet Switches</ref>
<ref source="CISCO">Cisco Catalyst Supervisor Remote Reload</ref>
<ref source="XF">cisco-catalyst-crash</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1103">1103</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0432" seq="1999-0432">
<status>Entry</status>
<desc>ftp on HP-UX 11.00 allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094">HPSBUX9903-094</ref>
<ref source="XF">hp-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0433" seq="1999-0433">
<status>Entry</status>
<desc>XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</desc>
<refs>
<ref source="SUSE">Mar28,1999</ref>
<ref source="BUGTRAQ">19990321 X11R6 NetBSD Security Problem</ref>
<ref source="XF">xfree86-temp-directories</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0436" seq="1999-0436">
<status>Entry</status>
<desc>Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095">HPSBUX9903-095</ref>
<ref source="XF">hp-desms-servers</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0437" seq="1999-0437">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.</desc>
<refs>
<ref source="ISS">WebRamp Denial of Service Attacks</ref>
<ref source="XF">webramp-device-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0438" seq="1999-0438">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.</desc>
<refs>
<ref source="ISS">WebRamp Denial of Service Attacks</ref>
<ref source="XF">webramp-ipchange</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0439" seq="1999-0439">
<status>Entry</status>
<desc>Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.</desc>
<refs>
<ref source="BUGTRAQ">19990405 Re: [SECURITY] new version of procmail with security fixes</ref>
<ref source="DEBIAN">19990422</ref>
<ref source="CALDERA">CSSA-1999:007</ref>
<ref source="XF">procmail-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0440" seq="1999-0440">
<status>Entry</status>
<desc>The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92333596624452&amp;w=2">19990405 Security Hole in Java 2 (and JDK 1.1.x)</ref>
<ref source="CONFIRM" url="http://java.sun.com/pr/1999/03/pr990329-01.html">http://java.sun.com/pr/1999/03/pr990329-01.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1939">1939</ref>
<ref source="XF">java-unverified-code</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0441" seq="1999-0441">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02221999.html">AD02221999</ref>
<ref source="XF">wingate-redirector-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/509">509</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0442" seq="1999-0442">
<status>Entry</status>
<desc>Solaris ff.core allows local users to modify files.</desc>
<refs>
<ref source="BUGTRAQ">19990107 really silly ff.core exploit for Solaris</ref>
<ref source="BUGTRAQ">19990108 ff.core exploit on Solaris (2.)7</ref>
<ref source="BUGTRAQ">19990408 Solaris7 and ff.core</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/327">327</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0445" seq="1999-0445">
<status>Entry</status>
<desc>In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.</desc>
<refs>
<ref source="CISCO">Cisco IOS(R) Software Input Access List Leakage with NAT</ref>
<ref source="XF">cisco-natacl-leakage</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1104">1104</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0446" seq="1999-0446">
<status>Entry</status>
<desc>Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.</desc>
<refs>
<ref source="NETBSD">1999-008</ref>
<ref source="XF">netbsd-vfslocking-panic</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7051">7051</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0447" seq="1999-0447">
<status>Entry</status>
<desc>Local users can gain privileges using the debug utility in the MPE/iX operating system.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006">HPSBMP9904-006</ref>
<ref source="XF">mpeix-debug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0448" seq="1999-0448">
<status>Entry</status>
<desc>IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.</desc>
<refs>
<ref source="BUGTRAQ">19990121 IIS 4 Request Logging Security Advisory</ref>
<ref source="XF">iis-http-request-logging</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0449" seq="1999-0449">
<status>Entry</status>
<desc>The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.</desc>
<refs>
<ref source="BUGTRAQ">19990126 IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="NTBUGTRAQ">19990126 IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="BUGTRAQ">19990125 Re: [NTSEC] IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/193">193</ref>
<ref source="OSVDB" url="http://www.osvdb.org/2">2</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3">3</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4">4</ref>
<ref source="XF">iis-exair-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0457" seq="1999-0457">
<status>Entry</status>
<desc>Linux ftpwatch program allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">Jan17,1999</ref>
<ref source="DEBIAN">19990117</ref>
<ref source="XF">ftpwatch-vuln</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/317">317</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0458" seq="1999-0458">
<status>Entry</status>
<desc>L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.</desc>
<refs>
<ref source="BUGTRAQ">Jan6,1999</ref>
<ref source="XF">l0phtcrack-temp-files</ref>
<ref source="OSVDB" url="http://www.osvdb.org/915">915</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0463" seq="1999-0463">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service using IRIX fcagent.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981201-01-PX">19981201-01-PX</ref>
<ref source="XF">sgi-fcagent-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0464" seq="1999-0464">
<status>Entry</status>
<desc>Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91553066310826&amp;w=2">19990104 Tripwire mess..</ref>
<ref source="CONFIRM" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6609">6609</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0466" seq="1999-0466">
<status>Entry</status>
<desc>The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.</desc>
<refs>
<ref source="NETBSD">1999-009</ref>
<ref source="OSVDB" url="http://www.osvdb.org/905">905</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0468" seq="1999-0468">
<status>Entry</status>
<desc>Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS99-012</ref>
<ref source="XF">ie-scriplet-fileread</ref>
<ref source="BUGTRAQ">Apr9,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0470" seq="1999-0470">
<status>Entry</status>
<desc>A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.</desc>
<refs>
<ref source="BUGTRAQ">19990409 New Novell Remote.NLM Password Decryption Algorithm with Exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/482">482</ref>
<ref source="XF">netware-remotenlm-passwords</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0471" seq="1999-0471">
<status>Entry</status>
<desc>The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the &quot;cancel&quot; button.</desc>
<refs>
<ref source="XF">winroute-config</ref>
<ref source="BUGTRAQ">Apr9,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0472" seq="1999-0472">
<status>Entry</status>
<desc>The SNMP default community name &quot;public&quot; is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.</desc>
<refs>
<ref source="XF">netcache-snmp</ref>
<ref source="BUGTRAQ">Apr7,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0473" seq="1999-0473">
<status>Entry</status>
<desc>The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.</desc>
<refs>
<ref source="BUGTRAQ">19990407 rsync 2.3.1 release - security fix</ref>
<ref source="CALDERA">CSSA-1999:010.0</ref>
<ref source="DEBIAN">19990823</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/145">145</ref>
<ref source="XF">rsync-permissions</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0474" seq="1999-0474">
<status>Entry</status>
<desc>The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.</desc>
<refs>
<ref source="XF">icq-webserver-read</ref>
<ref source="BUGTRAQ">Apr5,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0475" seq="1999-0475">
<status>Entry</status>
<desc>A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.</desc>
<refs>
<ref source="XF">procmail-race</ref>
<ref source="BUGTRAQ">Apr5,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0478" seq="1999-0478">
<status>Entry</status>
<desc>Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9904-097">HPSBUX9904-097</ref>
<ref source="XF">sendmail-headers-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0479" seq="1999-0479">
<status>Entry</status>
<desc>Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-092">HPSBUX9903-092</ref>
<ref source="XF">netscape-server-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0481" seq="1999-0481">
<status>Entry</status>
<desc>Denial of service in &quot;poll&quot; in OpenBSD.</desc>
<refs>
<ref source="OPENBSD">Mar22,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7556">7556</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0482" seq="1999-0482">
<status>Entry</status>
<desc>OpenBSD kernel crash through TSS handling, as caused by the crashme program.</desc>
<refs>
<ref source="OPENBSD">Mar21,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7557">7557</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0483" seq="1999-0483">
<status>Entry</status>
<desc>OpenBSD crash using nlink value in FFS and EXT2FS filesystems.</desc>
<refs>
<ref source="OPENBSD">Feb25,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6129">6129</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0484" seq="1999-0484">
<status>Entry</status>
<desc>Buffer overflow in OpenBSD ping.</desc>
<refs>
<ref source="OPENBSD">Feb23,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6130">6130</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0485" seq="1999-0485">
<status>Entry</status>
<desc>Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.</desc>
<refs>
<ref source="OPENBSD">Feb19,1999</ref>
<ref source="XF">openbsd-ipintr-race</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7558">7558</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0487" seq="1999-0487">
<status>Entry</status>
<desc>The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-011.mspx">MS99-011</ref>
<ref source="XF">ie-dhtml-control</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0491" seq="1999-0491">
<status>Entry</status>
<desc>The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9904202114070.6623-100000@smooth.Operator.org">19990420 Bash Bug</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt">CSSA-1999-008.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/119">119</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0493" seq="1999-0493">
<status>Entry</status>
<desc>rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/186&amp;type=0&amp;nav=sec.sba">00186</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-045.shtml">J-045</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/450">450</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0494" seq="1999-0494">
<status>Entry</status>
<desc>Denial of service in WinGate proxy through a buffer overflow in POP3.</desc>
<refs>
<ref source="XF">wingate-pop3-user-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0496" seq="1999-0496">
<status>Entry</status>
<desc>A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user's permissions, aka GetAdmin.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q146965">Q146965</ref>
<ref source="XF">nt-getadmin</ref>
<ref source="XF">nt-getadmin-present</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0513" seq="1999-0513">
<status>Entry</status>
<desc>ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.</desc>
<refs>
<ref source="CERT">CA-98.01.smurf</ref>
<ref source="FREEBSD">FreeBSD-SA-98:06</ref>
<ref source="XF">smurf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0514" seq="1999-0514">
<status>Entry</status>
<desc>UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.</desc>
<refs>
<ref source="XF">fraggle</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0526" seq="1999-0526">
<status>Entry</status>
<desc>An X server's access control is disabled (e.g. through an &quot;xhost +&quot; command) and allows anyone to connect to the server.</desc>
<refs>
<ref source="XF">xcheck-keystroke</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/704969">VU#704969</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0551" seq="1999-0551">
<status>Entry</status>
<desc>HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9804-078">HPSBUX9804-078</ref>
<ref source="XF">hp-openmail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0566" seq="1999-0566">
<status>Entry</status>
<desc>An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.</desc>
<refs>
<ref source="XF">ibm-syslogd</ref>
<ref source="XF">syslog-flood</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0608" seq="1999-0608">
<status>Entry</status>
<desc>An incorrect configuration of the PDG Shopping Cart CGI program &quot;shopper.cgi&quot; could disclose private information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref>
<ref source="CONFIRM" url="http://www.pdgsoft.com/Security/security.html.">http://www.pdgsoft.com/Security/security.html.</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3857">pdgsoftcart-misconfig(3857)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0612" seq="1999-0612">
<status>Entry</status>
<desc>A version of finger is running that exposes valid user information to any entity on the network.</desc>
<refs>
<ref source="XF">finger-out</ref>
<ref source="XF">finger-running</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0626" seq="1999-0626">
<status>Entry</status>
<desc>A version of rusers is running that exposes valid user information to any entity on the network.</desc>
<refs>
<ref source="XF">rusersd</ref>
<ref source="XF">ruser</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0627" seq="1999-0627">
<status>Entry</status>
<desc>The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.</desc>
<refs>
<ref source="XF">rexd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0628" seq="1999-0628">
<status>Entry</status>
<desc>The rwho/rwhod service is running, which exposes machine status and user information.</desc>
<refs>
<ref source="XF">rwhod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0668" seq="1999-0668">
<status>Entry</status>
<desc>The scriptlet.typelib ActiveX control is marked as &quot;safe for scripting&quot; for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</desc>
<refs>
<ref source="BUGTRAQ">19990821 IE 5.0 allows executing programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-032.asp">MS99-032</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/598">598</ref>
<ref source="XF">ms-scriptlet-eyedog-unsafe</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240308">Q240308</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0671" seq="1999-0671">
<status>Entry</status>
<desc>Buffer overflow in ToxSoft NextFTP client through CWD command.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/572">572</ref>
<ref source="XF">toxsoft-nextftp-cwd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0672" seq="1999-0672">
<status>Entry</status>
<desc>Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.</desc>
<refs>
<ref source="XF">fujitsu-topic-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/573">573</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0674" seq="1999-0674">
<status>Entry</status>
<desc>The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.</desc>
<refs>
<ref source="NETBSD">1999-011</ref>
<ref source="OPENBSD">Aug 9,1999</ref>
<ref source="FREEBSD">FreeBSD-SA-99:02</ref>
<ref source="BUGTRAQ">19990809 profil(2) bug, a simple test program</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/570">570</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-067.shtml">J-067</ref>
<ref source="XF">netbsd-profil</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0675" seq="1999-0675">
<status>Entry</status>
<desc>Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/23615">19990809 FW1 UDP Port 0 DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/576">576</ref>
<ref source="XF">checkpoint-port</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1038">1038</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0676" seq="1999-0676">
<status>Entry</status>
<desc>sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19990809134220.A1191@hades.chaoz.org">19990808 sdtcm_convert</ref>
<ref source="XF">sun-sdtcm-convert</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/575">575</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0678" seq="1999-0678">
<status>Entry</status>
<desc>A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.</desc>
<refs>
<ref source="XF">apache-debian-usrdoc</ref>
<ref source="BUGTRAQ">19990405 An issue with Apache on Debian</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/318">318</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0679" seq="1999-0679">
<status>Entry</status>
<desc>Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.</desc>
<refs>
<ref source="BUGTRAQ">19990813 w00w00's efnet ircd advisory (exploit included)</ref>
<ref source="CONFIRM" url="http://www.efnet.org/archive/servers/hybrid/ChangeLog">http://www.efnet.org/archive/servers/hybrid/ChangeLog</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/581">581</ref>
<ref source="XF">hybrid-ircd-minvite-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0680" seq="1999-0680">
<status>Entry</status>
<desc>Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-028.mspx">MS99-028</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238600">Q238600</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-057.shtml">J-057</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/571">571</ref>
<ref source="XF">nt-terminal-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0681" seq="1999-0681">
<status>Entry</status>
<desc>Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1999-q3/0381.html">19990807 Crash FrontPage Remotely...</ref>
<ref source="XF" url="http://xforce.iss.net/static/3117.php">frontpage-pws-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/568">568</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0682" seq="1999-0682">
<status>Entry</status>
<desc>Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-027.mspx">MS99-027</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237927">Q237927</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/567">567</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-056.shtml">J-056</ref>
<ref source="XF">exchange-relay</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0683" seq="1999-0683">
<status>Entry</status>
<desc>Denial of service in Gauntlet Firewall via a malformed ICMP packet.</desc>
<refs>
<ref source="XF">gauntlet-dos</ref>
<ref source="BUGTRAQ">19990729 Remotely Lock Up Gauntlet 5.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/556">556</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1029">1029</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0685" seq="1999-0685">
<status>Entry</status>
<desc>Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.</desc>
<refs>
<ref source="BUGTRAQ">19991209 Netscape communicator 4.06J, 4.5J-4.6J, 4.61e Buffer Overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/618">618</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0686" seq="1999-0686">
<status>Entry</status>
<desc>Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.</desc>
<refs>
<ref source="BUGTRAQ">19990514 TGAD DoS</ref>
<ref source="BUGTRAQ">19990610 Re: VVOS/Netscape Bug</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-098">HPSBUX9906-098</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-046.shtml">J-046</ref>
<ref source="XF">hp-tgad-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0687" seq="1999-0687">
<status>Entry</status>
<desc>The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Vulnerability in ttsession</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="COMPAQ">SSRT0617U_TTSESSION</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-001.shtml">K-001</ref>
<ref source="CERT">CA-99-11</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/637">637</ref>
<ref source="XF">cde-ttsession-rpc-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0688" seq="1999-0688">
<status>Entry</status>
<desc>Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-101">HPSBUX9907-101</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/545">545</ref>
<ref source="XF">hp-sd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0689" seq="1999-0689">
<status>Entry</status>
<desc>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Vulnerability in dtspcd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="CERT">CA-99-11</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1880">oval:org.mitre.oval:def:1880</ref>
<ref source="XF">cde-dtspcd-file-auth</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/636">636</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0690" seq="1999-0690">
<status>Entry</status>
<desc>HP CDE program includes the current directory in root's PATH variable.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-100">HPSBUX9907-100</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-053.shtml">J-053</ref>
<ref source="XF">hp-cde-directory</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0691" seq="1999-0691">
<status>Entry</status>
<desc>Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Vulnerability in dtaction</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="COMPAQ">SSRTO615U_DTACTION</ref>
<ref source="CERT">CA-99-11</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/635">635</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3078">oval:org.mitre.oval:def:3078</ref>
<ref source="XF">cde-dtaction-username-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0692" seq="1999-0692">
<status>Entry</status>
<desc>The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-99-09</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-052.shtml">J-052</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990701-01-P">19990701-01-P</ref>
<ref source="XF">sgi-arrayd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0693" seq="1999-0693">
<status>Entry</status>
<desc>Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-99-11</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/641">641</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4374">oval:org.mitre.oval:def:4374</ref>
<ref source="XF">cde-dtsession-env-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0694" seq="1999-0694">
<status>Entry</status>
<desc>Denial of service in AIX ptrace system call allows local users to crash the system.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-055.shtml">J-055</ref>
<ref source="IBM">ERS-SVA-E01-1999:002.1</ref>
<ref source="XF">aix-ptrace-halt</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0695" seq="1999-0695">
<status>Entry</status>
<desc>The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19990904 [Sybase] software vendors do not think about old bugs</ref>
<ref source="XF">http-powerdynamo-dotdotslash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/620">620</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1064">1064</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0696" seq="1999-0696">
<status>Entry</status>
<desc>Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).</desc>
<refs>
<ref source="BUGTRAQ">19990709 Exploit of rpc.cmsd</ref>
<ref source="SCO">SB-99.12</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/188">00188</ref>
<ref source="SUNBUG">4230754</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9908-102">HPSBUX9908-102</ref>
<ref source="COMPAQ">SSRT0614U_RPC_CMSD</ref>
<ref source="CERT">CA-99-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-051.shtml">J-051</ref>
<ref source="XF">sun-cmsd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0697" seq="1999-0697">
<status>Entry</status>
<desc>SCO Doctor allows local users to gain root privileges through a Tools option.</desc>
<refs>
<ref source="BUGTRAQ">19990908 SCO 5.0.5 /bin/doctor nightmare</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/621">621</ref>
<ref source="XF">sco-doctor-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0699" seq="1999-0699">
<status>Entry</status>
<desc>The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.</desc>
<refs>
<ref source="BUGTRAQ">19990908 [Security] Spoofed Id in Bluestone Sapphire/Web</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/623">623</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0700" seq="1999-0700">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237185">Q237185</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-026.mspx">MS99-026</ref>
<ref source="XF">nt-malformed-dialer</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0701" seq="1999-0701">
<status>Entry</status>
<desc>After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-036.mspx">MS99-036</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q173039">Q173039</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/626">626</ref>
<ref source="XF">nt-install-unattend-file</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0702" seq="1999-0702">
<status>Entry</status>
<desc>Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the &quot;ImportExportFavorites&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ">19990909 IE 5.0 security vulnerabilities - ImportExportFavorites - at least creating and overwriting files, probably executing programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-037.mspx">MS99-037</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241361">Q241361</ref>
<ref source="XF">ie5-import-export-favorites</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/627">627</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0703" seq="1999-0703">
<status>Entry</status>
<desc>OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.</desc>
<refs>
<ref source="BUGTRAQ">19990805 4.4 BSD issue -- chflags</ref>
<ref source="OPENBSD">Jul30,1999</ref>
<ref source="FREEBSD">FreeBSD-SA-99:01</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-066.shtml">J-066</ref>
<ref source="XF">openbsd-chflags-fchflags-permitted</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0704" seq="1999-0704">
<status>Entry</status>
<desc>Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.</desc>
<refs>
<ref source="REDHAT">RHSA-1999:032-01</ref>
<ref source="CALDERA">CSSA-1999:024.0</ref>
<ref source="FREEBSD">SA-99:06</ref>
<ref source="DEBIAN">19991018</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/614">614</ref>
<ref source="CERT">CA-99-12</ref>
<ref source="XF">amd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0705" seq="1999-0705">
<status>Entry</status>
<desc>Buffer overflow in INN inews program.</desc>
<refs>
<ref source="XF">inn-inews-bo</ref>
<ref source="REDHAT">RHSA1999033_01</ref>
<ref source="CALDERA">CSSA-1999-026</ref>
<ref source="SUSE">19990831 Security hole in INN</ref>
<ref source="DEBIAN">19990907</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/616">616</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0706" seq="1999-0706">
<status>Entry</status>
<desc>Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.</desc>
<refs>
<ref source="DEBIAN">19990807</ref>
<ref source="SUSE">19990817 Security hole in i4l (xmonisdn)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/583">583</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0707" seq="1999-0707">
<status>Entry</status>
<desc>The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-099">HPSBUX9906-099</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-050.shtml">J-050</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/493">493</ref>
<ref source="XF">hp-visualize-conference-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0708" seq="1999-0708">
<status>Entry</status>
<desc>Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.</desc>
<refs>
<ref source="BUGTRAQ">19990921 BP9909-00: cfingerd local buffer overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/651">651</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0710" seq="1999-0710">
<status>Entry</status>
<desc>The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.</desc>
<refs>
<ref source="BUGTRAQ">19990725 Redhat 6.0 cachemgr.cgi lameness</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid">http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-576">DSA-576</ref>
<ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref>
<ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-025.html">RHSA-1999:025</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-489.html">RHSA-2005:489</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2059">2059</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2385">http-cgi-cachemgr(2385)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0711" seq="1999-0711">
<status>Entry</status>
<desc>The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?t=92550157100002&amp;w=2&amp;r=1">19990430 *Huge* security hole in Oracle 8.0.5 with Intellegent agent installed</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92609807906778&amp;w=2">19990506 Oracle Security Followup, patch and FAQ: setuid on oratclsh</ref>
<ref source="XF">oracle-oratclsh</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0713" seq="1999-0713">
<status>Entry</status>
<desc>The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">19990404 Digital Unix 4.0E /var permission</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-044.shtml">J-044</ref>
<ref source="XF">cde-dtlogin</ref>
<ref source="COMPAQ">SSRT0600U</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0714" seq="1999-0714">
<status>Entry</status>
<desc>Vulnerability in Compaq Tru64 UNIX edauth command.</desc>
<refs>
<ref source="COMPAQ">SSRT0588U</ref>
<ref source="XF">du-edauth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0715" seq="1999-0715">
<status>Entry</status>
<desc>Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.</desc>
<refs>
<ref source="BUGTRAQ">19990519 Buffer Overruns in RAS allows execution of arbitary code as system</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-016.mspx">MS99-016</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230677">Q230677</ref>
<ref source="XF">nt-ras-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0716" seq="1999-0716">
<status>Entry</status>
<desc>Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.</desc>
<refs>
<ref source="XF">nt-helpfile-bo</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231605">Q231605</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-015.asp">MS99-015</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0717" seq="1999-0717">
<status>Entry</status>
<desc>A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-014.mspx">MS99-014</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231304">Q231304</ref>
<ref source="XF">excel-virus-warning</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0718" seq="1999-0718">
<status>Entry</status>
<desc>IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9908&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5534">19990823 IBM Gina security warning</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/608">608</ref>
<ref source="XF" url="http://xforce.iss.net/static/3166.php">ibm-gina-group-add</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0719" seq="1999-0719">
<status>Entry</status>
<desc>The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.</desc>
<refs>
<ref source="BUGTRAQ">19990802 Gnumeric potential security hole.</ref>
<ref source="REDHAT">RHSA-1999:023-01</ref>
<ref source="XF">gnu-guile-plugin-export</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/563">563</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0720" seq="1999-0720">
<status>Entry</status>
<desc>The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=lcamtuf.4.05.9907041223290.355-300000@nimue.ids.pl">19990823 [Linux] glibc 2.1.x / wu-ftpd &lt;=2.5 / BeroFTPD / lynx / vlock / mc / glibc 2.0.x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/597">597</ref>
<ref source="XF">linux-pt-chown</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0721" seq="1999-0721">
<status>Entry</status>
<desc>Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.</desc>
<refs>
<ref source="BINDVIEW">Phantom Technical Advisory</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231457">Q231457</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-020.mspx">MS99-020</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref>
<ref source="XF">msrpc-lsa-lookupnames-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0722" seq="1999-0722">
<status>Entry</status>
<desc>The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.</desc>
<refs>
<ref source="CERT">CA-99-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/558">558</ref>
<ref source="XF">cobalt-raq2-default-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0723" seq="1999-0723">
<status>Entry</status>
<desc>The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.</desc>
<refs>
<ref source="NTBUGTRAQ">19990411 Death by MessageBox</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-021.mspx">MS99-021</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233323">Q233323</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/478">478</ref>
<ref source="XF">nt-csrss-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0724" seq="1999-0724">
<status>Entry</status>
<desc>Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.</desc>
<refs>
<ref source="OPENBSD">Aug12,1999</ref>
<ref source="XF">openbsd-uio_offset-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6128">6128</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0725" seq="1999-0725">
<status>Entry</status>
<desc>When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. &quot;Double Byte Code Page&quot;.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q233335">Q233335</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-022.mspx">MS99-022</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/477">477</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2302">iis-double-byte-code-page(2302)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0726" seq="1999-0726">
<status>Entry</status>
<desc>An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-023.mspx">MS99-023</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234557">Q234557</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/499">499</ref>
<ref source="XF">nt-malformed-image-header</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0727" seq="1999-0727">
<status>Entry</status>
<desc>A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.</desc>
<refs>
<ref source="OPENBSD">19990608 Packets that should have been handled by IPsec may be transmitted as cleartext</ref>
<ref source="XF">openbsd-ipsec-cleartext</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6127">6127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0728" seq="1999-0728">
<status>Entry</status>
<desc>A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-024.mspx">MS99-024</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q236359">Q236359</ref>
<ref source="XF">nt-ioctl-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0729" seq="1999-0729">
<status>Entry</status>
<desc>Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise34.php">19990823 Denial of Service Attack against Lotus Notes Domino Server 4.6</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-061.shtml">J-061</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/601">601</ref>
<ref source="XF">lotus-ldap-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1057">1057</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0730" seq="1999-0730">
<status>Entry</status>
<desc>The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.</desc>
<refs>
<ref source="DEBIAN">19990612</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0731" seq="1999-0731">
<status>Entry</status>
<desc>The KDE klock program allows local users to unlock a session using malformed input.</desc>
<refs>
<ref source="BUGTRAQ">19990623 Security flaw in klock</ref>
<ref source="CALDERA">CSSA-1999:017</ref>
<ref source="SUSE">19990629 Security hole in Klock</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/489">489</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0732" seq="1999-0732">
<status>Entry</status>
<desc>The logging facilitity of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.</desc>
<refs>
<ref source="DEBIAN">19990823b</ref>
<ref source="XF">smtp-refuser-tmp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0733" seq="1999-0733">
<status>Entry</status>
<desc>Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19990626 VMWare Advisory - buffer overflows</ref>
<ref source="BUGTRAQ">19990626 VMware Security Alert</ref>
<ref source="BUGTRAQ">19990705 Re: VMWare Advisory.. - exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/490">490</ref>
<ref source="XF">vmware-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0734" seq="1999-0734">
<status>Entry</status>
<desc>A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.</desc>
<refs>
<ref source="CISCO"> CiscoSecure Access Control Server for UNIX Remote Administration Vulnerability</ref>
<ref source="XF">ciscosecure-read-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0735" seq="1999-0735">
<status>Entry</status>
<desc>KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.</desc>
<refs>
<ref source="ISS">KDE K-Mail File Creation Vulnerability</ref>
<ref source="CALDERA">CSSA-1999:016</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA1999015_01.html">RHSA-1999:015-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/300">300</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0740" seq="1999-0740">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/594">594</ref>
<ref source="XF">linux-telnetd-term</ref>
<ref source="CALDERA">CSSA-1999:022</ref>
<ref source="REDHAT">RHSA1999029_01</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0742" seq="1999-0742">
<status>Entry</status>
<desc>The Debian mailman package uses weak authentication, which allows attackers to gain privileges.</desc>
<refs>
<ref source="DEBIAN">19990623</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/480">480</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0743" seq="1999-0743">
<status>Entry</status>
<desc>Trn allows local users to overwrite other users' files via symlinks.</desc>
<refs>
<ref source="BUGTRAQ">19990819 Insecure use of file in /tmp by trn</ref>
<ref source="DEBIAN">19990823c</ref>
<ref source="SUSE">19990824 Security hole in trn</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3144">trn-symlinks(3144)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0744" seq="1999-0744">
<status>Entry</status>
<desc>Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.</desc>
<refs>
<ref source="ISS">Buffer Overflow in Netscape Enterprise and FastTrack Web Servers</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/603">603</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0745" seq="1999-0745">
<status>Entry</status>
<desc>Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.</desc>
<refs>
<ref source="IBM">ERS-SVA-E01-1999:003.1</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-059.shtml">J-059</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/590">590</ref>
<ref source="XF">aix-pdnsd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0746" seq="1999-0746">
<status>Entry</status>
<desc>A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">19990814 DOS against SuSE's identd</ref>
<ref source="SUSE">19990824 Security hole in netcfg</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/587">587</ref>
<ref source="XF">suse-identd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0747" seq="1999-0747">
<status>Entry</status>
<desc>Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSI.4.10.9908170253560.19291-100000@saturn.psn.net">19990816 Symmetric Multiprocessing (SMP) Vulnerbility in BSDi 4.0.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/589">589</ref>
<ref source="XF">bsdi-smp-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0749" seq="1999-0749">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.</desc>
<refs>
<ref source="BUGTRAQ">19990815 telnet.exe heap overflow - remotely exploitable</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-033.mspx">MS99-033</ref>
<ref source="XF">win-ie5-telnet-heap-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/586">586</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0751" seq="1999-0751">
<status>Entry</status>
<desc>Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Accept overflow on Netscape Enterprise Server 3.6 SP2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/631">631</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3256">netscape-accept-bo(3256)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0752" seq="1999-0752">
<status>Entry</status>
<desc>Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.</desc>
<refs>
<ref source="BUGTRAQ">19990706 Netscape Enterprise Server SSL Handshake Bug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0753" seq="1999-0753">
<status>Entry</status>
<desc>The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.</desc>
<refs>
<ref source="BUGTRAQ">19990817 Stupid bug in W3-msql</ref>
<ref source="XF">mini-sql-w3-msql-cgi</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/591">591</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0754" seq="1999-0754">
<status>Entry</status>
<desc>The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19990511 INN 2.0 and higher. Root compromise potential</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-011.0.txt">CSSA-1999-011.0</ref>
<ref source="SUSE">19990518 Security hole in INN</ref>
<ref source="MISC" url="http://www.redhat.com/corp/support/errata/inn99_05_22.html">http://www.redhat.com/corp/support/errata/inn99_05_22.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/255">255</ref>
<ref source="XF">inn-innconf-env</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0755" seq="1999-0755">
<status>Entry</status>
<desc>Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the &quot;Save password&quot; option.</desc>
<refs>
<ref source="XF">nt-ras-pwcache</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q230681">Q230681</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-017.mspx">MS99-017</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0756" seq="1999-0756">
<status>Entry</status>
<desc>ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=10968&amp;Method=Full">ASB99-07</ref>
<ref source="XF" url="http://xforce.iss.net/static/2207.php">coldfusion-admin-dos(2207)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0758" seq="1999-0758">
<status>Entry</status>
<desc>Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL.</desc>
<refs>
<ref source="ALLAIRE">ASB99-06</ref>
<ref source="XF">netscape-space-view</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0759" seq="1999-0759">
<status>Entry</status>
<desc>Buffer overflow in FuseMAIL POP service via long USER and PASS commands.</desc>
<refs>
<ref source="BUGTRAQ">19990913 Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug</ref>
<ref source="CONFIRM" url="http://www.crosswinds.net/~fuseware/faq.html#8">http://www.crosswinds.net/~fuseware/faq.html#8</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/634">634</ref>
<ref source="XF">fuseware-popmail-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0760" seq="1999-0760">
<status>Entry</status>
<desc>Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=11714&amp;Method=Full">ASB99-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/550">550</ref>
<ref source="XF" url="http://xforce.iss.net/static/3288.php">coldfusion-server-cfml-tags</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0761" seq="1999-0761">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-99:05</ref>
<ref source="XF">freebsd-fts-lib-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/644">644</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1074">1074</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0762" seq="1999-0762">
<status>Entry</status>
<desc>When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the &quot;about&quot; protocol to gain access to browser information.</desc>
<refs>
<ref source="XF">netscape-title</ref>
<ref source="BUGTRAQ">19990524 Netscape Communicator JavaScript in &lt;TITLE&gt; security vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0763" seq="1999-0763">
<status>Entry</status>
<desc>NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network.</desc>
<refs>
<ref source="NETBSD">1999-010</ref>
<ref source="XF">netbsd-arp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6540">6540</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0764" seq="1999-0764">
<status>Entry</status>
<desc>NetBSD allows ARP packets to overwrite static ARP entries.</desc>
<refs>
<ref source="NETBSD">1999-010</ref>
<ref source="XF">netbsd-arp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6539">6539</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0765" seq="1999-0765">
<status>Entry</status>
<desc>SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.</desc>
<refs>
<ref source="BUGTRAQ">19990619 IRIX midikeys root exploit.</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990501-01-A">19990501-01-A</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/262">262</ref>
<ref source="XF">irix-midikeys</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0766" seq="1999-0766">
<status>Entry</status>
<desc>The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-031.mspx">MS99-031</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q240346">Q240346</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/600">600</ref>
<ref source="XF">msvm-verifier-java</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0768" seq="1999-0768">
<status>Entry</status>
<desc>Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/602">602</ref>
<ref source="REDHAT">RHSA-1999:030-02</ref>
<ref source="SUSE">19990829 Security hole in cron</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0769" seq="1999-0769">
<status>Entry</status>
<desc>Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.</desc>
<refs>
<ref source="REDHAT">RHSA-1999:030-02</ref>
<ref source="CALDERA">CSSA-1999:023.0</ref>
<ref source="SUSE">19990829 Security hole in cron</ref>
<ref source="DEBIAN">19990830 cron</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/611">611</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0770" seq="1999-0770">
<status>Entry</status>
<desc>Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.</desc>
<refs>
<ref source="BUGTRAQ">19990729 Simple DOS attack on FW-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/549">549</ref>
<ref source="CHECKPOINT">ACK DOS ATTACK</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1027">1027</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0771" seq="1999-0771">
<status>Entry</status>
<desc>The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19990526 Infosec.19990526.compaq-im.a</ref>
<ref source="COMPAQ">SSRT0612U</ref>
<ref source="XF">management-agent-file-read</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0772" seq="1999-0772">
<status>Entry</status>
<desc>Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.</desc>
<refs>
<ref source="BUGTRAQ">19990527 Re: Infosec.19990526.compaq-im.a (New DoS and correction to my previous post)</ref>
<ref source="COMPAQ">SSRT0612U</ref>
<ref source="XF">management-agent-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0773" seq="1999-0773">
<status>Entry</status>
<desc>Buffer overflow in Solaris lpset program allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.netspace.org/cgi-bin/wa?A2=ind9905B&amp;L=bugtraq&amp;P=R2017">19990511 Solaris2.6 and 2.7 lpset overflow</ref>
<ref source="XF">sol-lpset-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0774" seq="1999-0774">
<status>Entry</status>
<desc>Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.</desc>
<refs>
<ref source="BUGTRAQ">19990830 Babcia Padlina Ltd. security advisory: mars_nwe buffer overf</ref>
<ref source="REDHAT">RHSA1999037_01</ref>
<ref source="SUSE">19990916 Security hole in mars nwe</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/617">617</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0775" seq="1999-0775">
<status>Entry</status>
<desc>Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the &quot;established&quot; keyword in an access list.</desc>
<refs>
<ref source="CISCO">19990610 Cisco IOS Software established Access List Keyword Error</ref>
<ref source="XF">cisco-gigaswitch</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0777" seq="1999-0777">
<status>Entry</status>
<desc>IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have &quot;No Access&quot; permissions.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp">MS99-039</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241407">Q241407</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242559">Q242559</ref>
<ref source="XF">iis-ftp-no-access-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/658">658</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0778" seq="1999-0778">
<status>Entry</status>
<desc>Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.</desc>
<refs>
<ref source="BUGTRAQ">19990626 KSR[T] #011: Accelerated-X</ref>
<ref source="KSRT">011</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/488">488</ref>
<ref source="XF">accelx-display-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0779" seq="1999-0779">
<status>Entry</status>
<desc>Denial of service in HP-UX SharedX recserv program.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9810-086">HPSBUX9810-086</ref>
<ref source="XF">hp-sharedx</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0780" seq="1999-0780">
<status>Entry</status>
<desc>KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF">kde-klock-process-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0781" seq="1999-0781">
<status>Entry</status>
<desc>KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF">kde-klock-bindir-trojans</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0782" seq="1999-0782">
<status>Entry</status>
<desc>KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref>
<ref source="XF">kde-kppp-directory-create</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0783" seq="1999-0783">
<status>Entry</status>
<desc>FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:05</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-057.shtml">I-057</ref>
<ref source="XF">freebsd-nfs-link-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6090">6090</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0785" seq="1999-0785">
<status>Entry</status>
<desc>The INN inndstart program allows local users to gain root privileges via the &quot;pathrun&quot; parameter in the inn.conf file.</desc>
<refs>
<ref source="BUGTRAQ">19990511 INN 2.0 and higher. Root compromise potential</ref>
<ref source="SUSE">19990518 Security hole in INN</ref>
<ref source="XF">inn-pathrun</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/254">254</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0786" seq="1999-0786">
<status>Entry</status>
<desc>The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19990922 LD_PROFILE local root exploit for solaris 2.6</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/659">659</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0787" seq="1999-0787">
<status>Entry</status>
<desc>The SSH authentication agent follows symlinks via a UNIX domain socket.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93760201002154&amp;w=2">19990917 A few bugs...</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93832856804415&amp;w=2">19990924 [Fwd: Truth about ssh 1.2.27 vulnerability]</ref>
<ref source="XF">ssh-socket-auth-symlink-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/660">660</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0788" seq="1999-0788">
<status>Entry</status>
<desc>Arkiea nlservd allows remote attackers to conduct a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837184228248&amp;w=2">19990924 Multiple vendor Knox Arkiea local root/remote DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/662">662</ref>
<ref source="XF">arkiea-backup-nlserverd-remote-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0789" seq="1999-0789">
<status>Entry</status>
<desc>Buffer overflow in AIX ftpd in the libc library.</desc>
<refs>
<ref source="BUGTRAQ">19990928 Remote bufferoverflow exploit for ftpd from AIX 4.3.2 running on an RS6000</ref>
<ref source="IBM">ERS-SVA-E01-1999:004.1</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-072.shtml">J-072</ref>
<ref source="XF">aix-ftpd-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/679">679</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0790" seq="1999-0790">
<status>Entry</status>
<desc>A remote attacker can read information from a Netscape user's cache via JavaScript.</desc>
<refs>
<ref source="MISC" url="http://home.netscape.com/security/notes/jscachebrowsing.html">http://home.netscape.com/security/notes/jscachebrowsing.html</ref>
<ref source="XF">netscape-javascript</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0791" seq="1999-0791">
<status>Entry</status>
<desc>Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol.</desc>
<refs>
<ref source="BUGTRAQ">19991006 KSR[T] Advisories #012: Hybrid Network's Cable Modems</ref>
<ref source="KSRT">012</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/695">695</ref>
<ref source="XF">hybrid-anon-cable-modem-reconfig</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0793" seq="1999-0793">
<status>Entry</status>
<desc>Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-043.mspx">MS99-043</ref>
<ref source="XF">ie-java-redirect</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0794" seq="1999-0794">
<status>Entry</status>
<desc>Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-044.mspx">MS99-044</ref>
<ref source="XF">excel-sylk</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241900">Q241900</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241901">Q241901</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q241902">Q241902</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0796" seq="1999-0796">
<status>Entry</status>
<desc>FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks.</desc>
<refs>
<ref source="FREEBSD">SA-98.03</ref>
<ref source="XF">freebsd-ttcp-spoof</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6089">6089</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0797" seq="1999-0797">
<status>Entry</status>
<desc>NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.</desc>
<refs>
<ref source="ISS">19980629 Distributed DoS attack against NIS/NIS+ based networks.</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-070.shtml">I-070</ref>
<ref source="XF">sun-nis-nisplus</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0799" seq="1999-0799">
<status>Entry</status>
<desc>Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.</desc>
<refs>
<ref source="BUGTRAQ">19970725 Exploitable buffer overflow in bootpd (most unices)</ref>
<ref source="XF">bootpd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0800" seq="1999-0800">
<status>Entry</status>
<desc>The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=9602&amp;Method=Full">ASB99-05</ref>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00332.html">19990211 ACFUG List: Alert: Allaire Forums GetFile bug</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1748">allaire-forums-file-read(1748)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/944">944</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0801" seq="1999-0801">
<status>Entry</status>
<desc>BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2075.php">bmc-patrol-frames(2075)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0802" seq="1999-0802">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.</desc>
<refs>
<ref source="BUGTRAQ">19990503 MSIE 5 FAVICON BUG</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx">MS99-018</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231450">Q231450</ref>
<ref source="XF">ie-favicon</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0803" seq="1999-0803">
<status>Entry</status>
<desc>The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92765973207648&amp;w=2">19990525 IBM eNetwork Firewall for AIX</ref>
<ref source="XF">ibm-enfirewall-tmpfiles</ref>
<ref source="OSVDB" url="http://www.osvdb.org/962">962</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0804" seq="1999-0804">
<status>Entry</status>
<desc>Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.</desc>
<refs>
<ref source="BUGTRAQ">19990601 Linux kernel 2.2.x vulnerability/exploit</ref>
<ref source="DEBIAN">19990607</ref>
<ref source="CALDERA">CSSA-1999:013</ref>
<ref source="SUSE">19990602 Denial of Service on the 2.2 kernel</ref>
<ref source="REDHAT">19990603 Kernel Update</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/302">302</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0806" seq="1999-0806">
<status>Entry</status>
<desc>Buffer overflow in Solaris dtprintinfo program.</desc>
<refs>
<ref source="BUGTRAQ">19990510 Solaris2.6,2.7 dtprintinfo exploits</ref>
<ref source="XF">cde-dtprintinfo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6552">6552</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0807" seq="1999-0807">
<status>Entry</status>
<desc>The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.</desc>
<refs>
<ref source="XF">netscape-dirsvc-password</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0809" seq="1999-0809">
<status>Entry</status>
<desc>Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to &quot;Only accept cookies originating from the same server as the page being viewed&quot;.</desc>
<refs>
<ref source="BUGTRAQ">19990709 Communicator 4.[56]x, JavaScript used to bypass cookie settings</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0810" seq="1999-0810">
<status>Entry</status>
<desc>Denial of service in Samba NETBIOS name service daemon (nmbd).</desc>
<refs>
<ref source="BUGTRAQ">19990721 Samba 2.0.5 security fixes</ref>
<ref source="CALDERA">CSSA-1999:018.0</ref>
<ref source="DEBIAN">19990731</ref>
<ref source="DEBIAN">19990804</ref>
<ref source="REDHAT">RHSA-1999:022-02</ref>
<ref source="SUSE">19990816 Security hole in Samba</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0811" seq="1999-0811">
<status>Entry</status>
<desc>Buffer overflow in Samba smbd program via a malformed message command.</desc>
<refs>
<ref source="BUGTRAQ">19990721 Samba 2.0.5 security fixes</ref>
<ref source="REDHAT">RHSA-1999:022-02</ref>
<ref source="CALDERA">CSSA-1999:018.0</ref>
<ref source="SUSE">19990816 Security hole in Samba</ref>
<ref source="DEBIAN">19990731 Samba</ref>
<ref source="XF">samba-message-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/536">536</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0812" seq="1999-0812">
<status>Entry</status>
<desc>Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.</desc>
<refs>
<ref source="BUGTRAQ">19990721 Samba 2.0.5 security fixes</ref>
<ref source="DEBIAN">19990731</ref>
<ref source="DEBIAN">19990804</ref>
<ref source="CALDERA">CSSA-1999:018.0</ref>
<ref source="REDHAT">RHSA-1999:022-02</ref>
<ref source="SUSE">19990816 Security hole in Samba</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0813" seq="1999-0813">
<status>Entry</status>
<desc>Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">19990810 Severe bug in cfingerd before 1.4.0</ref>
<ref source="BUGTRAQ">19980724 CFINGERD root security hole</ref>
<ref source="DEBIAN">19990814</ref>
<ref source="XF">cfingerd-privileges</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0814" seq="1999-0814">
<status>Entry</status>
<desc>Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-027.html">RHSA-1999:027</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0815" seq="1999-0815">
<status>Entry</status>
<desc>Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q196/2/70.asp">Q196270</ref>
<ref source="XF" url="http://xforce.iss.net/static/1974.php">nt-snmpagent-leak(1974)</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:952">oval:org.mitre.oval:def:952</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0817" seq="1999-0817">
<status>Entry</status>
<desc>Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.</desc>
<refs>
<ref source="SUSE">19990915 Security hole in lynx</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0819" seq="1999-0819">
<status>Entry</status>
<desc>NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.</desc>
<refs>
<ref source="NTBUGTRAQ">19991130 NTmail and VRFY</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94398141118586&amp;w=2">19991130 NTmail and VRFY</ref>
<ref source="XF">nt-mail-vrfy</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0820" seq="1999-0820">
<status>Entry</status>
<desc>FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/838">838</ref>
<ref source="XF">freebsd-seyon-dir-add</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5996">5996</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0823" seq="1999-0823">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/839">839</ref>
<ref source="XF">freebsd-xmindpath</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1150">1150</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0824" seq="1999-0824">
<status>Entry</status>
<desc>A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/833">833</ref>
<ref source="NTBUGTRAQ">19991130 SUBST problem</ref>
<ref source="BUGTRAQ">19991130 Subst.exe carelessness (fwd)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0826" seq="1999-0826">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD angband allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Several FreeBSD-3.3 vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/840">840</ref>
<ref source="XF">angband-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1151">1151</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0831" seq="1999-0831">
<status>Entry</status>
<desc>Denial of service in Linux syslogd via a large number of connections.</desc>
<refs>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-035.0.txt">CSSA-1999-035.0</ref>
<ref source="REDHAT">RHSA1999055-01</ref>
<ref source="SUSE">19991118 syslogd-1.3.33 (a1)</ref>
<ref source="BUGTRAQ">19991130 [david@slackware.com: New Patches for Slackware 4.0 Available]</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/809">809</ref>
<ref source="XF">slackware-syslogd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0832" seq="1999-0832">
<status>Entry</status>
<desc>Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.20.9911091058140.12964-100000@mail.zigzag.pl">19991109 undocumented bugs - nfsd</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/1999/19991111">19991111 buffer overflow in nfs server</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_29.html">19991110 Security hole in nfs-server &lt; 2.2beta47 within nkita</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-033.0.txt">CSSA-1999-033.0</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/rh42-errata-general.html#NFS">RHSA-1999:053-01</ref>
<ref source="BUGTRAQ">19991130 [david@slackware.com: New Patches for Slackware 4.0 Available]</ref>
<ref source="XF">linux-nfs-maxpath-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/782">782</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0833" seq="1999-0833">
<status>Entry</status>
<desc>Buffer overflow in BIND 8.2 via NXT records.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-nxt-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0834" seq="1999-0834">
<status>Entry</status>
<desc>Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.</desc>
<refs>
<ref source="BUGTRAQ">19991201 Security Advisory: Buffer overflow in RSAREF2</ref>
<ref source="BUGTRAQ">19991202 OpenBSD sslUSA26 advisory (Re: CORE-SDI: Buffer overflow in RSAREF2)</ref>
<ref source="CERT">CA-99-15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/843">843</ref>
<ref source="XF">rsaref-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0835" seq="1999-0835">
<status>Entry</status>
<desc>Denial of service in BIND named via malformed SIG records.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="XF">bind-sigrecord-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0836" seq="1999-0836">
<status>Entry</status>
<desc>UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991202160111.20553.qmail@nwcst282.netaddress.usa.net">19991202 UnixWare 7 uidadmin exploit + discussion</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.22a">SB-99.22a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/842">842</ref>
<ref source="XF">unixware-uid-admin</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0837" seq="1999-0837">
<status>Entry</status>
<desc>Denial of service in BIND by improperly closing TCP sessions via so_linger.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="XF">bind-solinger-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0838" seq="1999-0838">
<status>Entry</status>
<desc>Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.</desc>
<refs>
<ref source="BUGTRAQ">19991202 Remote DoS Attack in Serv-U FTP-Server v2.5a Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/859">859</ref>
<ref source="XF">servu-ftp-site-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0839" seq="1999-0839">
<status>Entry</status>
<desc>Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.</desc>
<refs>
<ref source="NTBUGTRAQ">19991130 Windows NT Task Scheduler vulnerability allows user to administrator elevation</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-051.mspx">MS99-051</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246972">Q246972</ref>
<ref source="XF">ie-task-scheduler-privs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/828">828</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0842" seq="1999-0842">
<status>Entry</status>
<desc>Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="NTBUGTRAQ">19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEAFCBAA.labs@ussrback.com">19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/827">827</ref>
<ref source="XF">symantec-mail-dir-traversal</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1144">1144</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0847" seq="1999-0847">
<status>Entry</status>
<desc>Buffer overflow in free internet chess server (FICS) program, xboard.</desc>
<refs>
<ref source="BUGTRAQ">19991129 FICS buffer overflow</ref>
<ref source="XF">fics-board-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0848" seq="1999-0848">
<status>Entry</status>
<desc>Denial of service in BIND named via consuming more than &quot;fdmax&quot; file descriptors.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-fdmax-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0849" seq="1999-0849">
<status>Entry</status>
<desc>Denial of service in BIND named via maxdname.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-maxdname-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0851" seq="1999-0851">
<status>Entry</status>
<desc>Denial of service in BIND named via naptr.</desc>
<refs>
<ref source="SUSE">19991111 Security hole in bind8 &lt; 8.2.2p2 and bind4 &lt; 4.9.7-REL</ref>
<ref source="DEBIAN">19991116 Denial of service vulnerabilities in bind</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref>
<ref source="REDHAT">RHSA-1999:054-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref>
<ref source="CERT">CA-99-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref>
<ref source="XF">bind-naptr-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0853" seq="1999-0853">
<status>Entry</status>
<desc>Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/847">847</ref>
<ref source="ISS">19991201 Buffer Overflow in Netscape Enterprise and FastTrack Authentication Procedure</ref>
<ref source="XF">netscape-fasttrack-auth-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0854" seq="1999-0854">
<status>Entry</status>
<desc>Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Ultimate Bulletin Board v5.3x? Bug</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl">20000225 FW: Important UBB News For Licensed Users</ref>
<ref source="CONFIRM" url="http://www.ultimatebb.com/home/versions.shtml">http://www.ultimatebb.com/home/versions.shtml</ref>
<ref source="XF">http-ultimate-bbs</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0856" seq="1999-0856">
<status>Entry</status>
<desc>login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.</desc>
<refs>
<ref source="BUGTRAQ">19991202 Slackware 7.0 - login bug</ref>
<ref source="XF">slackware-remote-login</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0858" seq="1999-0858">
<status>Entry</status>
<desc>Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-054.mspx">MS99-054</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q247333">Q247333</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/846">846</ref>
<ref source="XF">ie-wpad-proxy-settings</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0859" seq="1999-0859">
<status>Entry</status>
<desc>Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.</desc>
<refs>
<ref source="BUGTRAQ">19991130 Solaris 2.x chkperm/arp vulnerabilities</ref>
<ref source="SUNBUG">4296166</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/837">837</ref>
<ref source="XF">sol-arp-parse</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6994">6994</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0861" seq="1999-0861">
<status>Entry</status>
<desc>Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-053.mspx">MS99-053</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q244613">Q244613</ref>
<ref source="XF">iis-ssl-isapi-filter</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0864" seq="1999-0864">
<status>Entry</status>
<desc>UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991203020720.13115.qmail@nwcst289.netaddress.usa.net">19991202 UnixWare coredumps follow symlinks</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref>
<ref source="XF">sco-coredump-symlink</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/851">851</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0865" seq="1999-0865">
<status>Entry</status>
<desc>Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94426440413027&amp;w=2">19991203 CommuniGatePro 3.1 for NT DoS</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94454565726775&amp;w=2">19991203 CommuniGatePro 3.1 for NT Buffer Overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/860">860</ref>
<ref source="XF">communigate-pro-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0866" seq="1999-0866">
<status>Entry</status>
<desc>Buffer overflow in UnixWare xauto program allows local users to gain root privilege.</desc>
<refs>
<ref source="BUGTRAQ">19991203 UnixWare gain root with non-su/gid binaries</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.24a">SB-99.24a</ref>
<ref source="XF">sco-xauto-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/848">848</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0867" seq="1999-0867">
<status>Entry</status>
<desc>Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-029.mspx">MS99-029</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238349">Q238349</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-058.shtml">J-058</ref>
<ref source="XF">http-iis-malformed-header</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/579">579</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0868" seq="1999-0868">
<status>Entry</status>
<desc>ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.</desc>
<refs>
<ref source="CERT">CA-97.08</ref>
<ref source="XF">inn-ucbmail-shell-meta</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0869" seq="1999-0869">
<status>Entry</status>
<desc>Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-020.mspx">MS98-020</ref>
<ref source="MSKB">167614</ref>
<ref source="XF">http-frame-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0870" seq="1999-0870">
<status>Entry</status>
<desc>Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-015.mspx">MS98-015</ref>
<ref source="MSKB">169245</ref>
<ref source="XF">ie-usp-cuartango</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0871" seq="1999-0871">
<status>Entry</status>
<desc>Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the &quot;Cross Frame Navigate&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-013.mspx">MS98-013</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7837">7837</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3668">ie-crossframe-file-read(3668)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0873" seq="1999-0873">
<status>Entry</status>
<desc>Buffer overflow in Skyfull mail server via MAIL FROM command.</desc>
<refs>
<ref source="BID" url="http://www.securityfocus.com/bid/759">759</ref>
<ref source="XF">skyfull-mail-from-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0874" seq="1999-0874">
<status>Entry</status>
<desc>Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-019.asp">MS99-019</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q234905">Q234905</ref>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD06081999.html">AD06081999</ref>
<ref source="CERT">CA-99-07</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-048.shtml">J-048</ref>
<ref source="XF">iis-htr-overflow</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:915">oval:org.mitre.oval:def:915</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0875" seq="1999-0875">
<status>Entry</status>
<desc>DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.</desc>
<refs>
<ref source="L0PHT">19990811</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q216141">Q216141</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/578">578</ref>
<ref source="XF">irdp-gateway-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0876" seq="1999-0876">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 4.0 via EMBED tag.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q185959">Q185959</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0877" seq="1999-0877">
<status>Entry</status>
<desc>Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243638">Q243638</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-042.mspx">MS99-042</ref>
<ref source="XF">ie-iframe-exec</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0878" seq="1999-0878">
<status>Entry</status>
<desc>Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.</desc>
<refs>
<ref source="COMPAQ">SSRT0622</ref>
<ref source="REDHAT">RHSA1999031_01</ref>
<ref source="AUSCERT">AA-1999.01</ref>
<ref source="CERT">CA-99-13</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/599">599</ref>
<ref source="XF">wu-ftpd-dir-name</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0879" seq="1999-0879">
<status>Entry</status>
<desc>Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.</desc>
<refs>
<ref source="CERT">CA-99-13</ref>
<ref source="XF">wuftp-message-file-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0880" seq="1999-0880">
<status>Entry</status>
<desc>Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.</desc>
<refs>
<ref source="CERT">CA-99-13</ref>
<ref source="XF">wuftp-site-newer-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0881" seq="1999-0881">
<status>Entry</status>
<desc>Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991025 Falcon Web Server</ref>
<ref source="BINDVIEW">Falcon Web Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/743">743</ref>
<ref source="XF">falcon-path-parsing</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1127">1127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0883" seq="1999-0883">
<status>Entry</status>
<desc>Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine.</desc>
<refs>
<ref source="BUGTRAQ">19991024 RFP9905: Zeus webserver remote root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1126">1126</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3380">zeus-remote-root(3380)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0884" seq="1999-0884">
<status>Entry</status>
<desc>The Zeus web server administrative interface uses weak encryption for its passwords.</desc>
<refs>
<ref source="BUGTRAQ">19991024 RFP9905: Zeus webserver remote root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8186">8186</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3833">zeus-weak-password(3833)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0886" seq="1999-0886">
<status>Entry</status>
<desc>The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242294">Q242294</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-041.mspx">MS99-041</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/645">645</ref>
<ref source="XF">nt-rasman-pathname</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0887" seq="1999-0887">
<status>Entry</status>
<desc>FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991104 FTGate Version 2.1 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1137">1137</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0888" seq="1999-0888">
<status>Entry</status>
<desc>dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.</desc>
<refs>
<ref source="BUGTRAQ">19990817 Security Bug in Oracle</ref>
<ref source="XF">oracle-dbsnmp</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/585">585</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0889" seq="1999-0889">
<status>Entry</status>
<desc>Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.</desc>
<refs>
<ref source="BUGTRAQ">19990810 Cisco 675 password nonsense</ref>
<ref source="XF">cisco-cbos-telnet</ref>
<ref source="OSVDB" url="http://www.osvdb.org/39">39</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0890" seq="1999-0890">
<status>Entry</status>
<desc>iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.</desc>
<refs>
<ref source="BUGTRAQ">19990928 Team Asylum: iHTML Merchant Vulnerabilities</ref>
<ref source="CONFIRM" url="http://www.ihtmlmerchant.com/support_patches_feedback.htm">http://www.ihtmlmerchant.com/support_patches_feedback.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/694">694</ref>
<ref source="XF">ihtml-merchant-file-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0891" seq="1999-0891">
<status>Entry</status>
<desc>The &quot;download behavior&quot; in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-040.mspx">MS99-040</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q242542">Q242542</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/37828">VU#37828</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-002.shtml">K-002</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/674">674</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11274">11274</ref>
<ref source="XF">ie-download-behavior</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0892" seq="1999-0892">
<status>Entry</status>
<desc>Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.</desc>
<refs>
<ref source="BUGTRAQ">19991018 Netscape 4.x buffer overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0893" seq="1999-0893">
<status>Entry</status>
<desc>userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991011 SCO OpenServer 5.0.5 overwrite /etc/shadow</ref>
<ref source="XF">sco-openserver-userosa-script</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0894" seq="1999-0894">
<status>Entry</status>
<desc>Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.</desc>
<refs>
<ref source="REDHAT">RHSA1999042-01</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0895" seq="1999-0895">
<status>Entry</status>
<desc>Firewall-1 does not properly restrict access to LDAP attributes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991020150002.21047.qmail@tarjan.mediaways.net">19991020 Checkpoint FireWall-1 V4.0: possible bug in LDAP authentication</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/725">725</ref>
<ref source="XF">checkpoint-ldap-auth</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1117">1117</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0896" seq="1999-0896">
<status>Entry</status>
<desc>Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.</desc>
<refs>
<ref source="BUGTRAQ">19991109 RealNetworks RealServer G2 buffer overflow.</ref>
<ref source="MISC" url="http://service.real.com/help/faq/servg260.html">http://service.real.com/help/faq/servg260.html</ref>
<ref source="XF">realserver-g2-pw-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/767">767</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0897" seq="1999-0897">
<status>Entry</status>
<desc>iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90538488231977&amp;w=2">19980908 bug in iChat 3.0 (maybe others)</ref>
<ref source="XF">ichat-file-read-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0898" seq="1999-0898">
<status>Entry</status>
<desc>Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx">MS99-047</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649">Q243649</ref>
<ref source="XF">nt-printer-spooler-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/768">768</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0899" seq="1999-0899">
<status>Entry</status>
<desc>The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx">MS99-047</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q243649">Q243649</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/769">769</ref>
<ref source="XF">nt-printer-spooler-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0900" seq="1999-0900">
<status>Entry</status>
<desc>Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation.</desc>
<refs>
<ref source="REDHAT">RHSA1999046-01</ref>
<ref source="SUSE">19991023 Security hole in ypserv &lt; 1.3.9</ref>
<ref source="DEBIAN">19991027 nis</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0901" seq="1999-0901">
<status>Entry</status>
<desc>ypserv allows a local user to modify the GECOS and login shells of other users.</desc>
<refs>
<ref source="REDHAT">RHSA1999046-01</ref>
<ref source="SUSE">19991023 Security hole in ypserv &lt; 1.3.9</ref>
<ref source="DEBIAN">19991027 nis</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0902" seq="1999-0902">
<status>Entry</status>
<desc>ypserv allows local administrators to modify password tables.</desc>
<refs>
<ref source="REDHAT">RHSA1999046-01</ref>
<ref source="SUSE">19991023 Security hole in ypserv &lt; 1.3.9</ref>
<ref source="DEBIAN">19991027 nis</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0903" seq="1999-0903">
<status>Entry</status>
<desc>genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.</desc>
<refs>
<ref source="BUGTRAQ">19991025 IBM AIX Packet Filter module</ref>
<ref source="BUGTRAQ">19991027 Re: IBM AIX Packet Filter module (followup)</ref>
<ref source="XF">aix-genfilt-filtering</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0904" seq="1999-0904">
<status>Entry</status>
<desc>Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.</desc>
<refs>
<ref source="BUGTRAQ">19991103 Remote DoS Attack in BFTelnet Server v1.1 for Windows NT</ref>
<ref source="XF">bftelnet-username-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/771">771</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0905" seq="1999-0905">
<status>Entry</status>
<desc>Denial of service in Axent Raptor firewall via malformed zero-length IP options.</desc>
<refs>
<ref source="BUGTRAQ">19991020 Remote DoS in Axent's Raptor 6.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/736">736</ref>
<ref source="XF">raptor-ipoptions-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1121">1121</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0906" seq="1999-0906">
<status>Entry</status>
<desc>Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19990923 SuSE 6.2 sccw overflow exploit</ref>
<ref source="SUSE">19990926 Security hole in sccw (Part II)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/656">656</ref>
<ref source="XF">linux-sccw-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0907" seq="1999-0907">
<status>Entry</status>
<desc>sccw allows local users to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ">19990916 SuSE 6.2 /usr/bin/sccw read any file</ref>
<ref source="SUSE">19990921 Security Hole in sccw-1.1 and earlier</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0908" seq="1999-0908">
<status>Entry</status>
<desc>Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.</desc>
<refs>
<ref source="BUGTRAQ">19990921 solaris DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/655">655</ref>
<ref source="XF">sun-tcp-mutex-enter-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0909" seq="1999-0909">
<status>Entry</status>
<desc>Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the &quot;Spoofed Route Pointer&quot; vulnerability.</desc>
<refs>
<ref source="NAI">Windows IP Source Routing Vulnerability</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-038.mspx">MS99-038</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238453">Q238453</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/646">646</ref>
<ref source="XF">nt-ip-source-route</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0912" seq="1999-0912">
<status>Entry</status>
<desc>FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.</desc>
<refs>
<ref source="BUGTRAQ">19990921 FreeBSD-specific denial of service</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/653">653</ref>
<ref source="XF">freebsd-vfscache-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1079">1079</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0914" seq="1999-0914">
<status>Entry</status>
<desc>Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.</desc>
<refs>
<ref source="DEBIAN">19990104</ref>
<ref source="BUGTRAQ">19990103 [SECURITY] New versions of netstd fixes buffer overflows</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/324">324</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0915" seq="1999-0915">
<status>Entry</status>
<desc>URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991028 URL Live! 1.0 WebServer</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/746">746</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1129">1129</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0916" seq="1999-0916">
<status>Entry</status>
<desc>WebTrends software stores account names and passwords in a file which does not have restricted access permissions.</desc>
<refs>
<ref source="ISS">19990629 Bad Permissions on Passwords Stored by WebTrends Software</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0917" seq="1999-0917">
<status>Entry</status>
<desc>The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx">MS99-018</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q231452">Q231452</ref>
<ref source="XF">legacy-activex-local-drive</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0918" seq="1999-0918">
<status>Entry</status>
<desc>Denial of service in various Windows systems via malformed, fragmented IGMP packets.</desc>
<refs>
<ref source="BUGTRAQ">19990703 IGMP fragmentation bug in Windows 98/2000</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238329">Q238329</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-034.mspx">MS99-034</ref>
<ref source="XF">igmp-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/514">514</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0920" seq="1999-0920">
<status>Entry</status>
<desc>Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.</desc>
<refs>
<ref source="BUGTRAQ">19990526 Remote vulnerability in pop2d</ref>
<ref source="DEBIAN">19990607a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/283">283</ref>
<ref source="XF">pop2-fold-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0921" seq="1999-0921">
<status>Entry</status>
<desc>BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/4291.php">bmc-patrol-udp-dos(4291)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1879">1879</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0922" seq="1999-0922">
<status>Entry</status>
<desc>An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref>
<ref source="XF">coldfusion-sourcewindow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0924" seq="1999-0924">
<status>Entry</status>
<desc>The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1742">coldfusion-syntax-checker(1742)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3236">3236</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0927" seq="1999-0927">
<status>Entry</status>
<desc>NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/279">279</ref>
<ref source="XF">ntmail-fileread</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0928" seq="1999-0928">
<status>Entry</status>
<desc>Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ">19990525 Buffer overflow in SmartDesk WebSuite v2.1</ref>
<ref source="XF">websuite-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/278">278</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0930" seq="1999-0930">
<status>Entry</status>
<desc>wwwboard allows a remote attacker to delete message board articles via a malformed argument.</desc>
<refs>
<ref source="BUGTRAQ">19980903 wwwboard.pl vulnerability</ref>
<ref source="CONFIRM" url="http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml">http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml</ref>
<ref source="XF" url="http://xforce.iss.net/static/2344.php">http-cgi-wwwboard(2344)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1795">1795</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0931" seq="1999-0931">
<status>Entry</status>
<desc>Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19990930 Security flaw in Mediahouse Statistics Server v4.28 &amp; 5.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/734">734</ref>
<ref source="XF">mediahouse-stats-login-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0932" seq="1999-0932">
<status>Entry</status>
<desc>Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.</desc>
<refs>
<ref source="BUGTRAQ">19990930 Security flaw in Mediahouse Statistics Server v4.28 &amp; 5.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/735">735</ref>
<ref source="XF">mediahouse-stats-adminpw-cleartext</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0933" seq="1999-0933">
<status>Entry</status>
<desc>TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19991001 RFP9904: TeamTrack webserver vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/689">689</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1096">1096</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0934" seq="1999-0934">
<status>Entry</status>
<desc>classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.</desc>
<refs>
<ref source="EL8">19991215 Classifieds (classifieds.cgi)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2020">2020</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3102">http-cgi-classifieds-read(3102)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0935" seq="1999-0935">
<status>Entry</status>
<desc>classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.</desc>
<refs>
<ref source="EL8">19991215 Classifieds (classifieds.cgi)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0936" seq="1999-0936">
<status>Entry</status>
<desc>BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="EL8">19981203 BNBSurvey (survey.cgi)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0937" seq="1999-0937">
<status>Entry</status>
<desc>BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.</desc>
<refs>
<ref source="EL8">19981203 BNBForm (bnbform.cgi)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0938" seq="1999-0938">
<status>Entry</status>
<desc>MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Sesion Initiation Protocol (SIP) messages.</desc>
<refs>
<ref source="CERT">VN-99-03</ref>
<ref source="XF">sdr-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0939" seq="1999-0939">
<status>Entry</status>
<desc>Denial of service in Debian IRC Epic/epic4 client via a long string.</desc>
<refs>
<ref source="BUGTRAQ">19990826 [SECURITY] New versions of epic4 fixes possible DoS vulnerability</ref>
<ref source="DEBIAN">19990826</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/605">605</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0940" seq="1999-0940">
<status>Entry</status>
<desc>Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.</desc>
<refs>
<ref source="CALDERA">CSSA-1999-031</ref>
<ref source="SUSE">19990927 Security hole in mutt</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0942" seq="1999-0942">
<status>Entry</status>
<desc>UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.</desc>
<refs>
<ref source="BUGTRAQ">19991005 SCO UnixWare 7.1 local root exploit</ref>
<ref source="XF">sco-unixware-dos7utils-root-privs</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0943" seq="1999-0943">
<status>Entry</status>
<desc>Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.</desc>
<refs>
<ref source="BUGTRAQ">19991015 OpenLink 3.2 Advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/720">720</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0945" seq="1999-0945">
<status>Entry</status>
<desc>Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise4.php">19980724 Denial of Service attacks against Microsoft Exchange 5.0 to 5.5</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-080.shtml">I-080</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q169174">Q169174</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1223">exchange-dos(1223)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0946" seq="1999-0946">
<status>Entry</status>
<desc>Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
<ref source="XF">yamaha-midiplug-embed</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/760">760</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0947" seq="1999-0947">
<status>Entry</status>
<desc>AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/762">762</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0950" seq="1999-0950">
<status>Entry</status>
<desc>Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via	a series of MKD and CWD commands that create nested directories.</desc>
<refs>
<ref source="BUGTRAQ">19991027 WFTPD v2.40 FTPServer remotely exploitable buffer overflow vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/747">747</ref>
<ref source="XF">wftpd-mkd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0951" seq="1999-0951">
<status>Entry</status>
<desc>Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19991022 Imagemap CGI overflow exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/739">739</ref>
<ref source="XF">http-cgi-imagemap-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3380">3380</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0953" seq="1999-0953">
<status>Entry</status>
<desc>WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.</desc>
<refs>
<ref source="BUGTRAQ">19980903 wwwboard.pl vulnerability</ref>
<ref source="BUGTRAQ">19990916 More fun with WWWBoard</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0954" seq="1999-0954">
<status>Entry</status>
<desc>WWWBoard has a default username and default password.</desc>
<refs>
<ref source="BUGTRAQ">19990916 More fun with WWWBoard</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/649">649</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0955" seq="1999-0955">
<status>Entry</status>
<desc>Race condition in wu-ftpd and BSDI ftpd allows remote attackers gain root access via the SITE EXEC command.</desc>
<refs>
<ref source="CERT">CA-94.08</ref>
<ref source="CIAC">E-17</ref>
<ref source="XF">ftp-exec</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0956" seq="1999-0956">
<status>Entry</status>
<desc>The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.</desc>
<refs>
<ref source="CERT">CA-93.02a</ref>
<ref source="XF">next-netinfo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0957" seq="1999-0957">
<status>Entry</status>
<desc>MajorCool mj_key_cache program allows local users to modify files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19970618 Security hole in MajorCool 1.0.3</ref>
<ref source="XF">majorcool-file-overwrite-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0958" seq="1999-0958">
<status>Entry</status>
<desc>sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88465708614896&amp;w=2">19980112 Re: hole in sudo for MP-RAS.</ref>
<ref source="XF">sudo-dot-dot-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0959" seq="1999-0959">
<status>Entry</status>
<desc>IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19970209 IRIX: Bug in startmidi</ref>
<ref source="AUSCERT">AA-97-05</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/469">469</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8447">8447</ref>
<ref source="XF">irix-startmidi-file-creation((1634)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0960" seq="1999-0960">
<status>Entry</status>
<desc>IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.</desc>
<refs>
<ref source="AUSCERT">AA-96.11</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref>
<ref source="XF">irix-cdplayer-directory-create</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0961" seq="1999-0961">
<status>Entry</status>
<desc>HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419906&amp;w=2">19960921 Vunerability in HP sysdiag ?</ref>
<ref source="CIAC">H-03</ref>
<ref source="XF">hp-sysdiag-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0962" seq="1999-0962">
<status>Entry</status>
<desc>Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.</desc>
<refs>
<ref source="AUSCERT">AA-96.13</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9701-045">HPSBUX9701-045</ref>
<ref source="XF">hp-password-cmd-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6415">6415</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0963" seq="1999-0963">
<status>Entry</status>
<desc>FreeBSD mount_union command allows local users to gain root privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19960517 BoS: SECURITY BUG in FreeBSD</ref>
<ref source="CERT">VB-96.06</ref>
<ref source="XF">freebsd-mount-union-root</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6088">6088</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0964" seq="1999-0964">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-97:01</ref>
<ref source="XF">freebsd-setlocale-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6086">6086</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0965" seq="1999-0965">
<status>Entry</status>
<desc>Race condition in xterm allows local users to modify arbitrary files via the logging option.</desc>
<refs>
<ref source="CERT">CA-93.17</ref>
<ref source="XF">xterm</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0966" seq="1999-0966">
<status>Entry</status>
<desc>Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].</desc>
<refs>
<ref source="L0PHT">19970127 Solaris libc - getopt(3)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0967" seq="1999-0967">
<status>Entry</status>
<desc>Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.</desc>
<refs>
<ref source="L0PHT">19971101 Microsoft Internet Explorer 4.0 Suite</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0968" seq="1999-0968">
<status>Entry</status>
<desc>Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11711">19981226 bnc exploit</ref>
<ref source="XF" url="http://xforce.iss.net/static/1546.php">bnc-proxy-bo(1546)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1927">1927</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0969" seq="1999-0969">
<status>Entry</status>
<desc>The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.</desc>
<refs>
<ref source="ISS">19980929 &quot;Snork&quot; Denial of Service Attack Against Windows NT RPC Service</ref>
<ref source="NTBUGTRAQ">19980929 ISS Security Advisory: Snork</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-014.mspx">MS98-014</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q193233">Q193233</ref>
<ref source="XF">snork-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0971" seq="1999-0971">
<status>Entry</status>
<desc>Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7301">19970722 Security hole in exim 1.62: local root exploit</ref>
<ref source="XF">exim-include-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0972" seq="1999-0972">
<status>Entry</status>
<desc>Buffer overflow in Xshipwars xsw program.</desc>
<refs>
<ref source="BUGTRAQ">19991209 xsw 1.24 remote buffer overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/863">863</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0973" seq="1999-0973">
<status>Entry</status>
<desc>Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.</desc>
<refs>
<ref source="BUGTRAQ">19991206 [w00giving #8] Solaris 2.7's snoop</ref>
<ref source="BUGTRAQ">19991209 Clarification needed on the snoop vuln(s) (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/858">858</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0974" seq="1999-0974">
<status>Entry</status>
<desc>Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.</desc>
<refs>
<ref source="ISS">19991209 Buffer Overflow in Solaris Snoop</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/190">00190</ref>
<ref source="BUGTRAQ">19991209 Clarification needed on the snoop vuln(s) (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/864">864</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0975" seq="1999-0975">
<status>Entry</status>
<desc>The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.</desc>
<refs>
<ref source="BUGTRAQ">19991207 Local user can fool another to run executable. .CNT/.GID/.HLP M$WINNT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/868">868</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0976" seq="1999-0976">
<status>Entry</status>
<desc>Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.</desc>
<refs>
<ref source="OPENBSD">19991204</ref>
<ref source="BUGTRAQ">19991207 [Debian] New version of sendmail released</ref>
<ref source="XF">sendmail-bi-alias</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/857">857</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0977" seq="1999-0977">
<status>Entry</status>
<desc>Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.</desc>
<refs>
<ref source="SF-INCIDENTS">19991209 sadmind</ref>
<ref source="BUGTRAQ">19991210 Solaris sadmind Buffer Overflow Vulnerability</ref>
<ref source="BUGTRAQ">19991210 Re: Solaris sadmind Buffer Overflow Vulnerability</ref>
<ref source="CERT">CA-99-16</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/191">00191</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/866">866</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2354">2354</ref>
<ref source="XF">sol-sadmind-amslverify-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/2558">2558</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0978" seq="1999-0978">
<status>Entry</status>
<desc>htdig allows remote attackers to execute commands via filenames with shell metacharacters.</desc>
<refs>
<ref source="DEBIAN">19991209</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/867">867</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0979" seq="1999-0979">
<status>Entry</status>
<desc>The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.</desc>
<refs>
<ref source="BUGTRAQ">19991209 Fundamental flaw in UnixWare 7 security</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/869">869</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0980" seq="1999-0980">
<status>Entry</status>
<desc>Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-055.mspx">MS99-055</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246045">Q246045</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0981" seq="1999-0981">
<status>Entry</status>
<desc>Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka &quot;Server-side Page Reference Redirect.&quot;</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-050.mspx">MS99-050</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246094">Q246094</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0982" seq="1999-0982">
<status>Entry</status>
<desc>The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.</desc>
<refs>
<ref source="BUGTRAQ">19991206 Solaris WBEM 1.0: plaintext password stored in world readable file</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0986" seq="1999-0986">
<status>Entry</status>
<desc>The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.</desc>
<refs>
<ref source="BUGTRAQ">19991209 Big problem on 2.0.x?</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/870">870</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0987" seq="1999-0987">
<status>Entry</status>
<desc>Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.</desc>
<refs>
<ref source="NTBUGTRAQ">19991118 NT System Policy for Win95 Not downloaded when adding a space after domain name</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q237923">Q237923</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0989" seq="1999-0989">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.</desc>
<refs>
<ref source="NTBUGTRAQ">19991205 new IE5 remote exploit</ref>
<ref source="BUGTRAQ">19991205 new IE5 remote exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/861">861</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0991" seq="1999-0991">
<status>Entry</status>
<desc>Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.</desc>
<refs>
<ref source="NTBUGTRAQ">19991206 Remote DoS Attack in GoodTech Telnet Server NT v2.2.1 Vulnerability</ref>
<ref source="BUGTRAQ">19991206 Remote DoS Attack in GoodTech Telnet Server NT v2.2.1 Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/862">862</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0992" seq="1999-0992">
<status>Entry</status>
<desc>HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9912-107">HPSBUX9912-107</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0994" seq="1999-0994">
<status>Entry</status>
<desc>Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.</desc>
<refs>
<ref source="BINDVIEW">19991216 Windows NT's SYSKEY feature</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-056.mspx">MS99-056</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248183">Q248183</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/873">873</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0995" seq="1999-0995">
<status>Entry</status>
<desc>Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka &quot;Malformed Security Identifier Request.&quot;</desc>
<refs>
<ref source="NAI">19991216 Windows NT LSA Remote Denial of Service</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-057.mspx">MS99-057</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248185">Q248185</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/875">875</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0996" seq="1999-0996">
<status>Entry</status>
<desc>Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD19991215.html">AD19991215</ref>
<ref source="BUGTRAQ">19991216 Infoseek Ultraseek Remote Buffer Overflow</ref>
<ref source="NTBUGTRAQ">19991216 Infoseek Ultraseek Remote Buffer Overflow</ref>
<ref source="XF">infoseek-ultraseek-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6490">6490</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0997" seq="1999-0997">
<status>Entry</status>
<desc>wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.</desc>
<refs>
<ref source="BUGTRAQ">19991220 Security vulnerability in certain wu-ftpd (and derivitives) configurations (fwd)</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-377">DSA-377</ref>
<ref source="XF">wuftp-ftp-conversion</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0998" seq="1999-0998">
<status>Entry</status>
<desc>Cisco Cache Engine allows an attacker to replace content in the cache.</desc>
<refs>
<ref source="CISCO">19991216 Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="BUGTRAQ">19991216 Cisco Security Advisory: Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="XF">cisco-cache-engine-replace</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0999" seq="1999-0999">
<status>Entry</status>
<desc>Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-059.mspx">MS99-059</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248749">Q248749</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/817">817</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1000" seq="1999-1000">
<status>Entry</status>
<desc>The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.</desc>
<refs>
<ref source="CISCO">19991216 Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="BUGTRAQ">19991216 Cisco Security Advisory: Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="XF">cisco-cache-engine-performance</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1001" seq="1999-1001">
<status>Entry</status>
<desc>Cisco Cache Engine allows a remote attacker to gain access via a null username and password.</desc>
<refs>
<ref source="CISCO">19991216 Cisco Cache Engine Authentication Vulnerabilities</ref>
<ref source="BUGTRAQ">19991216 Cisco Security Advisory: Cisco Cache Engine Authentication Vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1004" seq="1999-1004">
<status>Entry</status>
<desc>Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/38970">19991217 NAV2000 Email Protection DoS</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39194">19991220 Norton Email Protection Remote Overflow (Addendum)</ref>
<ref source="CONFIRM" url="http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy">http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6267">6267</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1005" seq="1999-1005">
<status>Entry</status>
<desc>Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94571433731824&amp;w=2">19991219 Groupewise Web Interface</ref>
<ref source="XF">groupwise-web-read-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/879">879</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3413">3413</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1007" seq="1999-1007">
<status>Entry</status>
<desc>Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94512259331599&amp;w=2">19991213 VDO Live Player 3.02 Buffer Overflow</ref>
<ref source="XF">vdolive-bo-execute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/872">872</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1008" seq="1999-1008">
<status>Entry</status>
<desc>xsoldier program allows local users to gain root access via a long argument.</desc>
<refs>
<ref source="BUGTRAQ">19991215 FreeBSD 3.3 xsoldier root exploit</ref>
<ref source="MISC" url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=94531826621620&amp;w=2">http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=94531826621620&amp;w=2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/871">871</ref>
<ref source="XF">unix-xsoldier-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1010" seq="1999-1010">
<status>Entry</status>
<desc>An SSH 1.2.27 server allows a client to use the &quot;none&quot; cipher, even if it is not allowed by the server policy.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94519142415338&amp;w=2">19991214 sshd1 allows unencrypted sessions regardless of server policy</ref>
<ref source="XF">ssh-policy-bypass</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1011" seq="1999-1011">
<status>Entry</status>
<desc>The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-004.asp">MS98-004</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-025.asp">MS99-025</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-054.shtml">J-054</ref>
<ref source="ISS">19990809 Vulnerabilities in Microsoft Remote Data Service</ref>
<ref source="BID" url="http://www.ciac.org/ciac/bulletins/j-054.shtml">529</ref>
<ref source="XF">nt-iis-rds</ref>
<ref source="OSVDB" url="http://www.osvdb.org/272">272</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1014" seq="1999-1014">
<status>Entry</status>
<desc>Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93727925026476&amp;w=2">19990913 Solaris 2.7 /usr/bin/mail</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93846422810162&amp;w=2">19990927 Working Solaris x86 /usr/bin/mail exploit</ref>
<ref source="SUNBUG">4276509</ref>
<ref source="XF" url="http://xforce.iss.net/static/3297.php">sun-usrbinmail-local-bo(3297)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/672">672</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1019" seq="1999-1019">
<status>Entry</status>
<desc>SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398713491&amp;w=2">19990623 Cabletron Spectrum security vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398513475&amp;w=2">19990624 Re: Cabletron Spectrum security vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/495">495</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1021" seq="1999-1021">
<status>Entry</status>
<desc>NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-15.html">CA-1992-15</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/117&amp;type=0&amp;nav=sec.sba">00117</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/47">47</ref>
<ref source="XF" url="http://xforce.iss.net/static/82.php">nfs-uid(82)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1027" seq="1999-1027">
<status>Entry</status>
<desc>Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925880&amp;w=2">19980507 admintool mode 0777 in Solaris 2.6 HW3/98</ref>
<ref source="SUNBUG">4178998</ref>
<ref source="XF" url="http://xforce.iss.net/static/7296.php">solaris-admintool-world-writable(7296)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/290">290</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1028" seq="1999-1028">
<status>Entry</status>
<desc>Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92807524225090&amp;w=2">19990528 DoS against PC Anywhere</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/288">288</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2256.php">pcanywhere-dos(2256)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1032" seq="1999-1032">
<status>Entry</status>
<desc>Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-11.html">CA-1991-11</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-36.shtml">B-36</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/26">26</ref>
<ref source="XF" url="http://xforce.iss.net/static/584.php">ultrix-telnet(584)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1034" seq="1999-1034">
<status>Entry</status>
<desc>Vulnerability in login in AT&amp;T System V Release 4 allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-08.html">CA-1991-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/b-28.shtml">B-28</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/23">23</ref>
<ref source="XF" url="http://xforce.iss.net/static/583.php">sysv-login(583)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1035" seq="1999-1035">
<status>Entry</status>
<desc>IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS &quot;GET&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-019.asp">MS98-019</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q192/2/96.asp">Q192296</ref>
<ref source="XF" url="http://xforce.iss.net/static/1823.php">iis-get-dos(1823)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1037" seq="1999-1037">
<status>Entry</status>
<desc>rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125986&amp;w=2">19980627 Re: vulnerability in satan, cops &amp; tiger</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7167.php">satan-rexsatan-symlink(7167)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3147">3147</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1044" seq="1999-1044">
<status>Entry</status>
<desc>Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.</desc>
<refs>
<ref source="COMPAQ" url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml">SSRT0495U</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml">I-050</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7431.php">dgux-advfs-softlinks(7431)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1045" seq="1999-1045">
<status>Entry</status>
<desc>pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88492978527261&amp;w=2">19980115 pnserver exploit..</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88490880523890&amp;w=2">19980115 [rootshell] Security Bulletin #7</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90338245305236&amp;w=2">19980817 Re: Real Audio Server Version 5 bug?</ref>
<ref source="MISC" url="http://service.real.com/help/faq/serv501.html">http://service.real.com/help/faq/serv501.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7297.php">realserver-pnserver-remote-dos(7297)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6979">6979</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1047" seq="1999-1047">
<status>Entry</status>
<desc>When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94026690521279&amp;w=2">19991018 Gauntlet 5.0 BSDI warning</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94036662326185&amp;w=2">19991019 Re: Gauntlet 5.0 BSDI warning</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3397.php">gauntlet-bsdi-bypass(3397)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1048" seq="1999-1048">
<status>Entry</status>
<desc>Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10542">19980905 BASH buffer overflow, LiNUX x86 exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602746719555&amp;w=2">19970821 Buffer overflow in /bin/bash</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/1998/19980909">19980909 problem with very long pathnames</ref>
<ref source="XF" url="http://xforce.iss.net/static/3414.php">linux-bash-bo(3414)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8345">8345</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1055" seq="1999-1055">
<status>Entry</status>
<desc>Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel &quot;CALL Vulnerability.&quot;</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-018.asp">MS98-018</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/179">179</ref>
<ref source="XF" url="http://xforce.iss.net/static/1737.php">excel-call(1737)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1057" seq="1999-1057">
<status>Entry</status>
<desc>VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-07.html">CA-1990-07</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-04.shtml">B-04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/12">12</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7137.php">vms-analyze-processdump-privileges(7137)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1059" seq="1999-1059">
<status>Entry</status>
<desc>Vulnerability in rexec daemon (rexecd) in AT&amp;T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-04.html">CA-1992-04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/36">36</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3159.php">att-rexecd(3159)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1074" seq="1999-1074">
<status>Entry</status>
<desc>Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9138">19980501 Warning! Webmin Security Advisory</ref>
<ref source="CONFIRM" url="http://www.webmin.com/webmin/changes.html">http://www.webmin.com/webmin/changes.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/98">98</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1080" seq="1999-1080">
<status>Entry</status>
<desc>rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92633694100270&amp;w=2">19990510 SunOS 5.7 rmmount, no nosuid.</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93971288323395&amp;w=2">19991011</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/250">250</ref>
<ref source="SUNBUG">4205437</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/8350">solaris-rmmount-gain-root(8350)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1085" seq="1999-1085">
<status>Entry</status>
<desc>SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the &quot;SSH insertion attack.&quot;</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125884&amp;w=2">19980612 CORE-SDI-04: SSH insertion attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525878&amp;w=2">19980703 UPDATE: SSH insertion attack</ref>
<ref source="CISCO">20010627 Multiple SSH Vulnerabilities</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/13877">VU#13877</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/1126.php">ssh-insert(1126)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1087" seq="1999-1087">
<status>Entry</status>
<desc>Internet Explorer 4 treats a 32-bit number (&quot;dotless IP address&quot;) in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS98-016.asp">MS98-016</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q168/6/17.asp">Q168617</ref>
<ref source="CONFIRM" url="http://www.microsoft.com/Windows/Ie/security/dotless.asp">http://www.microsoft.com/Windows/Ie/security/dotless.asp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7828">7828</ref>
<ref source="XF" url="http://xforce.iss.net/static/2209.php">ie-dotless(2209)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1090" seq="1999-1090">
<status>Entry</status>
<desc>The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an &quot;ftp=yes&quot; line, which allows remote attackers to read and modify arbitrary files.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-15.html">CA-1991-15</ref>
<ref source="XF" url="http://xforce.iss.net/static/1844.php">ftp-ncsa(1844)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1093" seq="1999-1093">
<status>Entry</status>
<desc>Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS98-011.asp">MS98-011</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q191/2/00.asp">Q191200</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/1276.php">java-script-patch(1276)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1094" seq="1999-1094">
<status>Entry</status>
<desc>Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the &quot;mk:&quot; protocol, aka the &quot;MK Overrun security issue.&quot;</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88480839506155&amp;w=2">19980114 L0pht Advisory MSIE4.0(1)</ref>
<ref source="XF" url="http://xforce.iss.net/static/917.php">iemk-bug(917)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1098" seq="1999-1098">
<status>Entry</status>
<desc>Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1995-03.html">CA-1995-03</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/f-12.shtml">F-12</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/516.php">bsd-telnet(516)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4881">4881</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1099" seq="1999-1099">
<status>Entry</status>
<desc>Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420184&amp;w=2">19961122 L0pht Kerberos Advisory</ref>
<ref source="XF" url="http://xforce.iss.net/static/65.php">kerberos-user-grab(65)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1100" seq="1999-1100">
<status>Entry</status>
<desc>Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixkey-pub.shtml">19980616 PIX Private Link Key Processing and Cryptography Issues</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-056.shtml">I-056</ref>
<ref source="XF" url="http://xforce.iss.net/static/1579.php">cisco-pix-parse-error(1579)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1102" seq="1999-1102">
<status>Entry</status>
<desc>lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.</desc>
<refs>
<ref source="MISC" url="http://www.phreak.org/archives/security/8lgm/8lgm.lpr">http://www.phreak.org/archives/security/8lgm/8lgm.lpr</ref>
<ref source="BUGTRAQ" url="http://www.aenigma.net/resources/maillist/bugtraq/1994/0091.htm">19940307 8lgm Advisory Releases</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-25.shtml">E-25a</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1103" seq="1999-1103">
<status>Entry</status>
<desc>dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.05.dec">VB-96.05</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-18.shtml">G-18</ref>
<ref source="MISC" url="http://www.tao.ca/fire/bos/0209.html">http://www.tao.ca/fire/bos/0209.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7138.php">osf-dxconsole-gain-privileges(7138)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1104" seq="1999-1104">
<status>Entry</status>
<desc>Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418931&amp;w=2">19951205 Cracked: WINDOWS.PWL</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=88540877601866&amp;w=2">19980121 How to recover private keys for various Microsoft products</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88536273725787&amp;w=2">19980120 How to recover private keys for various Microsoft products</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q140/5/57.asp">Q140557</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/71.php">win95-nbsmbpwl(71)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1105" seq="1999-1105">
<status>Entry</status>
<desc>Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.</desc>
<refs>
<ref source="CONFIRM" url="http://www.zdnet.com/eweek/reviews/1016/tr42bug.html">http://www.zdnet.com/eweek/reviews/1016/tr42bug.html</ref>
<ref source="MISC" url="http://www.net-security.sk/bugs/NT/netware1.html">http://www.net-security.sk/bugs/NT/netware1.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7231.php">win95-netware-hidden-share(7231)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1109" seq="1999-1109">
<status>Entry</status>
<desc>Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94632241202626&amp;w=2">19991222 Re: procmail / Sendmail - five bugs</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780566911948&amp;w=2">20000113 Re: procmail / Sendmail - five bugs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/904">904</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7760.php">sendmail-etrn-dos(7760)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1111" seq="1999-1111">
<status>Entry</status>
<desc>Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94218618329838&amp;w=2">19911109 ImmuniX OS Security Alert: StackGuard 1.21 Released</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/786">786</ref>
<ref source="XF" url="http://xforce.iss.net/static/3524.php">immunix-stackguard-bo(3524)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1114" seq="1999-1114">
<status>Entry</status>
<desc>Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-15a.shtml">H-15A</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.17.suid_exec.vul">AA-96.17</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980405-01-I">19980405-01-I</ref>
<ref source="XF" url="http://xforce.iss.net/static/2100.php">ksh-suid_exec(2100)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/467">467</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1115" seq="1999-1115">
<status>Entry</status>
<desc>Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-04.html">CA-1990-04</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/a-30.shtml">A-30</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/7">7</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/6721.php">apollo-suidexec-unauthorized-access(6721)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1116" seq="1999-1116">
<status>Entry</status>
<desc>Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970503-01-PX">19970503-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/462">462</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1009">1009</ref>
<ref source="XF" url="http://xforce.iss.net/static/2108.php">sgi-runpriv(2108)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1117" seq="1999-1117">
<status>Entry</status>
<desc>lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;w=2&amp;r=1&amp;s=lquerypv&amp;q=b">19961124</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420195&amp;w=2">19961125 lquerypv fix</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420196&amp;w=2">19961125 AIX lquerypv</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/455">455</ref>
<ref source="XF" url="http://xforce.iss.net/static/1752.php">ibm-lquerypv(1752)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1118" seq="1999-1118">
<status>Entry</status>
<desc>ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/165&amp;type=0&amp;nav=sec.sba">00165</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/433">433</ref>
<ref source="XF" url="http://xforce.iss.net/static/817.php">sun-ndd(817)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1119" seq="1999-1119">
<status>Entry</status>
<desc>FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-09.html">CA-1992-09</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/41">41</ref>
<ref source="XF" url="http://xforce.iss.net/static/3154.php">aix-anon-ftp(3154)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1120" seq="1999-1120">
<status>Entry</status>
<desc>netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420403&amp;w=2">19970104 Irix: netprint story</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-01-PX">19961203-01-PX</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX">19961203-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/395">395</ref>
<ref source="OSVDB" url="http://www.osvdb.org/993">993</ref>
<ref source="XF" url="http://xforce.iss.net/static/2107.php">sgi-netprint(2107)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1121" seq="1999-1121">
<status>Entry</status>
<desc>The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-06.html">CA-1992-06</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/38">38</ref>
<ref source="XF" url="http://xforce.iss.net/static/554.php">ibm-uucp(554)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/891">891</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1122" seq="1999-1122">
<status>Entry</status>
<desc>Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1989-02.html">CA-1989-02</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/ciac-08.shtml">CIAC-08</ref>
<ref source="SUNBUG">1019265</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/3">3</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6695">sun-restore-gain-privileges(6695)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1127" seq="1999-1127">
<status>Entry</status>
<desc>Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the &quot;Named Pipes Over RPC&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-017.asp">MS98-017</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q195/7/33.asp">Q195733</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/523.php">nt-spoolss(523)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1131" seq="1999-1131">
<status>Entry</status>
<desc>Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.12.opengroup">VB-97.12</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-060.shtml">I-060</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980601-01-PX">19980601-01-PX</ref>
<ref source="XF" url="http://xforce.iss.net/static/1123.php">sgi-osf-dce-dos(1123)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1132" seq="1999-1132">
<status>Entry</status>
<desc>Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90763508011966&amp;w=2">19981005 NMRC Advisory - Lame NT Token Ring DoS</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90760603030452&amp;w=2">19981002 NMRC Advisory - Lame NT Token Ring DoS</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q179/1/57.asp">Q179157</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/1399.php">token-ring-dos(1399)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1136" seq="1999-1136">
<status>Entry</status>
<desc>Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.</desc>
<refs>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9807-081.html">HPSBUX9807-081</ref>
<ref source="HP" url="http://cert.ip-plus.net/bulletin-archive/msg00040.html">HPSBMP9807-005</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526177&amp;w=2">19980729 HP-UX Predictive &amp; Netscape SSL Vulnerabilities</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-081.shtml">I-081</ref>
<ref source="XF" url="http://xforce.iss.net/static/1413.php">mpeix-predictive(1413)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1137" seq="1999-1137">
<status>Entry</status>
<desc>The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/e-01.shtml">E-01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
<ref source="XF" url="http://xforce.iss.net/static/549.php">sun-audio(549)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6436">6436</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1138" seq="1999-1138">
<status>Entry</status>
<desc>SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-13.html">CA-1993-13</ref>
<ref source="XF" url="http://xforce.iss.net/static/546.php">sco-homedir(546)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1139" seq="1999-1139">
<status>Entry</status>
<desc>Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-199801/0122.html">19980121 HP-UX CUE, CUD and LAND vulnerabilities</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019745&amp;w=2">19970901 HP UX Bug :)</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9801-074.html">HPSBUX9801-074</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-027b.shtml">I-027B</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/2007.php">hp-cue(2007)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1140" seq="1999-1140">
<status>Entry</status>
<desc>Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88209041500913&amp;w=2">19971214 buffer overflows in cracklib?!</ref>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.16.CrackLib">VB-97.16</ref>
<ref source="XF" url="http://xforce.iss.net/static/1539.php">cracklib-bo(1539)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1142" seq="1999-1142">
<status>Entry</status>
<desc>SunOS 4.1.2 and earlier allows local users to gain privileges via &quot;LD_*&quot; environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1992-11.html">CA-1992-11</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/116">00116</ref>
<ref source="XF" url="http://xforce.iss.net/static/3152.php">sun-env(3152)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1143" seq="1999-1143">
<status>Entry</status>
<desc>Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-65.shtml">H-065</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970504-01-PX">19970504-01-PX</ref>
<ref source="XF" url="http://xforce.iss.net/static/2109.php">sgi-rld(2109)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1144" seq="1999-1144">
<status>Entry</status>
<desc>Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-051.html">HPSBUX9701-051</ref>
<ref source="XF" url="http://xforce.iss.net/static/2056.php">hp-mpower(2056)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1145" seq="1999-1145">
<status>Entry</status>
<desc>Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=1514">HPSBUX9701-044</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21</ref>
<ref source="XF" url="http://xforce.iss.net/static/2059.php">hp-glanceplus(2059)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1146" seq="1999-1146">
<status>Entry</status>
<desc>Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/advisories/1555">HPSBUX9405-011</ref>
<ref source="XF" url="http://xforce.iss.net/static/2060.php">hp-glanceplus-gpm(2060)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1147" seq="1999-1147">
<status>Entry</status>
<desc>Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91273739726314&amp;w=2">19981204 [SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0</ref>
<ref source="BUGTRAQ">19981207 Re: [SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0</ref>
<ref source="XF" url="http://xforce.iss.net/static/1430.php">pcm-dos-execute(1430)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3164">3164</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1148" seq="1999-1148">
<status>Entry</status>
<desc>FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-006.asp">MS98-006</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q189/2/62.ASP">Q189262</ref>
<ref source="XF" url="http://xforce.iss.net/static/1215.php">iis-passive-ftp(1215)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1156" seq="1999-1156">
<status>Entry</status>
<desc>BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns.</desc>
<refs>
<ref source="NTBUGTRAQ">19990517 Vulnerabilities in BisonWare FTP Server 3.5</ref>
<ref source="XF" url="http://xforce.iss.net/static/2254.php">bisonware-port-crash(2254)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1157" seq="1999-1157">
<status>Entry</status>
<desc>Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q192/7/74.ASP">Q192774</ref>
<ref source="XF" url="http://xforce.iss.net/static/3894.php">tcpipsys-icmp-dos(3894)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1159" seq="1999-1159">
<status>Entry</status>
<desc>SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91495920911490&amp;w=2">19981229 ssh2 security problem (and patch) (fwd)</ref>
<ref source="XF" url="http://xforce.iss.net/static/1471.php">ssh-privileged-port-forward(1471)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1160" seq="1999-1160">
<status>Entry</status>
<desc>Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.</desc>
<refs>
<ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420581&amp;w=2">HPSBUX9702-055</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-33.shtml">H-33</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7437.php">hp-ftpd-kftpd(7437)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1161" seq="1999-1161">
<status>Entry</status>
<desc>Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420102&amp;w=2">19961103 Re: Untitled</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420103&amp;w=2">19961104 ppl bugs</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9704-057.html">HPSBUX9704-057</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-32.shtml">H-32</ref>
<ref source="AUSCERT">AA-97.07</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7438.php">hp-ppl(7438)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1162" seq="1999-1162">
<status>Entry</status>
<desc>Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-08.html">CA-1993-08</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/542.php">sco-passwd-deny(542)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1163" seq="1999-1163">
<status>Entry</status>
<desc>Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.</desc>
<refs>
<ref source="HP" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94347039929958&amp;w=2">HPSBUX9911-105</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7439.php">hp-ssp(7439)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1167" seq="1999-1167">
<status>Entry</status>
<desc>Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.</desc>
<refs>
<ref source="CONFIRM" url="http://www.wired.com/news/technology/0,1282,20677,00.html">http://www.wired.com/news/technology/0,1282,20677,00.html</ref>
<ref source="MISC" url="http://www.wired.com/news/technology/0,1282,20636,00.html">http://www.wired.com/news/technology/0,1282,20636,00.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7252.php">thirdvoice-cross-site-scripting(7252)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1175" seq="1999-1175">
<status>Entry</status>
<desc>Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/wccpauth-pub.shtml">19980513 Cisco Web Cache Control Protocol Router Vulnerability</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-054.shtml">I-054</ref>
<ref source="XF" url="http://xforce.iss.net/static/1577.php">cisco-wccp-vuln(1577)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1177" seq="1999-1177">
<status>Entry</status>
<desc>Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.</desc>
<refs>
<ref source="MISC" url="http://www.w3.org/Security/Faq/wwwsf4.html">http://www.w3.org/Security/Faq/wwwsf4.html</ref>
<ref source="CONFIRM" url="http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish">http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish</ref>
<ref source="XF" url="http://xforce.iss.net/static/2055.php">http-cgi-nphpublish(2055)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1181" seq="1999-1181">
<status>Entry</status>
<desc>Vulnerability in On-Line Customer Registration software for IRIX 6.2 through 6.4 allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980901-01-PX">19980901-01-PX</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-003.shtml">J-003</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7441.php">irix-register(7441)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1188" seq="1999-1188">
<status>Entry</status>
<desc>mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91479159617803&amp;w=2">19981227 mysql: mysqld creates world readable logs..</ref>
<ref source="XF" url="http://xforce.iss.net/static/1568.php">mysql-readable-log-files(1568)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1189" seq="1999-1189">
<status>Entry</status>
<desc>Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/36306">19991124 Netscape Communicator 4.7 - Navigator Overflows</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/36608">19991127 Netscape Communicator 4.7 - Navigator Overflows</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/822">822</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7884">netscape-long-argument-bo(7884)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1191" seq="1999-1191">
<status>Entry</status>
<desc>Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418335&amp;w=2">19970519 Re: Finally, most of an exploit for Solaris 2.5.1's ps.</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.18.solaris.chkey.buffer.overflow.vul">AA-97.18</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/144">00144</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/207">207</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7442.php">solaris-chkey-bo(7442)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1192" seq="1999-1192">
<status>Entry</status>
<desc>Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/143">00143</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/206">206</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7444.php">solaris-eeprom-bo(7444)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1193" seq="1999-1193">
<status>Entry</status>
<desc>The &quot;me&quot; user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-06.html">CA-1991-06</ref>
<ref source="XF" url="http://xforce.iss.net/static/581.php">next-me(581)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/20">20</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1194" seq="1999-1194">
<status>Entry</status>
<desc>chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1991-05.html">CA-1991-05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/17">17</ref>
<ref source="XF" url="http://xforce.iss.net/static/577.php">dec-chroot(577)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1197" seq="1999-1197">
<status>Entry</status>
<desc>TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-12.html">CA-1990-12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/14">14</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7140.php">sunos-tioccons-console-redirection(7140)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1198" seq="1999-1198">
<status>Entry</status>
<desc>BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml">B-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/11">11</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7141.php">nextstep-builddisk-root-access(7141)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1199" seq="1999-1199">
<status>Entry</status>
<desc>Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the &quot;sioux&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90252779826784&amp;w=2">19980807 YA Apache DoS attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90276683825862&amp;w=2">19980808 Debian Apache Security Update</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90286768232093&amp;w=2">19980810 Apache DoS Attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90280517007869&amp;w=2">19980811 Apache 'sioux' DOS fix for TurboLinux</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#apache">http://www.redhat.com/support/errata/rh51-errata-general.html#apache</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1201" seq="1999-1201">
<status>Entry</status>
<desc>Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91849617221319&amp;w=2">19990206 New Windows 9x Bug:  TCP Chorusing</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/225">225</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7542">win-multiple-ip-dos(7542)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1203" seq="1999-1203">
<status>Entry</status>
<desc>Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91868964203769&amp;w=2">19990210 Security problems in ISDN equipment authentication</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91888117502765&amp;w=2">19990212 PPP/ISDN multilink security issue - summary</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7498.php">ascend-ppp-isdn-dos(7498)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1204" seq="1999-1204">
<status>Entry</status>
<desc>Check Point Firewall-1 does not properly handle certain restricted keywords (e.g., Mail, auth, time) in user-defined objects, which could produce a rule with a default &quot;ANY&quot; address and result in access to more systems than intended by the administrator.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925912&amp;w=2">19980511 Firewall-1 Reserved Keywords Vulnerability</ref>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/config/keywords.html">http://www.checkpoint.com/techsupport/config/keywords.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/7293.php">fw1-user-defined-keywords-access(7293)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4416">4416</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1205" seq="1999-1205">
<status>Entry</status>
<desc>nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419195&amp;w=2">19960607 HP-UX B.10.01 vulnerability</ref>
<ref source="HP" url="http://packetstormsecurity.org/advisories/ibm-ers/96-08">HPSBUX9607-035</ref>
<ref source="CIAC">G-34</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/414">hp-nettune(414)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1208" seq="1999-1208">
<status>Entry</status>
<desc>Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419337&amp;w=2">19970721 AIX ping, lchangelv, xlock fixes</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419330&amp;w=2">19970721 AIX ping (Exploit)</ref>
<ref source="XF" url="http://xforce.iss.net/static/803.php">ping-bo(803)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1209" seq="1999-1209">
<status>Entry</status>
<desc>Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88131151000069&amp;w=2">19971204 scoterm exploit</ref>
<ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.14.scoterm">VB-97.14</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/690">sco-scoterm(690)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1214" seq="1999-1214">
<status>Entry</status>
<desc>The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.com/advisories/signals.txt">19970915 Vulnerability in I/O Signal Handling</ref>
<ref source="MISC" url="http://www.openbsd.com/advisories/signals.txt">http://www.openbsd.com/advisories/signals.txt</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11062">11062</ref>
<ref source="XF" url="http://xforce.iss.net/static/556.php">openbsd-iosig(556)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1215" seq="1999-1215">
<status>Entry</status>
<desc>LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-21.shtml">D-21</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-12.html">CA-1993-12</ref>
<ref source="XF" url="http://xforce.iss.net/static/545.php">novell-login(545)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1217" seq="1999-1217">
<status>Entry</status>
<desc>The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319435&amp;w=2">19970725 Re: NT security - why bother?</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319426&amp;w=2">19970723 NT security - why bother?</ref>
<ref source="XF" url="http://xforce.iss.net/static/526.php">nt-path(526)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1222" seq="1999-1222">
<status>Entry</status>
<desc>Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q188/5/71.ASP">Q188571</ref>
<ref source="XF" url="http://xforce.iss.net/static/3893.php">dns-netbtsys-dos(3893)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1223" seq="1999-1223">
<status>Entry</status>
<desc>IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q187/5/03.asp">Q187503</ref>
<ref source="XF" url="http://xforce.iss.net/static/3892.php">url-asp-av(3892)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1226" seq="1999-1226">
<status>Entry</status>
<desc>Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.</desc>
<refs>
<ref source="MISC" url="http://www.securiteam.com/exploits/Netscape_4_7_and_earlier_vulnerable_to__Huge_Key__DoS.html">http://www.securiteam.com/exploits/Netscape_4_7_and_earlier_vulnerable_to__Huge_Key__DoS.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/3436.php">netscape-huge-key-dos(3436)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1233" seq="1999-1233">
<status>Entry</status>
<desc>IIS 4.0 does not properly restrict access for the initial session request from a user's IP address if the address does not resolve to a DNS domain, aka the &quot;Domain Resolution&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp">MS99-039</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q241/5/62.asp">241562</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/657">657</ref>
<ref source="XF" url="http://xforce.iss.net/static/3306.php">iis-unresolved-domain-access(3306)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1243" seq="1999-1243">
<status>Entry</status>
<desc>SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-16.shtml">F-16</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950301-01-P373">19950301-01-P373</ref>
<ref source="XF" url="http://xforce.iss.net/static/2113.php">sgi-permissions(2113)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1246" seq="1999-1246">
<status>Entry</status>
<desc>Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q229/9/72.asp">Q229972</ref>
<ref source="XF" url="http://xforce.iss.net/static/2068.php">siteserver-directmail-passwords(2068)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1249" seq="1999-1249">
<status>Entry</status>
<desc>movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-047.html">HPSBUX9701-047</ref>
<ref source="XF" url="http://xforce.iss.net/static/2057.php">hp-movemail(2057)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8099">8099</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1258" seq="1999-1258">
<status>Entry</status>
<desc>rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/102">00102</ref>
<ref source="XF" url="http://xforce.iss.net/static/1782.php">sun-pwdauthd(1782)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1259" seq="1999-1259">
<status>Entry</status>
<desc>Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q189/5/29.asp">Q189529</ref>
<ref source="XF" url="http://xforce.iss.net/static/1780.php">office-extraneous-data(1780)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1262" seq="1999-1262">
<status>Entry</status>
<desc>Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12231">19990202 Unsecured server in applets under Netscape</ref>
<ref source="XF" url="http://xforce.iss.net/static/1727.php">java-socket-open(1727)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1263" seq="1999-1263">
<status>Entry</status>
<desc>Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87773365324657&amp;w=2">19971024 Vulnerability in metamail</ref>
<ref source="XF" url="http://xforce.iss.net/static/1677.php">metamail-file-creation(1677)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1276" seq="1999-1276">
<status>Entry</status>
<desc>fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/1998/19981207">19981207 fte-console: does not drop its root priviliges</ref>
<ref source="XF" url="http://xforce.iss.net/static/1609.php">fte-console-privileges(1609)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1279" seq="1999-1279">
<status>Entry</status>
<desc>An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q138/0/01.asp">Q138001</ref>
<ref source="XF" url="http://xforce.iss.net/static/1548.php">snaserver-shared-folders(1548)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1284" seq="1999-1284">
<status>Entry</status>
<desc>NukeNabber allows remote attackers to cause a denial of service by connecting to the NukeNabber port (1080) without sending any data, which causes the CPU usage to rise to 100% from the report.exe program that is executed upon the connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11131">19981105 various *lame* DoS attacks</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91063407332594&amp;w=2">19981107 Re: various *lame* DoS attacks</ref>
<ref source="MISC" url="http://www.dynamsol.com/puppet/text/new.txt">http://www.dynamsol.com/puppet/text/new.txt</ref>
<ref source="XF" url="http://xforce.iss.net/static/1540.php">nukenabber-timeout-dos(1540)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1288" seq="1999-1288">
<status>Entry</status>
<desc>Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11397">19981119 Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux</ref>
<ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/SA-1998.35.txt">SA-1998.35</ref>
<ref source="XF" url="http://xforce.iss.net/static/1406.php">samba-wsmbconf(1406)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1290" seq="1999-1290">
<status>Entry</status>
<desc>Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91127951426494&amp;w=2">19981117 nftp vulnerability (fwd)</ref>
<ref source="CONFIRM" url="http://www.ayukov.com/nftp/history.html">http://www.ayukov.com/nftp/history.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/1397.php">nftp-bo(1397)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1294" seq="1999-1294">
<status>Entry</status>
<desc>Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q146/6/04.asp">Q146604</ref>
<ref source="XF" url="http://xforce.iss.net/static/562.php">nt-filemgr(562)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1297" seq="1999-1297">
<status>Entry</status>
<desc>cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.</desc>
<refs>
<ref source="SUNBUG" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100452&amp;zone_32=10045%2A%20">1077164</ref>
<ref source="XF" url="http://xforce.iss.net/static/7482.php">sun-cmdtool-echo(7482)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1298" seq="1999-1298">
<status>Entry</status>
<desc>Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-97:03.sysinstall.asc">FreeBSD-SA-97:03</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7537.php">freebsd-sysinstall-ftp-password(7537)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6087">6087</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1301" seq="1999-1301">
<status>Entry</status>
<desc>A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-31.shtml">G-31</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc">FreeBSD-SA-96:17</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7540.php">rzsz-command-execution(7540)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1309" seq="1999-1309">
<status>Entry</status>
<desc>Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0040.html">19940314 sendmail -d problem (OLD yet still here)</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0043.html">19940315 so...</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0042.html">19940315 anyone know details?</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0048.html">19940315 Security problem in sendmail versions 8.x.x</ref>
<ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0078.html">19940327 sendmail exploit script - resend</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities">CA-1994-12</ref>
<ref source="XF" url="http://xforce.iss.net/static/7155.php">sendmail-debug-gain-root(7155)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1316" seq="1999-1316">
<status>Entry</status>
<desc>Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/Q247/9/75.asp">Q247975</ref>
<ref source="XF" url="http://xforce.iss.net/static/7391.php">passfilt-fullname(7391)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1317" seq="1999-1317">
<status>Entry</status>
<desc>Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92127046701349&amp;w=2">19990312 [ ALERT ] Case Sensitivity and Symbolic Links</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92162979530341&amp;w=2">19990314 AW: [ ALERT ] Case Sensitivity and Symbolic Links</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q222/1/59.asp">Q222159</ref>
<ref source="XF" url="http://xforce.iss.net/static/7398.php">nt-symlink-case(7398)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1318" seq="1999-1318">
<status>Entry</status>
<desc>/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.</desc>
<refs>
<ref source="SUNBUG" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100630&amp;zone_32=112193%2A%20">1121935</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7480.php">sun-su-path(7480)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1320" seq="1999-1320">
<status>Entry</status>
<desc>Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-01.shtml">D-01</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7213.php">netware-packet-spoofing-privileges(7213)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1321" seq="1999-1321">
<status>Entry</status>
<desc>Buffer overflow in ssh 1.2.26 client with Kerberos V enabled could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing.</desc>
<refs>
<ref source="BUGTRAQ" url="http://lists.netspace.org/cgi-bin/wa?A2=ind9811A&amp;L=bugtraq&amp;P=R4814">19981105 security patch for ssh-1.2.26 kerberos code</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4883">4883</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1324" seq="1999-1324">
<status>Entry</status>
<desc>VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-06.shtml">D-06</ref>
<ref source="XF" url="http://xforce.iss.net/static/7225.php">openvms-sysgen-enabled(7225)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1325" seq="1999-1325">
<status>Entry</status>
<desc>SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/c-19.shtml">C-19</ref>
<ref source="XF" url="http://xforce.iss.net/static/7261.php">vaxvms-sas-gain-privileges(7261)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1326" seq="1999-1326">
<status>Entry</status>
<desc>wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420401&amp;w=2">19970104 serious security bug in wu-ftpd v2.4</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420408&amp;w=2">19970105 BoS:  serious security bug in wu-ftpd v2.4 -- PATCH</ref>
<ref source="XF" url="http://xforce.iss.net/static/7169.php">wuftpd-abor-gain-privileges(7169)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1327" seq="1999-1327">
<status>Entry</status>
<desc>Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125826&amp;w=2">19980601 Re: SECURITY: Red Hat Linux 5.1 linuxconf bug (fwd)</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7239.php">linuxconf-lang-bo(7239)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6065">6065</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1328" seq="1999-1328">
<status>Entry</status>
<desc>linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19980826 [djb@redhat.com: Unidentified subject!]</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90383955231511&amp;w=2">19980823 Security concerns in linuxconf shipped w/RedHat 5.1</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7232.php">linuxconf-symlink-gain-privileges(7232)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6068">6068</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1329" seq="1999-1329">
<status>Entry</status>
<desc>Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.</desc>
<refs>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit">http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7250.php">sysvinit-root-bo(7250)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1330" seq="1999-1330">
<status>Entry</status>
<desc>The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419259&amp;w=2">19970709 [linux-security] so-called snprintf() in db-1.85.4 (fwd)</ref>
<ref source="CONFIRM" url="http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html">http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#db">http://www.redhat.com/support/errata/rh42-errata-general.html#db</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7244.php">linux-libdb-snprintf-bo(7244)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1331" seq="1999-1331">
<status>Entry</status>
<desc>netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.</desc>
<refs>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg">http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7245.php">netcfg-ethernet-dos(7245)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1332" seq="1999-1332">
<status>Entry</status>
<desc>gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88603844115233&amp;w=2">19980128 GZEXE - the big problem</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#gzip">http://www.redhat.com/support/errata/rh50-errata-general.html#gzip</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-308">DSA-308</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/7845">7845</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3812">3812</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7241.php">gzip-gzexe-tmp-symlink(7241)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1333" seq="1999-1333">
<status>Entry</status>
<desc>automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89042322924057&amp;w=2">19980319 ncftp 2.4.2 MkDirs bug</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp">http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7240.php">ncftp-autodownload-command-execution(7240)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6111">6111</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1335" seq="1999-1335">
<status>Entry</status>
<desc>snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.</desc>
<refs>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp">http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp</ref>
<ref source="XF" url="http://xforce.iss.net/static/7251.php">cmusnmp-read-write(7251)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1336" seq="1999-1336">
<status>Entry</status>
<desc>3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93458364903256&amp;w=2">19990812 3com hiperarch flaw [hiperbomb.c]</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93492615408725&amp;w=2">19990816 Re: 3com hiperarch flaw [hiperbomb.c]</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6057">6057</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1337" seq="1999-1337">
<status>Entry</status>
<desc>FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93370073207984&amp;w=2">19990801 midnight commander vulnerability(?) (fwd)</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/9873.php">midnight-commander-data-disclosure(9873)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5921">5921</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1339" seq="1999-1339">
<status>Entry</status>
<desc>Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277766505061&amp;w=2">19990722 Re: ping -R causes kernel panic on a forwarding machine ( 2.2.5 a nd 2 .2.10)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277426802802&amp;w=2">19990722 Linux +ipchains+ ping -R</ref>
<ref source="CONFIRM" url="http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz">http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7257.php">ipchains-ping-route-dos(7257)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6105">6105</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1341" seq="1999-1341">
<status>Entry</status>
<desc>Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94061108411308&amp;w=2">19991022 Local user can send forged packets</ref>
<ref source="XF" url="http://xforce.iss.net/static/7858.php">linux-tiocsetd-forge-packets(7858)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1351" seq="1999-1351">
<status>Entry</status>
<desc>Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the &quot;Listen to !nick &lt;soundname&gt; requests&quot; option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93845560631314&amp;w=2">19990924 Kvirc bug</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7761.php">kvirc-dot-directory-traversal(7761)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1356" seq="1999-1356">
<status>Entry</status>
<desc>Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93646669500991&amp;w=2">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93637792706047&amp;w=2">19990902 Compaq CIM UG Overwrites Legal Notice</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93759822830815&amp;w=2">19990917 Re: Compaq CIM UG Overwrites Legal Notice</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7763.php">compaq-smartstart-legal-notice(7763)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1358" seq="1999-1358">
<status>Entry</status>
<desc>When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q157/6/73.asp">Q157673</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7400.php">nt-user-policy-update(7400)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1359" seq="1999-1359">
<status>Entry</status>
<desc>When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/8/75.asp">Q163875</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7401.php">nt-group-policy-longname(7401)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1360" seq="1999-1360">
<status>Entry</status>
<desc>Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q160/6/50.asp">Q160650</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7402.php">nt-kernel-handle-dos(7402)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1362" seq="1999-1362">
<status>Entry</status>
<desc>Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q160/6/01.asp">Q160601</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7403.php">nt-win32k-dos(7403)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1363" seq="1999-1363">
<status>Entry</status>
<desc>Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/1/43.asp">Q163143</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7405.php">nt-nonpagedpool-dos(7405)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1365" seq="1999-1365">
<status>Entry</status>
<desc>Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93069418400856&amp;w=2">19990628 NT runs Explorer.exe, Taskmgr.exe etc. from wrong location</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93127894731200&amp;w=2">19990630 Update: NT runs explorer.exe, etc...</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2336">nt-login-default-folder(2336)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/0515">0515</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1379" seq="1999-1379">
<status>Entry</status>
<desc>DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93348057829957&amp;w=2">19990730 Possible Denial Of Service using DNS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93433758607623&amp;w=2">19990810 Possible Denial Of Service using DNS</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos">AL-1999.004</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-063.shtml">J-063</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7238.php">dns-udp-query-dos(7238)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1380" seq="1999-1380">
<status>Entry</status>
<desc>Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.</desc>
<refs>
<ref source="MISC" url="http://www.net-security.sk/bugs/NT/nu20.html">http://www.net-security.sk/bugs/NT/nu20.html</ref>
<ref source="MISC" url="http://mlarchive.ima.com/win95/1997/May/0342.html">http://mlarchive.ima.com/win95/1997/May/0342.html</ref>
<ref source="MISC" url="http://news.zdnet.co.uk/story/0,,s2065518,00.html">http://news.zdnet.co.uk/story/0,,s2065518,00.html</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7188.php">nu-tuneocx-activex-control(7188)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1382" seq="1999-1382">
<status>Entry</status>
<desc>NetWare NFS mode 1 and 2 implements the &quot;Read Only&quot; flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to &quot;Read Only,&quot; which NetWare-NFS changes to a setuid root program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88427711321769&amp;w=2">19980108 NetWare NFS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90295697702474&amp;w=2">19980812 Re: Netware NFS (fwd)</ref>
<ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551">http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7246.php">netware-nfs-file-ownership(7246)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1384" seq="1999-1384">
<status>Entry</status>
<desc>Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420095&amp;w=2">19961030 (Another) vulnerability in new SGIs</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul">AA-96.08</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I">19961101-01-I</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/470">470</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7456.php">irix-systour(7456)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1385" seq="1999-1385">
<status>Entry</status>
<desc>Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420332&amp;w=2">19961219 Exploit for ppp bug (FreeBSD 2.1.0).</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:20.stack-overflow.asc">FreeBSD-SA-96:20</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7465.php">ppp-bo(7465)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6085">6085</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1386" seq="1999-1386">
<status>Entry</status>
<desc>Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88932165406213&amp;w=2">19980308 another /tmp race: `perl -e' opens temp file not safely</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#perl">http://www.redhat.com/support/errata/rh50-errata-general.html#perl</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7243.php">perl-e-tmp-symlink(7243)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1397" seq="1999-1397">
<status>Entry</status>
<desc>Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92242671024118&amp;w=2">19990323 Index Server 2.0 and the Registry</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92223293409756&amp;w=2">19990323 Index Server 2.0 and the Registry</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/476">476</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7559.php">iis-indexserver-reveal-path(7559)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1402" seq="1999-1402">
<status>Entry</status>
<desc>The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418317&amp;w=2">19970517 UNIX domain socket (Solarisx86 2.5)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248718482&amp;w=2">19971003 Solaris 2.6 and sockets</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/456">456</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7172.php">sun-domain-socket-permissions(7172)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1407" seq="1999-1407">
<status>Entry</status>
<desc>ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88950856416985&amp;w=2">19980309 *sigh* another RH5 /tmp problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/368">368</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7294.php">initscripts-ifdhcpdone-dhcplog-symlink(7294)</ref>
<ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts">http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1409" seq="1999-1409">
<status>Entry</status>
<desc>The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.shmoo.com/mail/bugtraq/jul98/msg00064.html">19980703 more about 'at'</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90233906612929&amp;w=2">19980805 irix-6.2 &quot;at -f&quot; vulnerability</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/security/advisories/NetBSD-SA1998-004.txt.asc">NetBSD-SA1998-004</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/331">331</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7577.php">at-f-read-files(7577)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1411" seq="1999-1411">
<status>Entry</status>
<desc>The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.</desc>
<refs>
<ref source="DEBIAN" url="http://lists.debian.org/debian-security-announce/debian-security-announce-1998/msg00033.html">19981126 new version of fsp fixes security flaw</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91228908407679&amp;w=2">19981128 Debian: Security flaw in FSP</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91244712808780&amp;w=2">19981130 Debian: Security flaw in FSP</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91936850009861&amp;w=2">19990217 Debian GNU/Linux 2.0r5 released (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/316">316</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7574.php">fsp-anon-ftp-access(7574)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1414" seq="1999-1414">
<status>Entry</status>
<desc>IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92765856706547&amp;w=2">19990525 Security Leak with IBM Netfinity Remote Control Software</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92902484317769&amp;w=2">19990609 IBM's response to &quot;Security Leak with IBM Netfinity Remote Control Software</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/284">284</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1419" seq="1999-1419">
<status>Entry</status>
<desc>Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/148">00148</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/219">219</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7535.php">sun-nisplus-bo(7535)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1423" seq="1999-1423">
<status>Entry</status>
<desc>ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319160&amp;w=2">19970626 Solaris Ping bug (DoS)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319171&amp;w=2">19970627 SUMMARY: Solaris Ping bug (DoS)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319181&amp;w=2">19970627 Solaris Ping bug(inetsvc)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319180&amp;w=2">19971005 Solaris Ping Bug and other [bc] oddities</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/146">00146</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/209">209</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7492.php">ping-multicast-loopback-dos(7492)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1432" seq="1999-1432">
<status>Entry</status>
<desc>Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525997&amp;w=2">19980716 Security risk with powermanagemnet on Solaris 2.6</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/160">160</ref>
<ref source="SUNBUG">4024179</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1433" seq="1999-1433">
<status>Entry</status>
<desc>HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525988&amp;w=2">19980715 JetAdmin software</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526067&amp;w=2">19980722 Re: JetAdmin software</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/157">157</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1437" seq="1999-1437">
<status>Entry</status>
<desc>ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525890&amp;w=2">19980707 ePerl: bad handling of ISINDEX queries</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525927&amp;w=2">19980710 ePerl Security Update Available</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/151">151</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1452" seq="1999-1452">
<status>Entry</status>
<desc>GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91764169410814&amp;w=2">19990129 ole objects in a &quot;secured&quot; environment?</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91822011021558&amp;w=2">19990205 Alert: MS releases GINA-fix for SP3, SP4, and TS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91788829326419&amp;w=2">19990129 ole objects in a &quot;secured&quot; environment?</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q214/8/02.asp">Q214802</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/198">198</ref>
<ref source="XF" url="http://xforce.iss.net/static/1975.php">nt-gina-clipboard(1975)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1455" seq="1999-1455">
<status>Entry</status>
<desc>RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q158/3/20.asp">Q158320</ref>
<ref source="XF" url="http://xforce.iss.net/static/7422.php">nt-rshsvc-ale-bypass(7422)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1456" seq="1999-1456">
<status>Entry</status>
<desc>thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/10368">19980819 thttpd 2.04 released (fwd)</ref>
<ref source="CONFIRM" url="http://www.acme.com/software/thttpd/thttpd.html#releasenotes">http://www.acme.com/software/thttpd/thttpd.html#releasenotes</ref>
<ref source="XF" url="http://xforce.iss.net/static/1809.php">thttpd-file-read(1809)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1468" seq="1999-1468">
<status>Entry</status>
<desc>rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.</desc>
<refs>
<ref source="MISC" url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-91.20.rdist.vulnerability">CA-91.20</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/31">31</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7160.php">rdist-popen-gain-privileges(7160)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8106">8106</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1472" seq="1999-1472">
<status>Entry</status>
<desc>Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87710897923098&amp;w=2">19971017 Security Hole in Explorer 4.0</ref>
<ref source="MISC" url="http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html">http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html</ref>
<ref source="CONFIRM" url="http://www.microsoft.com/Windows/ie/security/freiburg.asp">http://www.microsoft.com/Windows/ie/security/freiburg.asp</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/7/94.asp">Q176794</ref>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
<ref source="XF" url="http://xforce.iss.net/static/587.php">http-ie-spy(587)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7819">7819</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1473" seq="1999-1473">
<status>Entry</status>
<desc>When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the &quot;Page Redirect Issue.&quot;</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7426.php">ie-page-redirect(7426)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7818">7818</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1476" seq="1999-1476">
<status>Entry</status>
<desc>A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the &quot;Invalid Operand with Locked CMPXCHG8B Instruction&quot; problem.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q163/8/52.asp ">Q163852</ref>
<ref source="XF" url="http://xforce.iss.net/static/704.php">pentium-crash(704)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1478" seq="1999-1478">
<status>Entry</status>
<desc>The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827429589&amp;w=2">19990706 Bug in SUN's Hotspot VM</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93240220324183&amp;w=2">19990716 FW: (Review ID: 85125) Hotspot crashes bringing down webserver</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/522">522</ref>
<ref source="XF" url="http://xforce.iss.net/static/2348.php">sun-hotspot-vm(2348)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1481" seq="1999-1481">
<status>Entry</status>
<desc>Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33295">19991025 [squid] exploit for external authentication problem</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33295">19991103 [squid]exploit for external authentication problem</ref>
<ref source="CONFIRM" url="http://www.squid-cache.org/Versions/v2/2.2/bugs/">http://www.squid-cache.org/Versions/v2/2.2/bugs/</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/741">741</ref>
<ref source="XF" url="http://xforce.iss.net/static/3433.php">squid-proxy-auth-access(3433)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1486" seq="1999-1486">
<status>Entry</status>
<desc>sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="CONFIRM" url="http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info">http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX75554&amp;apar=only">IX75554</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76853&amp;apar=only">IX76853</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76330&amp;apar=only">IX76330</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/408">408</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7675">aix-sadc-timex(7675)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1488" seq="1999-1488">
<status>Entry</status>
<desc>sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.</desc>
<refs>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-079a.shtml">I-079A</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/371">371</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7217.php">ibm-sdr-read-files(7217)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1490" seq="1999-1490">
<status>Entry</status>
<desc>xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926021&amp;w=2">19980528 ALERT: Tiresome security hole in &quot;xosview&quot;, RedHat5.1?</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926034&amp;w=2">19980529 Re: Tiresome security hole in &quot;xosview&quot; (xosexp.c)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/362">362</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/8787.php">linux-xosview-bo(8787)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1494" seq="1999-1494">
<status>Entry</status>
<desc>colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/675">19940809 Re: IRIX 5.2 Security Advisory</ref>
<ref source="BUGTRAQ" url="http://www.tryc.on.ca/archives/bugtraq/1995_1/0614.html">19950307 sigh. another Irix 5.2 hole.</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950209-01-P">19950209-00-P</ref>
<ref source="XF" url="http://xforce.iss.net/static/2112.php">sgi-colorview(2112)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/336">336</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1507" seq="1999-1507">
<status>Entry</status>
<desc>Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-03.html">CA-1993-03</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/59">59</ref>
<ref source="XF" url="http://xforce.iss.net/static/521.php">sun-dir(521)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1512" seq="1999-1512">
<status>Entry</status>
<desc>The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93219846414732&amp;w=2">19990716 AMaViS virus scanner for Linux - root exploit</ref>
<ref source="CONFIRM" url="http://www.amavis.org/ChangeLog.txt">http://www.amavis.org/ChangeLog.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/527">527</ref>
<ref source="XF" url="http://xforce.iss.net/static/2349.php">amavis-command-execute(2349)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1520" seq="1999-1520">
<status>Entry</status>
<desc>A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92647407227303&amp;w=2">19990511 [ALERT] Site Server 3.0 May Expose SQL IDs and PSWs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/256">256</ref>
<ref source="XF" url="http://xforce.iss.net/static/2270.php">siteserver-site-csc(2270)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1530" seq="1999-1530">
<status>Entry</status>
<desc>cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94209954200450&amp;w=2">19991108 Security flaw in Cobalt RaQ2 cgiwrap</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225629200045&amp;w=2">19991109 [Cobalt] Security Advisory - cgiwrap</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/777">777</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7764.php">cobalt-cgiwrap-incorrect-permissions(7764)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/35">35</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1531" seq="1999-1531">
<status>Entry</status>
<desc>Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/763">763</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7767.php">ibm-homepageprint-bo(7767)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1535" seq="1999-1535">
<status>Entry</status>
<desc>Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93256878011447&amp;w=2">19990720 Buffer overflow in AspUpload 1.4</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93501427820328&amp;w=2">19990818 AspUpload Buffer Overflow Fixed</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/592">592</ref>
<ref source="XF" url="http://xforce.iss.net/static/3291.php">http-aspupload-bo(3291)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1537" seq="1999-1537">
<status>Entry</status>
<desc>IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827329577&amp;w=2">19990707 SSL and IIS.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/521">521</ref>
<ref source="XF" url="http://xforce.iss.net/static/2352.php">ssl-iis-dos(2352)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1542" seq="1999-1542">
<status>Entry</status>
<desc>RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the &quot;MAIL FROM&quot; command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915641729415&amp;w=2">19991004 RH6.0 local/remote command execution</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923853105687&amp;w=2">19991006 Fwd: [Re: RH6.0 local/remote command execution]</ref>
<ref source="XF" url="http://xforce.iss.net/static/3353.php">linux-rh-rpmmail(3353)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1550" seq="1999-1550">
<status>Entry</status>
<desc>bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the &quot;file&quot; parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217006208374&amp;w=2">19991108 BigIP - bigconf.cgi holes</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217879020184&amp;w=2">19991109 Re: BigIP - bigconf.cgi holes </ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225879703021&amp;w=2">19991109 </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/778">778</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/7771.php">bigip-bigconf-view-files(7771)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1556" seq="1999-1556">
<status>Entry</status>
<desc>Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222453431645&amp;w=2">19980629 MS SQL Server 6.5 stores password in unprotected registry keys</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/109">109</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7354">mssql-sqlexecutivecmdexec-password(7354)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1565" seq="1999-1565">
<status>Entry</status>
<desc>Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/24784">19990820 [SECURITY] New versions of man2html fixes postinst glitch</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6291">6291</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-1568" seq="1999-1568">
<status>Entry</status>
<desc>Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91981352617720&amp;w=2">19990223 NcFTPd remote buffer overflow</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12699">19990223 Comments on NcFTPd &quot;theoretical root compromise&quot;</ref>
<ref source="XF" url="http://xforce.iss.net/static/1833.php">ncftpd-port-bo(1833)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0001" seq="2000-0001">
<status>Entry</status>
<desc>RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.</desc>
<refs>
<ref source="BUGTRAQ">19991222 RealMedia Server 5.0 Crasher (rmscrash.c)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/888">888</ref>
<ref source="XF">realserver-ramgen-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0002" seq="2000-0002">
<status>Entry</status>
<desc>Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94598388530358&amp;w=2">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=36B0596E.8D111D66@teleline.es">20000128 ZBServer 1.50-r1x exploit (WinNT)</ref>
<ref source="VULNWATCH">20020114 ZBServer Pro DoS Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/889">889</ref>
<ref source="XF">zbserver-get-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0003" seq="2000-0003">
<status>Entry</status>
<desc>Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19991230 UnixWare rtpm exploit + discussion</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94908470928258&amp;w=2">20000127 New SCO patches...</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0004" seq="2000-0004">
<status>Entry</status>
<desc>ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606572912422&amp;w=2">19991223 Re: Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref>
<ref source="XF">zbserver-url-dot</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0006" seq="2000-0006">
<status>Entry</status>
<desc>strace allows local users to read arbitrary files via memory mapped file names.</desc>
<refs>
<ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/39831">19991225 strace can lie</ref>
<ref source="XF" url="http://xforce.iss.net/static/4554.php">linux-strace(4554)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0007" seq="2000-0007">
<status>Entry</status>
<desc>Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">19991230 PC-Cillin 6.x DoS Attack</ref>
<ref source="XF" url="http://xforce.iss.net/static/4491.php">pccillin-proxy-remote-dos(4491)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1740">1740</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0009" seq="2000-0009">
<status>Entry</status>
<desc>The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the &quot;rm&quot; program, which allows local users to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ">19991230 bna,sh</ref>
<ref source="XF">netarchitect-path-vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/907">907</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0010" seq="2000-0010">
<status>Entry</status>
<desc>WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.</desc>
<refs>
<ref source="BUGTRAQ">19991226 WebWho+ ADVISORY</ref>
<ref source="XF">http-cgi-webwhoplus</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0011" seq="2000-0011">
<status>Entry</status>
<desc>Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ">19991231 Local / Remote GET Buffer Overflow Vulnerability in AnalogX SimpleServer:WWW HTTP Server v1.1</ref>
<ref source="MISC" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref>
<ref source="XF">simpleserver-get-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/906">906</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1184">1184</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0012" seq="2000-0012">
<status>Entry</status>
<desc>Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">19991227 remote buffer overflow in miniSQL</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/898">898</ref>
<ref source="XF">w3-msql-scanf-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0013" seq="2000-0013">
<status>Entry</status>
<desc>IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program.</desc>
<refs>
<ref source="BUGTRAQ">19991231 irix-soundplayer.sh</ref>
<ref source="XF">irix-soundplayer-symlink</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/909">909</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0014" seq="2000-0014">
<status>Entry</status>
<desc>Denial of service in Savant web server via a null character in the requested URL.</desc>
<refs>
<ref source="BUGTRAQ">19991228 Local / Remote D.o.S Attack in Savant Web Server V2.0 WIN9X / NT / 2K</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/897">897</ref>
<ref source="XF">savant-server-null-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0015" seq="2000-0015">
<status>Entry</status>
<desc>CascadeView TFTP server allows local users to gain privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991231 tftpserv.sh</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/910">910</ref>
<ref source="XF">cascadeview-tftp-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0018" seq="2000-0018">
<status>Entry</status>
<desc>wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.</desc>
<refs>
<ref source="BUGTRAQ">19991221 Wmmon under FreeBSD</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/885">885</ref>
<ref source="XF">freebsd-wmmon-root-exploit</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1169">1169</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0020" seq="2000-0020">
<status>Entry</status>
<desc>DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.</desc>
<refs>
<ref source="NTBUGTRAQ">19991221 Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability</ref>
<ref source="BUGTRAQ">19991221 Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability</ref>
<ref source="XF">dnspro-flood-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0022" seq="2000-0022">
<status>Entry</status>
<desc>Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.</desc>
<refs>
<ref source="BUGTRAQ">19991221 serious Lotus Domino HTTP denial of service</ref>
<ref source="BUGTRAQ">19991227 Re: Lotus Domino HTTP denial of service attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0023" seq="2000-0023">
<status>Entry</status>
<desc>Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ">19991221 serious Lotus Domino HTTP denial of service</ref>
<ref source="BUGTRAQ">19991222 Lotus Notes HTTP cgi-bin vulnerability: possible workaround</ref>
<ref source="BUGTRAQ">19991227 Re: Lotus Domino HTTP denial of service attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref>
<ref source="OSVDB" url="http://www.osvdb.org/51">51</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0024" seq="2000-0024">
<status>Entry</status>
<desc>IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the &quot;Escape Character Parsing&quot; vulnerability.</desc>
<refs>
<ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-061.asp">MS99-061</ref>
<ref source="BUGTRAQ">19991228 Third Party Software Affected by IIS &quot;Escape Character Parsing&quot; Vulnerability</ref>
<ref source="BUGTRAQ">19991229 More info on MS99-061 (IIS escape character vulnerability)</ref>
<ref source="XF">iis-badescapes</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246401">Q246401</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0025" seq="2000-0025">
<status>Entry</status>
<desc>IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the &quot;Virtual Directory Naming&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-058.mspx">MS99-058</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q238606">Q238606</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8098">8098</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0026" seq="2000-0026">
<status>Entry</status>
<desc>Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.</desc>
<refs>
<ref source="BUGTRAQ">19991222 UnixWare i2odialogd remote root exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/876">876</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6310">6310</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0027" seq="2000-0027">
<status>Entry</status>
<desc>IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39962">19991227 IBM NetStation/UnixWare local root exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/900">900</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/5381.php">ibm-netstat-race-condition(5381)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0029" seq="2000-0029">
<status>Entry</status>
<desc>UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19991227 UnixWare local pis exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/901">901</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0030" seq="2000-0030">
<status>Entry</status>
<desc>Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.</desc>
<refs>
<ref source="BUGTRAQ">19991222 Solaris 2.7 dmispd local/remote problems</ref>
<ref source="XF">sol-dmispd-fill-disk</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/878">878</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0031" seq="2000-0031">
<status>Entry</status>
<desc>The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.</desc>
<refs>
<ref source="L0PHT">19991227 initscripts-4.48-1 RedHat Linux 6.1</ref>
<ref source="REDHAT">RHSA-1999:052-04</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0032" seq="2000-0032">
<status>Entry</status>
<desc>Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.</desc>
<refs>
<ref source="BUGTRAQ">19991222 Solaris 2.7 dmispd local/remote problems</ref>
<ref source="XF">sol-dmispd-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/878">878</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7582">7582</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0033" seq="2000-0033">
<status>Entry</status>
<desc>InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.</desc>
<refs>
<ref source="BUGTRAQ">19991227 Trend Micro InterScan VirusWall SMTP bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/899">899</ref>
<ref source="XF">interscan-viruswall-bypass</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0034" seq="2000-0034">
<status>Entry</status>
<desc>Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled &quot;remember passwords.&quot;</desc>
<refs>
<ref source="BUGTRAQ">19991222 More Netscape Passwords Available.</ref>
<ref source="XF">netscape-password-preferences</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0036" seq="2000-0036">
<status>Entry</status>
<desc>Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the &quot;HTML Mail Attachment&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-060.asp">MS99-060</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q249082">Q249082</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0037" seq="2000-0037">
<status>Entry</status>
<desc>Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.</desc>
<refs>
<ref source="BUGTRAQ">19991228 majordomo local exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref>
<ref source="BUGTRAQ">20000124 majordomo 1.94.5 does not fix all vulnerabilities</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-005.html">RHSA-2000:005</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/903">903</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0039" seq="2000-0039">
<status>Entry</status>
<desc>AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.</desc>
<refs>
<ref source="BUGTRAQ">19991229 AltaVista</ref>
<ref source="BUGTRAQ">19991230 Follow UP AltaVista</ref>
<ref source="BUGTRAQ">19991229 AltaVista followup and monitor script</ref>
<ref source="BUGTRAQ">20000103 FW: Patch issued for AltaVista Search Engine Directory TraversalVulnerability</ref>
<ref source="BUGTRAQ">20000109 Altavista followup</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/896">896</ref>
<ref source="OSVDB" url="http://www.osvdb.org/15">15</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0040" seq="2000-0040">
<status>Entry</status>
<desc>glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.</desc>
<refs>
<ref source="BUGTRAQ">19991223 Multiple vulnerabilites in glFtpD (current versions)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0041" seq="2000-0041">
<status>Entry</status>
<desc>Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.</desc>
<refs>
<ref source="BUGTRAQ">19991229 The &quot;Mac DoS Attack,&quot; a Scheme for Blocking Internet Connections</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/890">890</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0042" seq="2000-0042">
<status>Entry</status>
<desc>Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.</desc>
<refs>
<ref source="BUGTRAQ">19991229 Local / Remote D.o.S Attack in  CSM Mail Server for Windows 95/NT v.2000.08.A</ref>
<ref source="XF">csm-server-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/895">895</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0043" seq="2000-0043">
<status>Entry</status>
<desc>Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ">19991230 Local / Remote GET Buffer Overflow Vulnerability in CamShot WebCam HTTP Server v2.5 for Win9x/NT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/905">905</ref>
<ref source="XF">camshot-http-get-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0044" seq="2000-0044">
<status>Entry</status>
<desc>Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.</desc>
<refs>
<ref source="BUGTRAQ">20000105 SECURITY ALERT - WAR FTP DAEMON ALL VERSIONS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/919">919</ref>
<ref source="XF">warftp-macro-access-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0045" seq="2000-0045">
<status>Entry</status>
<desc>MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.</desc>
<refs>
<ref source="BUGTRAQ">20000111 Serious bug in MySQL password handling.</ref>
<ref source="BUGTRAQ">20000113 New MySQL Available</ref>
<ref source="XF">mysql-pwd-grant</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/926">926</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0048" seq="2000-0048">
<status>Entry</status>
<desc>get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program.</desc>
<refs>
<ref source="BUGTRAQ">20000112 Serious Bug in Corel Linux.(Local root exploit)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/928">928</ref>
<ref source="CONFIRM" url="http://linux.corel.com/support/clos_patch1.htm">http://linux.corel.com/support/clos_patch1.htm</ref>
<ref source="XF">linux-corel-update</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0050" seq="2000-0050">
<status>Entry</status>
<desc>The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=13976&amp;Method=Full">ASB00-01</ref>
<ref source="XF">allaire-webtop-access</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/915">915</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0051" seq="2000-0051">
<status>Entry</status>
<desc>The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting data collections for indexing via a URL.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=13977&amp;Method=Full">ASB00-02</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/916">916</ref>
<ref source="XF">allaire-spectra-config-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0052" seq="2000-0052">
<status>Entry</status>
<desc>Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.</desc>
<refs>
<ref source="L0PHT" url="http://www.l0pht.com/advisories/pam_advisory">20000104 PamSlam</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-001.html">RHSA-2000:001</ref>
<ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=linux-pam-userhelper">linux-pam-userhelper</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/913">913</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0053" seq="2000-0053">
<status>Entry</status>
<desc>Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-001.asp">MS00-001</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q246731">Q246731</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/912">912</ref>
<ref source="XF">mcis-malformed-imap</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0056" seq="2000-0056">
<status>Entry</status>
<desc>IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.</desc>
<refs>
<ref source="BUGTRAQ">20000105 Local / Remote D.o.S Attack in IMail IMONITOR Server for WinNT Version 5.08</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/914">914</ref>
<ref source="XF">imail-imonitor-status-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0057" seq="2000-0057">
<status>Entry</status>
<desc>Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=13978&amp;Method=Full">ASB00-03</ref>
<ref source="XF">coldfusion-cfcache</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/917">917</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0060" seq="2000-0060">
<status>Entry</status>
<desc>Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94647711311057&amp;w=2">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94633851427858&amp;w=2">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/894">894</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3765.php">avirt-rover-pop3-dos(3765)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0062" seq="2000-0062">
<status>Entry</status>
<desc>The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000104222219.B41650@schvin.net">20000104 [petrilli@digicool.com: [Zope] SECURITY ALERT]</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/922">922</ref>
<ref source="XF">zope-dtml</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0063" seq="2000-0063">
<status>Entry</status>
<desc>cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script.</desc>
<refs>
<ref source="BUGTRAQ">20000118 Nortel Contivity Vulnerability</ref>
<ref source="XF">http-cgi-cgiproc-file-read</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/938">938</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0064" seq="2000-0064">
<status>Entry</status>
<desc>cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">20000118 Nortel Contivity Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/938">938</ref>
<ref source="XF">http-cgi-cgiproc-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7583">7583</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0065" seq="2000-0065">
<status>Entry</status>
<desc>Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.</desc>
<refs>
<ref source="NTBUGTRAQ">20000117 Remote Buffer Exploit - InetServ 3.0</ref>
<ref source="XF">inetserv-get-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0070" seq="2000-0070">
<status>Entry</status>
<desc>NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka &quot;Spoofed LPC Port Request.&quot;</desc>
<refs>
<ref source="BINDVIEW" url="http://www.bindview.com/security/advisory/adv_NtImpersonate.html">20000113 Local Promotion Vulnerability in Windows NT 4</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-003.asp">MS00-003</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q247869">Q247869</ref>
<ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=nt-spoofed-lpc-port">nt-spoofed-lpc-port</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/934">934</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0072" seq="2000-0072">
<status>Entry</status>
<desc>Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94823061421676&amp;w=2">20000118 Warning: VCasel security hole.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/937">937</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/3867.php">vcasel-filename-trusting(3867)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0073" seq="2000-0073">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-005.asp">MS00-005</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q249973">Q249973</ref>
<ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=win-malformed-rtf-control-word">win-malformed-rtf-control-word</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0075" seq="2000-0075">
<status>Entry</status>
<desc>Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session.</desc>
<refs>
<ref source="NTBUGTRAQ">20000113 Local / Remote D.o.S Attack in Super Mail Transfer Package (SMTP) Server for WinNT Version 1.9x</ref>
<ref source="BUGTRAQ">20000113 Local / Remote D.o.S Attack in Super Mail Transfer Package (SMTP) Server for WinNT Version 1.9x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/930">930</ref>
<ref source="XF">supermail-memleak-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0076" seq="2000-0076">
<status>Entry</status>
<desc>nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94709988232618&amp;w=2">19991230 vibackup.sh</ref>
<ref source="DEBIAN">20000108</ref>
<ref source="XF">nvi-delete-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1439">1439</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0080" seq="2000-0080">
<status>Entry</status>
<desc>AIX techlibss allows local users to overwrite files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94757136413681&amp;w=2">20000110 2nd attempt: AIX techlibss follows links</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/931">931</ref>
<ref source="XF">aix-techlibss-symbolic-link</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0083" seq="2000-0083">
<status>Entry</status>
<desc>HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=2031">HPSBUX0001-109</ref>
<ref source="XF">hp-audio-security-perms</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0087" seq="2000-0087">
<status>Entry</status>
<desc>Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94790377622943&amp;w=2">20000113 Misleading sense of security in Netscape</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/4385.php">netscape-mail-notify-plaintext(4385)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0088" seq="2000-0088">
<status>Entry</status>
<desc>Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the &quot;Malformed Conversion Data&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-002.mspx">MS00-002</ref>
<ref source="XF">office-malformed-convert</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/946">946</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0089" seq="2000-0089">
<status>Entry</status>
<desc>The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the &quot;RDISK Registry Enumeration File&quot; vulnerability.</desc>
<refs>
<ref source="NTBUGTRAQ">20000121 RDISK registry enumeration file vulnerability in Windows NT 4.0 Terminal Server Edition</ref>
<ref source="BUGTRAQ">20000122 RDISK registry enumeration file vulnerability in Windows NT 4.0 Terminal Server Edition</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-004.mspx">MS00-004</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q249108">Q249108</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/947">947</ref>
<ref source="XF">nt-rdisk-enum-file</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0090" seq="2000-0090">
<status>Entry</status>
<desc>VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">20000124 VMware 1.1.2 Symlink Vulnerability</ref>
<ref source="XF">linux-vmware-symlink</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/943">943</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1205">1205</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0091" seq="2000-0091">
<status>Entry</status>
<desc>Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.</desc>
<refs>
<ref source="BUGTRAQ">20000122 remote root qmail-pop with vpopmail advisory and exploit with patch</ref>
<ref source="BUGTRAQ">20000123 Re: vpopmail/vchkpw remote root exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/942">942</ref>
<ref source="MISC" url="http://www.inter7.com/vpopmail/ChangeLog">http://www.inter7.com/vpopmail/ChangeLog</ref>
<ref source="MISC" url="http://www.inter7.com/vpopmail/">http://www.inter7.com/vpopmail/</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0092" seq="2000-0092">
<status>Entry</status>
<desc>The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:01.make.asc">FreeBSD-SA-00:01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/939">939</ref>
<ref source="XF">gnu-makefile-tmp-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0094" seq="2000-0094">
<status>Entry</status>
<desc>procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.</desc>
<refs>
<ref source="BUGTRAQ">20000121 *BSD procfs vulnerability</ref>
<ref source="FREEBSD">FreeBSD-SA-00:02</ref>
<ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-001.txt.asc">NetBSD-SA2000-001</ref>
<ref source="OPENBSD">20000120 [2.6] 018: SECURITY FIX: Jan 20, 2000</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/940">940</ref>
<ref source="OSVDB" url="http://www.osvdb.org/20760">20760</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3995">netbsd-procfs(3995)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0095" seq="2000-0095">
<status>Entry</status>
<desc>The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=2041">HPSBUX0001-110</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/944">944</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0097" seq="2000-0097">
<status>Entry</status>
<desc>The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the &quot;Malformed Hit-Highlighting Argument&quot; vulnerability.</desc>
<refs>
<ref source="NTBUGTRAQ">20000127 Alert: MS IIS 4 / IS 2 (Cerberus Security Advisory CISADV000126)</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp">MS00-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/950">950</ref>
<ref source="XF">http-indexserver-dirtrans</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1210">1210</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0098" seq="2000-0098">
<status>Entry</status>
<desc>Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp">MS00-006</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0099" seq="2000-0099">
<status>Entry</status>
<desc>Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94848865112897&amp;w=2">20000119 Unixware ppptalk</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0100" seq="2000-0100">
<status>Entry</status>
<desc>The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/current/0045.html">20000115 Security Vulnerability with SMS 2.0 Remote Control</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-012.asp">MS00-012</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0107" seq="2000-0107">
<status>Entry</status>
<desc>Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000201">20000201</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/958">958</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0111" seq="2000-0111">
<status>Entry</status>
<desc>The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.</desc>
<refs>
<ref source="BUGTRAQ">20000129 [LoWNOISE] Rightfax web client 5.2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/953">953</ref>
<ref source="XF">avt-rightfax-predict-session</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0112" seq="2000-0112">
<status>Entry</status>
<desc>The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94973075614088&amp;w=2">20000202 vulnerability in Linux Debian default boot configuration</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/960">960</ref>
<ref source="XF">debian-mbr-bypass-security</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0113" seq="2000-0113">
<status>Entry</status>
<desc>The SyGate Remote Management program does not properly restrict access to its administration service, which allows remote attackers to cause a denial of service, or access network traffic statistics.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94934808714972&amp;w=2">20000128 SyGate 3.11 Port 7323 / Remote Admin hole</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94952641025328&amp;w=2">20000202 SV: SyGate 3.11 Port 7323 / Remote Admin hole</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94973281714994&amp;w=2">20000203 UPDATE: Sygate 3.11 Port 7323 Telnet Hole</ref>
<ref source="CONFIRM" url="http://www.sybergen.com/support/fix.htm">http://www.sybergen.com/support/fix.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/952">952</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0116" seq="2000-0116">
<status>Entry</status>
<desc>Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the &quot;Strip Script Tags&quot; restriction by including an extra &lt; in front of the SCRIPT tag.</desc>
<refs>
<ref source="NTBUGTRAQ">20000129 &quot;Strip Script Tags&quot; in FW-1 can be circumvented</ref>
<ref source="BUGTRAQ">20000129 &quot;Strip Script Tags&quot; in FW-1 can be circumvented</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/954">954</ref>
<ref source="XF">http-script-bypass</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1212">1212</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0117" seq="2000-0117">
<status>Entry</status>
<desc>The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).</desc>
<refs>
<ref source="BUGTRAQ">20000127 Cobalt RaQ2 - a user of mine changed my admin password..</ref>
<ref source="BUGTRAQ">20000131 [ Cobalt ] Security Advisory -- 01.31.2000</ref>
<ref source="XF">http-cgi-cobalt-passwords</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/951">951</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0120" seq="2000-0120">
<status>Entry</status>
<desc>The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.</desc>
<refs>
<ref source="ALLAIRE">ASB00-04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/955">955</ref>
<ref source="XF" url="http://xforce.iss.net/static/4025.php">allaire-spectra-ras-access(4025)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0121" seq="2000-0121">
<status>Entry</status>
<desc>The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the &quot;Recycle Bin Creation&quot; vulnerability.</desc>
<refs>
<ref source="NTBUGTRAQ">20000201 &quot;Recycle Bin Creation&quot; Vulnerability in Windows NT / Windows 2000</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-007.mspx">MS00-007</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q248399">Q248399</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/963">963</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0127" seq="2000-0127">
<status>Entry</status>
<desc>The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.</desc>
<refs>
<ref source="BUGTRAQ">20000203 Webspeed security issue</ref>
<ref source="CONFIRM" url="http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&amp;keywords=security%20Webspeed">http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&amp;keywords=security%20Webspeed</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/969">969</ref>
<ref source="XF">webspeed-adminutil-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0128" seq="2000-0128">
<status>Entry</status>
<desc>The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">20000204 &quot;The Finger Server&quot;</ref>
<ref source="CONFIRM" url="http://www.glazed.org/finger/changelog.txt">http://www.glazed.org/finger/changelog.txt</ref>
<ref source="XF">finger-server-input</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7610">7610</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0130" seq="2000-0130">
<status>Entry</status>
<desc>Buffer overflow in SCO scohelp program allows remote attackers to execute commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94908470928258&amp;w=2">20000127 New SCO patches...</ref>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.02a">SB-00.02a</ref>
<ref source="XF">sco-help-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0131" seq="2000-0131">
<status>Entry</status>
<desc>Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94960703721503&amp;w=2">20000201 war-ftpd 1.6x DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/966">966</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4677">4677</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0139" seq="2000-0139">
<status>Entry</status>
<desc>Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95021326417936&amp;w=2">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/982">982</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0140" seq="2000-0140">
<status>Entry</status>
<desc>Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service via a large number of connections.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95021326417936&amp;w=2">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
<ref source="NTBUGTRAQ">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/980">980</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0141" seq="2000-0141">
<status>Entry</status>
<desc>Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-8&amp;msg=20000211224935.A13236@infomag.ape.relarn.ru">20000211 perl-cgi hole in UltimateBB by Infopop Corp.</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl">20000225 FW: Important UBB News For Licensed Users</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/991">991</ref>
<ref source="MISC" url="http://www.ultimatebb.com/home/versions.shtml">http://www.ultimatebb.com/home/versions.shtml</ref>
<ref source="XF">http-cgi-ultimatebb</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0144" seq="2000-0144">
<status>Entry</status>
<desc>Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0034.html">20000207 Infosec.20000207.axis700.a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/971">971</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0145" seq="2000-0145">
<status>Entry</status>
<desc>The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.</desc>
<refs>
<ref source="BUGTRAQ">20000205 Debian (frozen): Perms on /usr/lib/libguile.so.6.0.0</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0146" seq="2000-0146">
<status>Entry</status>
<desc>The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0049.html">20000207 Novell GroupWise 5.5 Enhancement Pack Web Access Denial of Servic e</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/972">972</ref>
<ref source="XF">novell-groupwise-url-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0148" seq="2000-0148">
<status>Entry</status>
<desc>MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0053.html">20000208 Remote access vulnerability in all MySQL server versions</ref>
<ref source="BUGTRAQ">20000214 MySQL 3.22.32 released</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/975">975</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0149" seq="2000-0149">
<status>Entry</status>
<desc>Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL.</desc>
<refs>
<ref source="BUGTRAQ">20000209 [SAFER 000209.EXP.1.2] Zeus Web Server - obtaining source of CGI scripts</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0057.html">20000208 Zeus Web Server: Null Terminated Strings</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/977">977</ref>
<ref source="OSVDB" url="http://www.osvdb.org/254">254</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3982">zeus-server-null-string(3982)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0150" seq="2000-0150">
<status>Entry</status>
<desc>Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.</desc>
<refs>
<ref source="BUGTRAQ">20000209 FireWall-1 FTP Server Vulnerability</ref>
<ref source="BUGTRAQ">20000212 Re: FireWall-1 FTP Server Vulnerability</ref>
<ref source="BUGTRAQ">20000210 Multiple firewalls: FTP Application Level Gateway &quot;PASV&quot; Vulnerability</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/328867">VU#328867</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/979">979</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4417">4417</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0152" seq="2000-0152">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000.</desc>
<refs>
<ref source="BUGTRAQ">20000209 Novell BorderManager 3.5 Remote Slow Death</ref>
<ref source="BUGTRAQ">20000211 BorderManager csatpxy.nlm fix avalable.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/976">976</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7468">7468</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0156" seq="2000-0156">
<status>Entry</status>
<desc>Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the &quot;Image Source Redirect&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-009.mspx">MS00-009</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7827">7827</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3996">ie-image-source-redirect(3996)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0157" seq="2000-0157">
<status>Entry</status>
<desc>NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.</desc>
<refs>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-012.txt.asc">1999-012</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/992">992</ref>
<ref source="XF">netbsd-ptrace</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0159" seq="2000-0159">
<status>Entry</status>
<desc>HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=20000217160216.13708.qmail@underground.org">HPSBUX0002-111</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0161" seq="2000-0161">
<status>Entry</status>
<desc>Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-010.asp">MS00-010</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/994">994</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0162" seq="2000-0162">
<status>Entry</status>
<desc>The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the &quot;VM File Reading&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-011.asp">MS00-011</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0164" seq="2000-0164">
<status>Entry</status>
<desc>The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.SOL.4.21.0002200031320.22675-100000@klayman.hq.formus.pl">20000220 Sun Internet Mail Server</ref>
<ref source="SUNBUG">4316521</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1004">1004</ref>
<ref source="XF">sims-temp-world-readable</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0165" seq="2000-0165">
<status>Entry</status>
<desc>The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.</desc>
<refs>
<ref source="BUGTRAQ">20000210 Re: application proxies?</ref>
<ref source="FREEBSD" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.BSF.4.21.0002192249290.10784-100000@freefall.freebsd.org">FreeBSD-SA-00:04</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-023.shtml">K-023</ref>
<ref source="XF">delegate-proxy-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0166" seq="2000-0166">
<status>Entry</status>
<desc>Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPGEJHCCAA.labs@ussrback.com">20000221 Local / Remote Exploiteable Buffer Overflow Vulnerability in InterAccess TelnetD Server 4.0 for Windows NT</ref>
<ref source="BUGTRAQ">20000223 Pragma Systems response to USSRLabs report</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/995">995</ref>
<ref source="XF">interaccess-telnet-login-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0168" seq="2000-0168">
<status>Entry</status>
<desc>Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the &quot;DOS Device in Path Name&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCENECCAA.labs@ussrback.com">20000306 con\con is a old thing (anyway is cool)</ref>
<ref source="MS" url="http://www.securityfocus.com/templates/advisory.html?id=2126">MS00-017</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1043">1043</ref>
<ref source="XF">win-dos-devicename-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0169" seq="2000-0169">
<status>Entry</status>
<desc>Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&amp;'.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0211.html">20000314 Oracle Web Listener 4.0.x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1053">1053</ref>
<ref source="XF">oracle-weblistener-remote-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0170" seq="2000-0170">
<status>Entry</status>
<desc>Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">20000226 man bugs might lead to root compromise (RH 6.1 and other boxes)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1011">1011</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0171" seq="2000-0171">
<status>Entry</status>
<desc>atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0102.html">20000311 TESO advisory -- atsadc</ref>
<ref source="XF">atsar-root-access</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1048">1048</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0172" seq="2000-0172">
<status>Entry</status>
<desc>The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">20000303 Potential security problem with mtr</ref>
<ref source="DEBIAN">20000309 mtr</ref>
<ref source="FREEBSD">FreeBSD-SA-00:09</ref>
<ref source="BUGTRAQ">20000308 [TL-Security-Announce] mtr-0.41 and earlier TLSA2000003-1 (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1038">1038</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0174" seq="2000-0174">
<status>Entry</status>
<desc>StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1040">1040</ref>
<ref source="XF">staroffice-scheduler-fileread</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0175" seq="2000-0175">
<status>Entry</status>
<desc>Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref>
<ref source="XF">staroffice-scheduler-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1039">1039</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0178" seq="2000-0178">
<status>Entry</status>
<desc>ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.</desc>
<refs>
<ref source="BUGTRAQ">20000227 Advisory: Foundry Networks ServerIron TCP/IP sequence predictability</ref>
<ref source="MISC" url="http://www.foundrynet.com/bugTraq.html">http://www.foundrynet.com/bugTraq.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1017">1017</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0179" seq="2000-0179">
<status>Entry</status>
<desc>HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0387.html">20000228 HP Omniback remote DoS</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0006-115">HPSBUX0006-115</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1015">1015</ref>
<ref source="XF">omniback-connection-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0180" seq="2000-0180">
<status>Entry</status>
<desc>Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0201.html">20000313 SOJOURN Search engine exposes files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1052">1052</ref>
<ref source="XF" url="http://xforce.iss.net/static/4197.php">sojourn-file-read(4197)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0181" seq="2000-0181">
<status>Entry</status>
<desc>Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0119.html">20000311 Our old friend Firewall-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1054">1054</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1256">1256</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0182" seq="2000-0182">
<status>Entry</status>
<desc>iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.</desc>
<refs>
<ref source="BUGTRAQ">20000223 DoS for the iPlanet Web Server, Enterprise Edition 4.1</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0183" seq="2000-0183">
<status>Entry</status>
<desc>Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0093.html">20000310 Fwd: ircii-4.4 buffer overflow</ref>
<ref source="FREEBSD">FreeBSD-SA-00:11</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-008.html">RHSA-2000:008</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1046">1046</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0184" seq="2000-0184">
<status>Entry</status>
<desc>Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0082.html">20000309</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1037">1037</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0185" seq="2000-0185">
<status>Entry</status>
<desc>RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0069.html">20000308 RealServer exposes internal IP addresses</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1049">1049</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0186" seq="2000-0186">
<status>Entry</status>
<desc>Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ">20000228 [ Hackerslab bug_paper ] Linux dump buffer overflow</ref>
<ref source="TURBO">TLSA200007-1</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-100.html">RHSA-2000:100</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1020">1020</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0189" seq="2000-0189">
<status>Entry</status>
<desc>ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.</desc>
<refs>
<ref source="NTBUGTRAQ">20000301 ColdFusions application.cfm shows full path</ref>
<ref source="BUGTRAQ">20000305 ColdFusion Bug: Application.cfm shows full path</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1021">1021</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0191" seq="2000-0191">
<status>Entry</status>
<desc>Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=41256894.00492503.00@mailgw.backupcentralen.se">20000229 Infosec.20000229.axisstorpointcd.a</ref>
<ref source="XF">axis-storpoint-auth</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1025">1025</ref>
<ref source="OSVDB" url="http://www.osvdb.org/19">19</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0192" seq="2000-0192">
<status>Entry</status>
<desc>The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0029.html">20000304 OpenLinux 2.3: rpm_query</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1036">1036</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0193" seq="2000-0193">
<status>Entry</status>
<desc>The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003020436.PAA20168@jawa.chilli.net.au">20000302 Corel Linux 1.0 dosemu default configuration: Local root vuln</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1030">1030</ref>
<ref source="XF">linux-dosemu-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0194" seq="2000-0194">
<status>Entry</status>
<desc>buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html">20000224 Corel Linux 1.0 local root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1007">1007</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0195" seq="2000-0195">
<status>Entry</status>
<desc>setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverrc file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html">20000224 Corel Linux 1.0 local root compromise</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1008">1008</ref>
<ref source="XF">corel-linux-setxconf-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0196" seq="2000-0196">
<status>Entry</status>
<desc>Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.</desc>
<refs>
<ref source="DEBIAN">20000229</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-006.html">RHSA-2000:006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1018">1018</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0200" seq="2000-0200">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the &quot;Clip Art Buffer Overrun&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-015.mspx">MS00-015</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1034">1034</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0201" seq="2000-0201">
<status>Entry</status>
<desc>The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.</desc>
<refs>
<ref source="BUGTRAQ">20000301 IE 5.x allows executing arbitrary programs using .chm files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1033">1033</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0202" seq="2000-0202">
<status>Entry</status>
<desc>Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-014.mspx">MS00-014</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1041">1041</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0206" seq="2000-0206">
<status>Entry</status>
<desc>The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0023.html">20000305 Oracle installer problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1035">1035</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0207" seq="2000-0207">
<status>Entry</status>
<desc>SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">20000301 infosrch.cgi vulnerability (IRIX 6.5)</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20000501-01-P">20000501-01-P</ref>
<ref source="XF">irix-infosrch-fname</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1031">1031</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0208" seq="2000-0208">
<status>Entry</status>
<desc>The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.</desc>
<refs>
<ref source="BUGTRAQ">20000228 ht://Dig remote information exposure</ref>
<ref source="FREEBSD">FreeBSD-SA-00:06</ref>
<ref source="DEBIAN">20000227</ref>
<ref source="TURBO">TLSA200005-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1026">1026</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0209" seq="2000-0209">
<status>Entry</status>
<desc>Buffer overflow in Lynx 2.x allows remote attackers to crash Lynx and possibly execute commands via a long URL in a malicious web page.</desc>
<refs>
<ref source="BUGTRAQ">20000227 lynx - someone is deaf and blind ;)</ref>
<ref source="FREEBSD">FreeBSD-SA-00:08</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1012">1012</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0210" seq="2000-0210">
<status>Entry</status>
<desc>The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ">20000221 flex license manager tempfile predictable name...</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/998">998</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0211" seq="2000-0211">
<status>Entry</status>
<desc>The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the &quot;Misordered Windows Media Services Handshake&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-013.mspx">MS00-013</ref>
<ref source="XF">win-media-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1000">1000</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0212" seq="2000-0212">
<status>Entry</status>
<desc>InterAccess TelnetID Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information.</desc>
<refs>
<ref source="BUGTRAQ">20000224 Local / Remote D.o.S Attack in InterAccess TelnetD Server Release 4.0 *ALL BUILDS* for WinNT Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1001">1001</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4033">interaccess-telnet-dos(4033)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0215" seq="2000-0215">
<status>Entry</status>
<desc>Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.</desc>
<refs>
<ref source="SCO">SB-00.05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1019">1019</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0217" seq="2000-0217">
<status>Entry</status>
<desc>The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.</desc>
<refs>
<ref source="BUGTRAQ">20000224 SSH &amp; xauth</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1006">1006</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0218" seq="2000-0218">
<status>Entry</status>
<desc>Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.</desc>
<refs>
<ref source="SUSE">20000210 util &lt; 2.10f</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-002.0.txt">CSSA-2000-002.0</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6980">6980</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7004">7004</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0221" seq="2000-0221">
<status>Entry</status>
<desc>The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP port.</desc>
<refs>
<ref source="BUGTRAQ">20000225 Scorpion Marlin</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1009">1009</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0222" seq="2000-0222">
<status>Entry</status>
<desc>The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000215155750.M4500@safe.hsc.fr">20000215 Windows 2000 installation process weakness</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/990">990</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0223" seq="2000-0223">
<status>Entry</status>
<desc>Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0107.html">20000311 TESO advisory -- wmcdplay</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1047">1047</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0224" seq="2000-0224">
<status>Entry</status>
<desc>ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.</desc>
<refs>
<ref source="NAI" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000101bf78af$94528870$4d2f45a1@jmagdych.na.nai.com">20000215 ARCserve symlink vulnerability</ref>
<ref source="SCO">SSE063</ref>
<ref source="XF">sco-openserver-arc-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0225" seq="2000-0225">
<status>Entry</status>
<desc>The Pocsag POC32 program does not properly prevent remote users from accessing its server port, even if the option has been disabled.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=003601bf854b$6893a090$0100a8c0@FIREWALKER">20000303 Pocsag remote access to client can't be disabled.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1032">1032</ref>
<ref source="XF">telnet-pocsag</ref>
<ref source="OSVDB" url="http://www.osvdb.org/259">259</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0226" seq="2000-0226">
<status>Entry</status>
<desc>IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the &quot;Chunked Transfer Encoding Buffer Overflow Vulnerability.&quot;</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-018.asp">MS00-018</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1066">1066</ref>
<ref source="XF">iis-chunked-encoding-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0228" seq="2000-0228">
<status>Entry</status>
<desc>Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the &quot;Malformed Media License Request&quot; Vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-016.asp">MS00-016</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1058">1058</ref>
<ref source="XF">mwmt-malformed-media-license</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0229" seq="2000-0229">
<status>Entry</status>
<desc>gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0242.html">20000322 gpm-root</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_45.html">20000405 Security hole in gpm &lt; 1.18.1</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-009.html">RHSA-2000:009</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-045.html">RHSA-2000:045</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1069">1069</ref>
<ref source="XF">linux-gpm-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0230" seq="2000-0230">
<status>Entry</status>
<desc>Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0168.html">20000316 TESO &amp; C-Skills development advisory -- imwheel</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-016.html">RHSA-2000:016</ref>
<ref source="XF">linux-imwheel-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1060">1060</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0231" seq="2000-0231">
<status>Entry</status>
<desc>Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0162.html">20000316 &quot;TESO &amp; C-Skills development advisory -- kreatecd&quot; at:</ref>
<ref source="SUSE">20000405 Security hole in kreatecd &lt; 0.3.8b</ref>
<ref source="XF">linux-kreatecd-path</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1061">1061</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0232" seq="2000-0232">
<status>Entry</status>
<desc>Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-021.asp">MS00-021</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0306.html">20000330 Remote DoS Attack in Windows 2000/NT 4.0 TCP/IP Print Request Server Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1082">1082</ref>
<ref source="XF">win-tcpip-printing-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0233" seq="2000-0233">
<status>Entry</status>
<desc>SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges.</desc>
<refs>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/vendor/2000-q1/0035.html">20000327 Security hole in SuSE Linux IMAP Server</ref>
<ref source="XF">linux-imap-remote-unauthorized-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0234" seq="2000-0234">
<status>Entry</status>
<desc>The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000330220757.28456.qmail@securityfocus.com">20000330 Cobalt apache configuration exposes .htaccess</ref>
<ref source="CONFIRM" url="http://www.securityfocus.com/templates/advisory.html?id=2150">http://www.securityfocus.com/templates/advisory.html?id=2150</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1083">1083</ref>
<ref source="XF">cobalt-raq-remote-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0235" seq="2000-0235">
<status>Entry</status>
<desc>Buffer overflow in the huh program in the orville-write package allows local users to gain root privileges.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:10-orville-write.asc">FreeBSD-SA-00:10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1070">1070</ref>
<ref source="XF">freebsd-orvillewrite-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1263">1263</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0236" seq="2000-0236">
<status>Entry</status>
<desc>Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38D2173D.24E39DD0@relaygroup.com">20000317 [SAFER 000317.EXP.1.5] Netscape Enterprise Server and '?wp' tags</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1063">1063</ref>
<ref source="XF">netscape-server-directory-indexing</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0237" seq="2000-0237">
<status>Entry</status>
<desc>Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.</desc>
<refs>
<ref source="MISC" url="http://zsh.stupidphat.com/advisory.cgi?000311-1">http://zsh.stupidphat.com/advisory.cgi?000311-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1075">1075</ref>
<ref source="XF">netscape-webpublisher-invalid-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0238" seq="2000-0238">
<status>Entry</status>
<desc>Buffer overflow in the web server for Norton AntiVirus for Internet Email Gateways allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=s8d1f3e3.036@kib.co.kodiak.ak.us">20000317 DoS with NAVIEG</ref>
<ref source="XF">nav-email-gateway-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1064">1064</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0240" seq="2000-0240">
<status>Entry</status>
<desc>vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.20000321084646.0095c7f0@olga.swip.net">20000321 vqserver /........../</ref>
<ref source="CONFIRM" url="http://www.vqsoft.com/vq/server/faqs/dotdotbug.html">http://www.vqsoft.com/vq/server/faqs/dotdotbug.html</ref>
<ref source="XF">vqserver-dir-traverse</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1067">1067</ref>
<ref source="OSVDB" url="http://www.osvdb.org/270">270</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0243" seq="2000-0243">
<status>Entry</status>
<desc>AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=web-5645555@post2.rnci.com">20000324 AnalogX SimpleServer 1.03 Remote Crash&quot; at: </ref>
<ref source="MISC" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref>
<ref source="XF" url="http://xforce.iss.net/static/4189.php">simpleserver-exception-dos(4189)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1076">1076</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1265">1265</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0245" seq="2000-0245">
<status>Entry</status>
<desc>Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003290852.aa27218@blaze.arl.mil">20000328 Objectserver vulnerability</ref>
<ref source="SGI" url="ftp://sgigate.sgi.com/security/20000303-01-PX">20000303-01-PX</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-030.shtml">K-030</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1079">1079</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1267">1267</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4206">irix-objectserver-create-accounts(4206)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0246" seq="2000-0246">
<status>Entry</status>
<desc>IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the &quot;Virtualized UNC Share&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-019.asp">MS00-019</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=249599">Q249599</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1081">1081</ref>
<ref source="XF">iis-virtual-unc-share</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0247" seq="2000-0247">
<status>Entry</status>
<desc>Unknown vulnerability in Generic-NQS (GNQS) allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0236.html">20000322 Local root compromise in GNQS 3.50.6 and 3.50.7</ref>
<ref source="MISC" url="http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt">http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt</ref>
<ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:13.generic-nqs.asc">FreeBSD-SA-00:13</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1842">1842</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4306">generic-nqs-local-root(4306)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0249" seq="2000-0249">
<status>Entry</status>
<desc>The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise47.php3">20000426 Insecure file handling in IBM AIX frcactrl program</ref>
<ref source="IBM">ERS-OAR-E01-2000:075.1</ref>
<ref source="XF">aix-frcactrl</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1152">1152</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0251" seq="2000-0251">
<status>Entry</status>
<desc>HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0021.html">HPSBUX0004-112</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1090">1090</ref>
<ref source="XF">hp-virtual-vault</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0252" seq="2000-0252">
<status>Entry</status>
<desc>The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0051.html">20000411 Back Door in Commercial Shopping Cart</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1115">1115</ref>
<ref source="XF" url="http://xforce.iss.net/static/4975.php">dansie-shell-metacharacters</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0253" seq="2000-0253">
<status>Entry</status>
<desc>The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.</desc>
<refs>
<ref source="BUGTRAQ">20000411 Re: Back Door in Commercial Shopping Cart</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1115">1115</ref>
<ref source="XF" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0254" seq="2000-0254">
<status>Entry</status>
<desc>The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.</desc>
<refs>
<ref source="BUGTRAQ">20000411 Re: Back Door in Commercial Shopping Cart</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1115">1115</ref>
<ref source="XF" url="http://xforce.iss.net/static/4954.php">dansie-form-variables</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0255" seq="2000-0255">
<status>Entry</status>
<desc>The Nbase-Xyplex EdgeBlaster router allows remote attackers to cause a denial of service via a scan for the FormMail CGI program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0022.html">20000405 SilverBack Security Advisory: Nbase-Xyplex DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1091">1091</ref>
<ref source="XF">nbase-xyplex-router</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0257" seq="2000-0257">
<status>Entry</status>
<desc>Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0004171825340.10088-100000@nimue.tpi.pl">20000418 Novell Netware 5.1 (server 5.00h, Dec 11, 1999)...</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1118">1118</ref>
<ref source="XF">netware-remote-admin-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0258" seq="2000-0258">
<status>Entry</status>
<desc>IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the &quot;Myriad Escaped Characters&quot; Vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-023.asp">MS00-023</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1101">1101</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0260" seq="2000-0260">
<status>Entry</status>
<desc>Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the &quot;Link View Server-Side Component&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-025.asp">MS00-025</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1109">1109</ref>
<ref source="OSVDB" url="http://www.osvdb.org/282">282</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0261" seq="2000-0261">
<status>Entry</status>
<desc>The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html">20000415 (no subject)</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com">20000418 AVM's Statement</ref>
<ref source="XF">ken-download-files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1103">1103</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1282">1282</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0262" seq="2000-0262">
<status>Entry</status>
<desc>The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html">20000415 (no subject)</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com">20000418 AVM's Statement</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1103">1103</ref>
<ref source="XF">ken-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0263" seq="2000-0263">
<status>Entry</status>
<desc>The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0079.html">20000416 xfs</ref>
<ref source="XF">redhat-fontserver-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1111">1111</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0264" seq="2000-0264">
<status>Entry</status>
<desc>Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es">20000417 bugs in Panda Security 3.0</ref>
<ref source="CONFIRM" url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref>
<ref source="XF">panda-admin-privileges</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1119">1119</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0265" seq="2000-0265">
<status>Entry</status>
<desc>Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es">20000417 bugs in Panda Security 3.0</ref>
<ref source="CONFIRM" url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1119">1119</ref>
<ref source="XF">panda-uninstall-program</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0267" seq="2000-0267">
<status>Entry</status>
<desc>Cisco Catalyst 5.4.x allows a user to gain access to the &quot;enable&quot; mode without a password.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/catos-enable-bypass-pub.shtml">20000419 Cisco Catalyst Enable Password Bypass Vulnerability</ref>
<ref source="XF">cisco-catalyst-password-bypass</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1122">1122</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1288">1288</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0268" seq="2000-0268">
<status>Entry</status>
<desc>Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/iostelnetopt-pub.shtml">20000420 Cisco IOS Software TELNET Option Handling Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1123">1123</ref>
<ref source="XF">cisco-ios-option-handling</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1289">1289</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0272" seq="2000-0272">
<status>Entry</status>
<desc>RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95625288231045&amp;w=2">20000420 Remote DoS attack in Real Networks Real Server Vulnerability</ref>
<ref source="CONFIRM" url="http://service.real.com/help/faq/servg270.html">http://service.real.com/help/faq/servg270.html</ref>
<ref source="XF">realserver-remote-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1128">1128</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0273" seq="2000-0273">
<status>Entry</status>
<desc>PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0031.html">20000409 A funny way to DOS pcANYWHERE8.0 and 9.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1095">1095</ref>
<ref source="XF">pcanywhere-login-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0274" seq="2000-0274">
<status>Entry</status>
<desc>The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0035.html">20000410 linux trustees 1.5 long path name vulnerability</ref>
<ref source="CONFIRM" url="http://www.braysystems.com/linux/trustees.html">http://www.braysystems.com/linux/trustees.html</ref>
<ref source="XF">linux-trustees-patch-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1096">1096</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0276" seq="2000-0276">
<status>Entry</status>
<desc>BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000410131628.659.qmail@securityfocus.com">20000410 BeOS syscall bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1098">1098</ref>
<ref source="XF">beos-syscall-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0277" seq="2000-0277">
<status>Entry</status>
<desc>Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the &quot;XLM Text Macro&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-022.asp">MS00-022</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1087">1087</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1272">1272</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0278" seq="2000-0278">
<status>Entry</status>
<desc>The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0006.html">20000331 SalesLogix Eviewer Web App Bug: URL request crashes eviewer web application</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1089">1089</ref>
<ref source="XF">eviewer-admin-request-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0279" seq="2000-0279">
<status>Entry</status>
<desc>BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0029.html">20000407 BeOS Networking DOS</ref>
<ref source="MISC" url="http://bebugs.be.com/devbugs/detail.php3?oid=2505312">http://bebugs.be.com/devbugs/detail.php3?oid=2505312</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1100">1100</ref>
<ref source="XF">beos-networking-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0282" seq="2000-0282">
<status>Entry</status>
<desc>TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0050.html">20000412 TalentSoft Web+ Input Validation Bug Vulnerability</ref>
<ref source="CONFIRM" url="ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html">ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1102">1102</ref>
<ref source="XF">talentsoft-web-input</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0283" seq="2000-0283">
<status>Entry</status>
<desc>The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html">20000412 Performance Copilot for IRIX 6.5</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1106">1106</ref>
<ref source="XF">irix-pmcd-info</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0285" seq="2000-0285">
<status>Entry</status>
<desc>Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0076.html">20000416 XFree86 server overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1306">1306</ref>
<ref source="XF">xfree86-xkbmap-parameter-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0287" seq="2000-0287">
<status>Entry</status>
<desc>The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0058.html">20000412 BizDB Search Script Enables Shell Command Execution at the Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1104">1104</ref>
<ref source="XF">http-cgi-bizdb</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0289" seq="2000-0289">
<status>Entry</status>
<desc>IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0284.html">20000327 Security Problems with Linux 2.2.x IP Masquerading</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_48.html">20000520 Security hole in kernel &lt; 2.2.15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1078">1078</ref>
<ref source="XF">linux-masquerading-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0290" seq="2000-0290">
<status>Entry</status>
<desc>Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0005.html">20000331 Webstar 4.0 Buffer overflow vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/4792.php">macos-webstar-get-bo(4792)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1822">1822</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0292" seq="2000-0292">
<status>Entry</status>
<desc>The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10004190908140.32750-100000@localhost.localdomain">20000418 Adtran DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1129">1129</ref>
<ref source="XF">adtran-ping-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0294" seq="2000-0294">
<status>Entry</status>
<desc>Buffer overflow in healthd for FreeBSD allows local users to gain root privileges.</desc>
<refs>
<ref source="FREEBSD" url="http://www.securityfocus.com/templates/advisory.html?id=2162">FreeBSD-SA-00:12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1107">1107</ref>
<ref source="XF">freebsd-healthd</ref>
<ref source="OSVDB" url="http://www.osvdb.org/606">606</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0296" seq="2000-0296">
<status>Entry</status>
<desc>fcheck allows local users to gain privileges by embedding shell metacharacters into file names that are processed by fcheck.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0011.html">20000331 fcheck v.2.7.45 and insecure use of Perl's system()</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1086">1086</ref>
<ref source="XF">fcheck-shell</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0297" seq="2000-0297">
<status>Entry</status>
<desc>Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.</desc>
<refs>
<ref source="ALLAIRE" url="http://www2.allaire.com/handlers/index.cfm?ID=15099&amp;Method=Full">ASB00-06</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1085">1085</ref>
<ref source="XF">allaire-forums-allaccess</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1270">1270</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0298" seq="2000-0298">
<status>Entry</status>
<desc>The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0027.html">20000407 All Users startup folder left open if unattended install and OEMP reinstall=1</ref>
<ref source="XF" url="http://xforce.iss.net/static/4278.php">win2k-unattended-install(4278)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1758">1758</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0301" seq="2000-0301">
<status>Entry</status>
<desc>Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95505800117143&amp;w=2">20000405 Re: IMAIL (Ipswitch) DoS with Eudora (Qualcomm)</ref>
<ref source="CONFIRM" url="http://support.ipswitch.com/kb/IM-20000208-DM02.htm">http://support.ipswitch.com/kb/IM-20000208-DM02.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1094">1094</ref>
<ref source="XF">ipswitch-imail-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0302" seq="2000-0302">
<status>Entry</status>
<desc>Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95453598317340&amp;w=2">20000331 Alert: MS Index Server (CISADV000330)</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp">MS00-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1084">1084</ref>
<ref source="XF">http-indexserver-asp-source</ref>
<ref source="OSVDB" url="http://www.osvdb.org/271">271</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0303" seq="2000-0303">
<status>Entry</status>
<desc>Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise50.php3">20000503 Vulnerability in Quake3Arena Auto-Download Feature</ref>
<ref source="CONFIRM" url="http://www.quake3arena.com/news/index.html">http://www.quake3arena.com/news/index.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1169">1169</ref>
<ref source="XF">quake3-auto-download</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7531">7531</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0304" seq="2000-0304">
<status>Entry</status>
<desc>Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the &quot;Undelimited .HTR Request&quot; vulnerability.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise52.php3">20000511 Microsoft IIS Remote Denial of Service Attack</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx">MS00-031</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1191">1191</ref>
<ref source="XF">iis-authchangeurl-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0305" seq="2000-0305">
<status>Entry</status>
<desc>Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the &quot;IP Fragment Reassembly&quot; vulnerability.</desc>
<refs>
<ref source="BINDVIEW" url="http://www.securityfocus.com/templates/advisory.html?id=2240">20000519 jolt2 - Remote DoS against NT, W2K, 9x</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-029.asp">MS00-029</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1236">1236</ref>
<ref source="XF">ip-fragment-reassembly-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0306" seq="2000-0306">
<status>Entry</status>
<desc>Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.02a">SB-99.02</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-12-29&amp;msg=AAh6GYsGU1@leshka.chuvashia.su">19981229 Local/remote exploit for SCO UNIX.</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0307" seq="2000-0307">
<status>Entry</status>
<desc>Vulnerability in xserver in SCO UnixWare 2.1.x and OpenServer 5.05 and earlier allows an attacker to cause a denial of service which prevents access to reserved port numbers below 1024.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.07b">SB-99.07</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0308" seq="2000-0308">
<status>Entry</status>
<desc>Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.08a">SB-99.08</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0309" seq="2000-0309">
<status>Entry</status>
<desc>The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.org/errata24.html#trctrap">19990212 i386 trace-trap handling when DDB was configured could cause a system crash.</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6126">6126</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0310" seq="2000-0310">
<status>Entry</status>
<desc>IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.org/errata24.html#maxqueue">19990217 IP fragment assembly can bog the machine excessively and cause problems.</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7539">7539</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0311" seq="2000-0311">
<status>Entry</status>
<desc>The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the &quot;Mixed Object Access&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-026.asp">MS00-026</ref>
<ref source="XF">ms-mixed-object</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1145">1145</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0313" seq="2000-0313">
<status>Entry</status>
<desc>Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.org/errata.html#ifmedia">19991109 Any user can change interface media configurations.</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7540">7540</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0314" seq="2000-0314">
<status>Entry</status>
<desc>traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91893782027835&amp;w=2">19990213 traceroute as a flooder</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc">NetBSD-SA1999-004</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7574">7574</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0315" seq="2000-0315">
<status>Entry</status>
<desc>traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91893782027835&amp;w=2">19990213 traceroute as a flooder</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc">NetBSD-SA1999-004</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7575">7575</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0316" seq="2000-0316">
<status>Entry</status>
<desc>Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0191.html">20000424 Solaris 7 x86 lp exploit</ref>
<ref source="SUNBUG">4314312</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1143">1143</ref>
<ref source="XF">solaris-lp-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0318" seq="2000-0318">
<status>Entry</status>
<desc>Atrium Mercur Mail Server 3.2 allows local attackers to read other user's email and create arbitrary files via a dot dot (..) attack.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0057.html">20000413 Security problems with Atrium Mercur Mailserver 3.20</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1144">1144</ref>
<ref source="XF">mercur-remote-dot-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0319" seq="2000-0319">
<status>Entry</status>
<desc>mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=2694.000424@SECURITY.NNOV.RU">20000424 unsafe fgets() in sendmail's mail.local</ref>
<ref source="XF">sendmail-maillocal-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1146">1146</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0320" seq="2000-0320">
<status>Entry</status>
<desc>Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=9763.000421@SECURITY.NNOV.RU">20000421 unsafe fgets() in qpopper</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1133">1133</ref>
<ref source="XF">qpopper-fgets-spoofing</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0322" seq="2000-0322">
<status>Entry</status>
<desc>The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execure arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Enip.BSO.23.0004241601140.28851-100000@www.whitehats.com">20000424 piranha default password/exploit</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-014.html">RHSA-2000:014</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1149">1149</ref>
<ref source="XF">piranha-passwd-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0323" seq="2000-0323">
<status>Entry</status>
<desc>The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the &quot;Text I-ISAM&quot; vulnerability. </desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-08-22&amp;msg=19990729195531.25108.qmail@underground.org">19990728 Alert : MS Office 97 Vulnerability</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-030.asp">MS99-030</ref>
<ref source="XF">jet-text-isam</ref>
<ref source="BID" url="http://www.securityfocus.com/level2/?go=vulnerabilities&amp;id=595">595</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0324" seq="2000-0324">
<status>Entry</status>
<desc>pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000425150157.13567A-100000@sword.damocles.com">20000425 Denial of Service Against pcAnywhere.</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0201.html">20010211 Symantec pcAnywhere 9.0 DoS / Buffer Overflow</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0258.html">20010212 Re: Symantec pcAnywhere 9.0 DoS / Buffer Overflow </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1150">1150</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/4347.php">pcanywhere-tcpsyn-dos(4347)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1301">1301</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0327" seq="2000-0327">
<status>Entry</status>
<desc>Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the &quot;Virtual Machine Verifier&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93993545118416&amp;w=2">19991014 Another Microsoft Java Flaw Disovered</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-045.asp">MS99-045</ref>
<ref source="XF">msvm-verifier-java</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0328" seq="2000-0328">
<status>Entry</status>
<desc>Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.19990824165629.00abcb40@192.168.124.1">19990824 NT Predictable Initial TCP Sequence numbers - changes observed with SP4</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-046.asp">MS99-046</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/604">604</ref>
<ref source="XF">nt-sequence-prediction-sp4</ref>
<ref source="XF">tcp-seq-predict</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0329" seq="2000-0329">
<status>Entry</status>
<desc>A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the &quot;Active Setup Control&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-048.asp">MS99-048</ref>
<ref source="XF">ie-active-setup-control</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0330" seq="2000-0330">
<status>Entry</status>
<desc>The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the &quot;File Access URL&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-049.asp">MS99-049</ref>
<ref source="XF">win-fileurl-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0331" seq="2000-0331">
<status>Entry</status>
<desc>Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the &quot;Malformed Environment Variable&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0147.html">20000421 CMD.EXE overflow (CISADV000420)</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-027.asp">MS00-027</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1135">1135</ref>
<ref source="XF">nt-cmd-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0332" seq="2000-0332">
<status>Entry</status>
<desc>UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000503091316.99073.qmail@hotmail.com">20000502 Fun with UltraBoard V1.6X</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1164">1164</ref>
<ref source="XF">ultraboard-printabletopic-fileread</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1309">1309</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4065">4065</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0334" seq="2000-0334">
<status>Entry</status>
<desc>The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=15411&amp;Method=Full">ASB00-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1181">1181</ref>
<ref source="XF">allaire-spectra-container-editor-preview</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0335" seq="2000-0335">
<status>Entry</status>
<desc>The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.</desc>
<refs>
<ref source="BUGTRAQ">20000502 glibc resolver weakness</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1166">1166</ref>
<ref source="XF">glibc-resolver-id-predictable</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0336" seq="2000-0336">
<status>Entry</status>
<desc>Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-012.html">RHSA-2000:012</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-009.0.txt">CSSA-2000-009.0</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-May/000009.html">TLSA2000010-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1232">1232</ref>
<ref source="XF">openldap-symlink-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0337" seq="2000-0337">
<status>Entry</status>
<desc>Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0188.html">20000424 Solaris x86 Xsun overflow.</ref>
<ref source="SUNBUG">4335411</ref>
<ref source="XF">solaris-xsun-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1140">1140</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0338" seq="2000-0338">
<status>Entry</status>
<desc>Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000423174038.A520%40clico.pl">20000423 CVS DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1136">1136</ref>
<ref source="XF">cvs-tempfile-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0339" seq="2000-0339">
<status>Entry</status>
<desc>ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000421044123.2353.qmail@securityfocus.com">20000420 ZoneAlarm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1137">1137</ref>
<ref source="XF">zonealarm-portscan</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1294">1294</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0340" seq="2000-0340">
<status>Entry</status>
<desc>Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=00042902575201.09597@wintermute-pub">20000428 SuSE 6.3 Gnomelib buffer overflow</ref>
<ref source="CONFIRM" url="http://www.suse.com/us/support/download/updates/axp_63.html">http://www.suse.com/us/support/download/updates/axp_63.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1155">1155</ref>
<ref source="XF">linux-gnomelib-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0341" seq="2000-0341">
<status>Entry</status>
<desc>ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=95736106504870&amp;w=2">20000501 Remote DoS attack in CASSANDRA NNTPServer v1.10 from ATRIUM</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1156">1156</ref>
<ref source="XF">nntpserver-cassandra-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0342" seq="2000-0342">
<status>Entry</status>
<desc>Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka &quot;Stealth Attachment.&quot;</desc>
<refs>
<ref source="MISC" url="http://www.peacefire.org/security/stealthattach/explanation.html">http://www.peacefire.org/security/stealthattach/explanation.html</ref>
<ref source="CONFIRM" url="http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077">http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1157">1157</ref>
<ref source="XF">eudora-warning-message</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0344" seq="2000-0344">
<status>Entry</status>
<desc>The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0005012042550.6419-100000@ferret.lmh.ox.ac.uk">20000501 Linux knfsd DoS issue</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1160">1160</ref>
<ref source="XF">linux-knfsd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0346" seq="2000-0346">
<status>Entry</status>
<desc>AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000502133240.21807.qmail@securityfocus.com">20000502 INFO:AppleShare IP 6.3.2 squashes security bug</ref>
<ref source="CONFIRM" url="http://asu.info.apple.com/swupdates.nsf/artnum/n11670">http://asu.info.apple.com/swupdates.nsf/artnum/n11670</ref>
<ref source="XF">macos-appleshare-invalid-range</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1162">1162</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0347" seq="2000-0347">
<status>Entry</status>
<desc>Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=95737580922397&amp;w=2">20000501 el8.org advisory - Win 95/98 DoS (RFParalyze.c)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1163">1163</ref>
<ref source="XF">win-netbios-source-null</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0348" seq="2000-0348">
<status>Entry</status>
<desc>A vulnerability in the Sendmail configuration file sendmail.cf as installed in SCO UnixWare 7.1.0 and earlier allows an attacker to gain root privileges.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.10a">SB-99.10</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0349" seq="2000-0349">
<status>Entry</status>
<desc>Vulnerability in the passthru driver in SCO UnixWare 7.1.0 allows an attacker to cause a denial of service.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.13a">SB-99.13</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0350" seq="2000-0350">
<status>Entry</status>
<desc>A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events.</desc>
<refs>
<ref source="MISC" url="http://www.securityfocus.com/templates/advisory.html?id=2220">http://www.securityfocus.com/templates/advisory.html?id=2220</ref>
<ref source="CONFIRM" url="http://advice.networkice.com/advice/Support/KB/q000166/">http://advice.networkice.com/advice/Support/KB/q000166/</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1216">1216</ref>
<ref source="XF">netice-icecap-alert-execute</ref>
<ref source="XF">netice-icecap-default</ref>
<ref source="OSVDB" url="http://www.osvdb.org/312">312</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0351" seq="2000-0351">
<status>Entry</status>
<desc>Some packaging commands in SCO UnixWare 7.1.0 have insecure privileges, which allows local users to add or remove software packages.</desc>
<refs>
<ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.09b">SB-99.09</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0352" seq="2000-0352">
<status>Entry</status>
<desc>Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9911171818220.12375-100000@ray.compu-aid.com">19991117 Pine: expanding env vars in URLs (seems to be fixed as of 4.21)</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-036.0.txt">CSSA-1999-036.0</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_36.html">19991227 Security hole in Pine &lt; 4.21</ref>
<ref source="XF">pine-remote-exe</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/810">810</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0353" seq="2000-0353">
<status>Entry</status>
<desc>Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.</desc>
<refs>
<ref source="MISC" url="http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html">http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_6.html">19990628 Execution of commands in Pine 4.x</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/pine_update_announcement.html">19990911 Update for Pine (fixed IMAP support)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1247">1247</ref>
<ref source="XF">pine-lynx-execute-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0354" seq="2000-0354">
<status>Entry</status>
<desc>mirror 2.8.x in Linux systems allows remote attackers to create files one level above the local target directory.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=15769.990928@tomcat.ru">19990928 mirror 2.9 hole</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/1999/19991018">19991018 Incorrect directory name handling in mirror</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_22.html">19991001 Security hole in mirror</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/681">681</ref>
<ref source="XF">mirror-perl-remote-file-creation</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0356" seq="2000-0356">
<status>Entry</status>
<desc>Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.</desc>
<refs>
<ref source="REDHAT" url="http://www.securityfocus.com/templates/advisory.html?id=1789">RHSA-1999:040</ref>
<ref source="XF">linux-pam-nis-login</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/697">697</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0359" seq="2000-0359">
<status>Entry</status>
<desc>Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1626.html">19991113 thttpd 2.04 stack overflow (VD#6)</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_30.html">19991116 Security hole in thttpd 1.90a - 2.04</ref>
<ref source="XF">thttpd-ifmodifiedsince-header-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1248">1248</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0360" seq="2000-0360">
<status>Entry</status>
<desc>Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.</desc>
<refs>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_34.html">19991124 Security hole in inn &lt;= 2.2.1</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-038.0.txt">CSSA-1999-038.0</ref>
<ref source="XF">inn-remote-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1249">1249</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0361" seq="2000-0361">
<status>Entry</status>
<desc>The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.</desc>
<refs>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_35.html">19991214 Security hole in wvdial &lt;= 1.4</ref>
<ref source="XF">wvdial-gain-dialup-info</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0362" seq="2000-0362">
<status>Entry</status>
<desc>Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.</desc>
<refs>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_25.html">19991019 Security hole in cdwtools &lt; 093</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/738">738</ref>
<ref source="XF">linux-cdda2cdr</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0363" seq="2000-0363">
<status>Entry</status>
<desc>Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.</desc>
<refs>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_25.html">19991019 Security hole in cdwtools &lt; 093</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/738">738</ref>
<ref source="XF">linux-cdda2cdr</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0366" seq="2000-0366">
<status>Entry</status>
<desc>dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/1999/19991202">19991202 problem restoring symlinks</ref>
<ref source="XF">debian-dump-modify-ownership</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1442">1442</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0367" seq="2000-0367">
<status>Entry</status>
<desc>Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/1999/19990218">19990218 Root exploit in eterm</ref>
<ref source="XF">linux-eterm</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0368" seq="2000-0368">
<status>Entry</status>
<desc>Classic Cisco IOS 9.1 and later allows attackers with access to the loging prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/ioshist-pub.shtml">19981014 Cisco IOS Command History Release at Login Prompt</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-009.shtml">J-009</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0369" seq="2000-0369">
<status>Entry</status>
<desc>The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.</desc>
<refs>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-029.1.txt">CSSA-1999-029.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1266">1266</ref>
<ref source="XF">caldera-ident-server-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0370" seq="2000-0370">
<status>Entry</status>
<desc>The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.</desc>
<refs>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-001.0.txt">CSSA-1999-001.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1268">1268</ref>
<ref source="XF">caldera-smail-rmail-command</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0371" seq="2000-0371">
<status>Entry</status>
<desc>The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.</desc>
<refs>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-005.0.txt">CSSA-1999-005.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1269">1269</ref>
<ref source="XF">kde-mediatool</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0372" seq="2000-0372">
<status>Entry</status>
<desc>Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.</desc>
<refs>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-014.0.txt">CSSA-1999-014.0</ref>
<ref source="XF" url="http://xforce.iss.net/static/2268.php">linux-rmt</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7940">7940</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0373" seq="2000-0373">
<status>Entry</status>
<desc>Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.</desc>
<refs>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-015.0.txt">CSSA-1999-015.0</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA1999015_01.html">RHSA-1999:015-01</ref>
<ref source="XF" url="http://xforce.iss.net/static/2266.php">kde-kvt</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0374" seq="2000-0374">
<status>Entry</status>
<desc>The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.</desc>
<refs>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-021.0.txt">CSSA-1999-021.0</ref>
<ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:025">MDKSA-2002:025</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1446">1446</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4856">xdmcp-kdm-default-configuration(4856)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0375" seq="2000-0375">
<status>Entry</status>
<desc>The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-99:04</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6084">6084</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0376" seq="2000-0376">
<status>Entry</status>
<desc>Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.</desc>
<refs>
<ref source="ISS">20000607 Buffer Overflow in i-drive Filo (tm) software</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1324">1324</ref>
<ref source="XF">idrive-filo-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0377" seq="2000-0377">
<status>Entry</status>
<desc>The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the &quot;Remote Registry Access Authentication&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-040.asp">MS00-040</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=264684">Q264684</ref>
<ref source="XF">nt-registry-request-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1331">1331</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1021">oval:org.mitre.oval:def:1021</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0378" seq="2000-0378">
<status>Entry</status>
<desc>The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0023.html">20000502 pam_console bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1176">1176</ref>
<ref source="XF">linux-pam-sniff-activities</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0379" seq="2000-0379">
<status>Entry</status>
<desc>The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005082054.NAA32590@linux.mtndew.com">20000507 Advisory: Netopia R9100 router vulnerability</ref>
<ref source="CONFIRM" url="http://www.netopia.com/equipment/purchase/fmw_update.html">http://www.netopia.com/equipment/purchase/fmw_update.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1177">1177</ref>
<ref source="XF">netopia-snmp-comm-strings</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0380" seq="2000-0380">
<status>Entry</status>
<desc>The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0261.html">20000426 Cisco HTTP possible bug:</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/ioshttpserver-pub.shtml">20000514 Cisco IOS HTTP Server Vulnerability</ref>
<ref source="XF">cisco-ios-http-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1154">1154</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1302">1302</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0381" seq="2000-0381">
<status>Entry</status>
<desc>The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0067.html">20000505 Black Watch Labs Vulnerability Alert</ref>
<ref source="MISC" url="http://www.perfectotech.com/blackwatchlabs/vul5_05.html">http://www.perfectotech.com/blackwatchlabs/vul5_05.html</ref>
<ref source="XF">http-cgi-dbman-db</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1178">1178</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0382" seq="2000-0382">
<status>Entry</status>
<desc>ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=15697&amp;Method=Full">ASB00-12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1179">1179</ref>
<ref source="XF">allaire-clustercats-url-redirect</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0387" seq="2000-0387">
<status>Entry</status>
<desc>The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:16.golddig.asc">FreeBSD-SA-00:16</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1184">1184</ref>
<ref source="XF">golddig-overwrite-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0388" seq="2000-0388">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A17.libmytinfo.asc">FreeBSD-SA-00:17</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1185">1185</ref>
<ref source="XF">libmytinfo-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0389" seq="2000-0389">
<status>Entry</status>
<desc>Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html">CA-2000-06</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref>
<ref source="XF">kerberos-krb-rd-req-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0390" seq="2000-0390">
<status>Entry</status>
<desc>Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html">CA-2000-06</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref>
<ref source="XF">kerberos-krb425-conv-principal-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4884">4884</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0391" seq="2000-0391">
<status>Entry</status>
<desc>Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html">CA-2000-06</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref>
<ref source="XF">kerberos-krshd-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4876">4876</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0392" seq="2000-0392">
<status>Entry</status>
<desc>Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html">CA-2000-06</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref>
<ref source="XF">kerberos-ksu-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0393" seq="2000-0393">
<status>Entry</status>
<desc>The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0172.html">20000516 kscd vulnerability</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_50.html">20000529 kmulti &lt;= 1.1.2</ref>
<ref source="XF">kscd-shell-env-variable</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1206">1206</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0394" seq="2000-0394">
<status>Entry</status>
<desc>NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler's Man-in-the-Middle signature.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95878603510835&amp;w=2">20000519 RFP2K05: NetProwler vs. RFProwler</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=392AD3B3.3E9BE3EA@axent.com">20000522 RFP2K05 - NetProwler &quot;Fragmentation&quot; Issue </ref>
<ref source="XF">axent-netprowler-ipfrag-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1225">1225</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0395" seq="2000-0395">
<status>Entry</status>
<desc>Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=007d01bfbf48$e44f0e40$01dc11ac@peopletel.org">20000516 CProxy v3.3 SP 2 DoS</ref>
<ref source="XF">cproxy-http-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1213">1213</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0396" seq="2000-0396">
<status>Entry</status>
<desc>The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0285.html">20000524 Alert: Carello File Creation flaw</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1245">1245</ref>
<ref source="XF">carello-file-duplication</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0397" seq="2000-0397">
<status>Entry</status>
<desc>The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0160.html">20000515 Vulnerability in EMURL-based e-mail providers</ref>
<ref source="XF">emurl-account-access</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1203">1203</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0398" seq="2000-0398">
<status>Entry</status>
<desc>Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0286.html">20000524 Alert: Buffer overflow in Rockliffe's MailSite</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1244">1244</ref>
<ref source="XF">mailsite-get-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0399" seq="2000-0399">
<status>Entry</status>
<desc>Buffer overflow in MDaemon POP server allows remote attackers to cause a denial of service via a long user name.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0301.html">20000524 Deerfield Communications MDaemon Mail Server DoS</ref>
<ref source="XF">deerfield-mdaemon-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1250">1250</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0402" seq="2000-0402">
<status>Entry</status>
<desc>The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the &quot;SQL Server 7.0 Service Pack Password&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-035.asp">MS00-035</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=263968">Q263968</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1281">1281</ref>
<ref source="XF">mssql-agent-stored-pw</ref>
<ref source="XF">mssql-sa-pw-in-sqlsplog</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0403" seq="2000-0403">
<status>Entry</status>
<desc>The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the &quot;HostAnnouncement Flooding&quot; or &quot;HostAnnouncement Frame&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-036.asp">MS00-036</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=263307">Q263307</ref>
<ref source="XF">win-browser-hostannouncement</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1261">1261</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0404" seq="2000-0404">
<status>Entry</status>
<desc>The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the &quot;ResetBrowser Frame&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-036.asp">MS00-036</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=262694">Q262694</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1262">1262</ref>
<ref source="XF">win-browser-reset-frame</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0405" seq="2000-0405">
<status>Entry</status>
<desc>Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.</desc>
<refs>
<ref source="L0PHT" url="http://www.l0pht.com/advisories/asniff_advisory.txt">20000515 AntiSniff version 1.01 and Researchers version 1 DNS overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1207">1207</ref>
<ref source="XF">antisniff-dns-overflow</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3179">3179</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0406" seq="2000-0406">
<status>Entry</status>
<desc>Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the &quot;Acros-Suencksen SSL&quot; vulnerability.</desc>
<refs>
<ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-2000-04-06-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-2000-04-06-1-PUB.txt</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-05.html">CA-2000-05</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-028.html">RHSA-2000:028</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1188">1188</ref>
<ref source="XF">netscape-invalid-ssl-sessions</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0407" seq="2000-0407">
<status>Entry</status>
<desc>Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0141.html">20000512 New Solaris root exploit for /usr/lib/lp/bin/netpr</ref>
<ref source="XF">sol-netpr-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1200">1200</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0408" seq="2000-0408">
<status>Entry</status>
<desc>IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the &quot;Malformed Extension Data in URL&quot; vulnerability.</desc>
<refs>
<ref source="MISC" url="http://www.ussrback.com/labs40.html">http://www.ussrback.com/labs40.html</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-030.asp">MS00-030</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=260205">Q260205</ref>
<ref source="XF">iis-url-extension-data-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1190">1190</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0409" seq="2000-0409">
<status>Entry</status>
<desc>Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0126.html">20000510 Possible symlink problems with Netscape 4.73</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1201">1201</ref>
<ref source="XF">netscape-import-certificate-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0410" seq="2000-0410">
<status>Entry</status>
<desc>ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0005&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=4843">20000510 Cold Fusion Server 4.5.1 DoS Vulnerability.</ref>
<ref source="XF">coldfusion-cfcache-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1192">1192</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0411" seq="2000-0411">
<status>Entry</status>
<desc>Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0125.html">20000510 Black Watch Labs Vulnerability Alert</ref>
<ref source="MISC" url="http://www.perfectotech.com/blackwatchlabs/vul5_10.html">http://www.perfectotech.com/blackwatchlabs/vul5_10.html</ref>
<ref source="XF">http-cgi-formmail-environment</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1187">1187</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0414" seq="2000-0414">
<status>Entry</status>
<desc>Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0047.html">HPSBUX0005-113</ref>
<ref source="XF">hp-shutdown-privileges</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1214">1214</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0416" seq="2000-0416">
<status>Entry</status>
<desc>NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NABBJLKKPKIHDIMKFKGCMEFANMAB.georger@nls.net">20000511 NTMail Proxy Exploit</ref>
<ref source="CONFIRM" url="http://www.gordano.com/support/archives/ntmail/2000-05/00001114.htm">http://www.gordano.com/support/archives/ntmail/2000-05/00001114.htm</ref>
<ref source="XF">ntmail-bypass-proxy</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1196">1196</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0417" seq="2000-0417">
<status>Entry</status>
<desc>The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0075.html">20000505 Cayman 3220-H DSL Router DOS</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0280.html">20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack</ref>
<ref source="XF">cayman-router-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1219">1219</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0418" seq="2000-0418">
<status>Entry</status>
<desc>The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) requests.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0280.html">20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack</ref>
<ref source="XF">cayman-dsl-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1240">1240</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0419" seq="2000-0419">
<status>Entry</status>
<desc>The Office 2000 UA ActiveX Control is marked as &quot;safe for scripting,&quot; which allows remote attackers to conduct unauthorized activities via the &quot;Show Me&quot; function in Office Help, aka the &quot;Office 2000 UA Control&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-034.asp">MS00-034</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=262767">Q262767</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-07.html">CA-2000-07</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1197">1197</ref>
<ref source="XF">office-ua-control</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0421" seq="2000-0421">
<status>Entry</status>
<desc>The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0128.html">20000510 Advisory: Unchecked system(blaat $var blaat) call in Bugzilla 2.8</ref>
<ref source="XF">bugzilla-unchecked-system-call</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1199">1199</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0424" seq="2000-0424">
<status>Entry</status>
<desc>The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005151024.aa01811@blaze.arl.mil">20000514 Vulnerability in CGI counter 4.0.7 by George Burgyan</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1202">1202</ref>
<ref source="XF">http-cgi-burgyan-counter</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0425" seq="2000-0425">
<status>Entry</status>
<desc>Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="CONFIRM" url="http://www.lsoft.com/news/default.asp?item=Advisory0">http://www.lsoft.com/news/default.asp?item=Advisory0</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0048.html">20000505 Alert: Listserv Web Archives (wa) buffer overflow</ref>
<ref source="XF">http-cgi-listserv-wa-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1167">1167</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0426" seq="2000-0426">
<status>Entry</status>
<desc>UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0059.html">20000505 Re: Fun with UltraBoard V1.6X</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1175">1175</ref>
<ref source="XF">ultraboard-cgi-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0427" seq="2000-0427">
<status>Entry</status>
<desc>The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.</desc>
<refs>
<ref source="L0PHT" url="http://www.l0pht.com/advisories/etoken-piepa.txt">20000504 eToken Private Information Extraction and Physical Attack</ref>
<ref source="XF">aladdin-etoken-pin-reset</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1170">1170</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3266">3266</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0428" seq="2000-0428">
<status>Entry</status>
<desc>Buffer overflow in the SMTP gateway for InterScan Virus Wall 3.32 and earlier allows a remote attacker to execute arbitrary commands via a long filename for a uuencoded attachment.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/39_Trend.asp">20000503 Trend Micro InterScan VirusWall Remote Overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1168">1168</ref>
<ref source="XF">interscan-viruswall-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0430" seq="2000-0430">
<status>Entry</status>
<desc>Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95738697301956&amp;w=2">20000503 Another interesting Cart32 command</ref>
<ref source="XF">cart32-expdate</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1358">1358</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0431" seq="2000-0431">
<status>Entry</status>
<desc>Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000523100045.B11049@HiWAAY.net">20000522  Problem with FrontPage on Cobalt RaQ2/RaQ3</ref>
<ref source="BUGTRAQ">20000525 Cobalt Networks - Security Advisory - Frontpage</ref>
<ref source="CONFIRM" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0305.html">http://archives.neohapsis.com/archives/bugtraq/2000-05/0305.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1238">1238</ref>
<ref source="XF">cobalt-cgiwrap-bypass</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1346">1346</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0432" seq="2000-0432">
<status>Entry</status>
<desc>The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0173.html">20000516 Vuln in calender.pl (Matt Kruse calender script)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1215">1215</ref>
<ref source="XF">http-cgi-calendar-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0435" seq="2000-0435">
<status>Entry</status>
<desc>The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0167.html">20000516 Allmanage.pl Vulnerabilities</ref>
<ref source="XF">http-cgi-allmanage-account-access</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1217">1217</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1337">1337</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0436" seq="2000-0436">
<status>Entry</status>
<desc>MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0254.html">20000522 MetaProducts Offline Explorer Directory Traversal Vulnerability</ref>
<ref source="CONFIRM" url="http://www.metaproducts.com/mpOE-HY.html">http://www.metaproducts.com/mpOE-HY.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1231">1231</ref>
<ref source="XF">offline-explorer-directory-traversal</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0437" seq="2000-0437">
<status>Entry</status>
<desc>Buffer overflow in the CyberPatrol daemon &quot;cyberdaemon&quot; used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands.</desc>
<refs>
<ref source="CONFIRM" url="http://www.tis.com/support/cyberadvisory.html">http://www.tis.com/support/cyberadvisory.html</ref>
<ref source="CONFIRM" url="http://www.pgp.com/jump/gauntlet_advisory.asp">http://www.pgp.com/jump/gauntlet_advisory.asp</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0249.html">20000522 Gauntlet CyberPatrol Buffer Overflow</ref>
<ref source="XF">gauntlet-cyberdaemon-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1234">1234</ref>
<ref source="OSVDB" url="http://www.osvdb.org/322">322</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0438" seq="2000-0438">
<status>Entry</status>
<desc>Buffer overflow in fdmount on Linux systems allows local users in the &quot;floppy&quot; group to execute arbitrary commands via a long mountpoint parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0245.html">20000522 fdmount buffer overflow</ref>
<ref source="XF">linux-fdmount-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1239">1239</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0439" seq="2000-0439">
<status>Entry</status>
<desc>Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the &quot;Unauthorized Cookie Access&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000511135609.D7774@securityfocus.com">20000510 IE Domain Confusion Vulnerability</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NDBBKGHPMKBKDDGLDEEHAEHMDIAA.rms2000@bellatlantic.net">20000511 IE Domain Confusion Vulnerability is an Email problem also</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-033.asp">MS00-033</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1194">1194</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1326">1326</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4447">ie-cookie-disclosure(4447)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0440" seq="2000-0440">
<status>Entry</status>
<desc>NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.</desc>
<refs>
<ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-002.txt.asc">NetBSD-SA2000-002</ref>
<ref source="FREEBSD">FreeBSD-SA-00:23</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0088.html">20000506 [NHC20000504a.0: NetBSD Panics when sent unaligned IP options]</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1173">1173</ref>
<ref source="XF">netbsd-unaligned-ip-options</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0441" seq="2000-0441">
<status>Entry</status>
<desc>Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.</desc>
<refs>
<ref source="IBM" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0275.html">ERS-OAR-E01-2000:087.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1241">1241</ref>
<ref source="XF">aix-local-filesystem</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0442" seq="2000-0442">
<status>Entry</status>
<desc>Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0267.html">20000523 Qpopper 2.53 remote problem, user can gain gid=mail</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_51.html">20000608 pop &lt;= 2000.3.4</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1242">1242</ref>
<ref source="XF">qualcomm-qpopper-euidl</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0443" seq="2000-0443">
<status>Entry</status>
<desc>The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0281.html">20000524 HP Web JetAdmin Version 5.6 Web interface Server Directory Traversal Vulnerability</ref>
<ref source="XF">hp-jetadmin-directory-traversal</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1243">1243</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1350">1350</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0445" seq="2000-0445">
<status>Entry</status>
<desc>The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0273.html">20000523 Key Generation Security Flaw in PGP 5.0</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-09.html">CA-2000-09</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1251">1251</ref>
<ref source="XF">pgp-key-predictable</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1355">1355</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0446" seq="2000-0446">
<status>Entry</status>
<desc>Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0274.html">20000524 Remote xploit for MDBMS</ref>
<ref source="XF">mdbms-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1252">1252</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0447" seq="2000-0447">
<status>Entry</status>
<desc>Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=6C740781F92BD411831F0090273A8AB806FD4A@exchange.servers.delphis.net">20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool </ref>
<ref source="XF">nai-webshield-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1254">1254</ref>
<ref source="OSVDB" url="http://www.osvdb.org/327">327</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0448" seq="2000-0448">
<status>Entry</status>
<desc>The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=6C740781F92BD411831F0090273A8AB806FD4A@exchange.servers.delphis.net">20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool </ref>
<ref source="XF">nai-webshield-getconfig</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1253">1253</ref>
<ref source="OSVDB" url="http://www.osvdb.org/326">326</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0451" seq="2000-0451">
<status>Entry</status>
<desc>The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0229.html">20000518 Remote Dos attack against Intel express 8100 router</ref>
<ref source="XF">intel-8100-remote-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1228">1228</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0452" seq="2000-0452">
<status>Entry</status>
<desc>Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0219.html">20000518 Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl))</ref>
<ref source="XF">lotus-domino-esmtp-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1229">1229</ref>
<ref source="OSVDB" url="http://www.osvdb.org/321">321</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0453" seq="2000-0453">
<status>Entry</status>
<desc>XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0223.html">20000518 Nasty XFree Xserver DoS</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-012.0.txt">CSSA-2000-012.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1235">1235</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0454" seq="2000-0454">
<status>Entry</status>
<desc>Buffer overflow in Linux cdrecord allows local users to gain privileges via the dev parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0367.html">20000527 Mandrake 7.0: /usr/bin/cdrecord gid=80 (strike #2)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0434.html">20000603 [Gael Duval ] [Security Announce] cdrecord</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0019.html">20000607 Conectiva Linux Security Announcement - cdrecord</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1265">1265</ref>
<ref source="XF">linux-cdrecord-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0455" seq="2000-0455">
<status>Entry</status>
<desc>Buffer overflow in xlockmore xlock program version 4.16 and earlier allows local users to read sensitive data from memory via a long -mode option.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/41initialized.asp">20000529 Initialized Data Overflow in Xlock</ref>
<ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-003.txt.asc">NetBSD-SA2000-003</ref>
<ref source="TURBO" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0375.html">TLSA2000012-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1267">1267</ref>
<ref source="XF">xlock-bo-read-passwd</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0456" seq="2000-0456">
<status>Entry</status>
<desc>NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in the kernel which do not yield the CPU, aka &quot;cpu-hog&quot;.</desc>
<refs>
<ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-005.txt.asc">NetBSD-SA2000-005</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1272">1272</ref>
<ref source="XF">bsd-syscall-cpu-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1365">1365</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0457" seq="2000-0457">
<status>Entry</status>
<desc>ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the &quot;.HTR File Fragment Reading&quot; or &quot;File Fragment Reading via .HTR&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95810120719608&amp;w=2">20000511 Alert: IIS ism.dll exposes file contents</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx">MS00-031</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1193">1193</ref>
<ref source="XF" url="http://xforce.iss.net/static/4448.php">iis-ism-file-access(4448)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0458" seq="2000-0458">
<status>Entry</status>
<desc>The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95672120116627&amp;w=2">20000424 Two Problems in IMP 2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1360">1360</ref>
<ref source="XF">imp-tmpfile-view</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0459" seq="2000-0459">
<status>Entry</status>
<desc>IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95672120116627&amp;w=2">20000424 Two Problems in IMP 2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1361">1361</ref>
<ref source="XF">imp-wordfile-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0460" seq="2000-0460">
<status>Entry</status>
<desc>Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0353.html">20000526 KDE: /usr/bin/kdesud, gid = 0 exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1274">1274</ref>
<ref source="XF">kde-display-environment-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0461" seq="2000-0461">
<status>Entry</status>
<desc>The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.org/errata26.html#semconfig">20000526</ref>
<ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-004.txt.asc">NetBSD-SA2000-004</ref>
<ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:19.semconfig.asc">FreeBSD-SA-00:19</ref>
<ref source="XF">bsd-semaphore-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1270">1270</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0462" seq="2000-0462">
<status>Entry</status>
<desc>ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory.</desc>
<refs>
<ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-006.txt.asc">NetBSD-SA2000-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1273">1273</ref>
<ref source="XF">netbsd-ftpchroot-parsing</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1366">1366</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0463" seq="2000-0463">
<status>Entry</status>
<desc>BeOS 5.0 allows remote attackers to cause a denial of service via fragmented TCP packets.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0197.html">20000517 AUX Security Advisory on Be/OS 5.0 (DoS)</ref>
<ref source="XF">beos-tcp-frag-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1222">1222</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0464" seq="2000-0464">
<status>Entry</status>
<desc>Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the &quot;Malformed Component Attribute&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-033.asp">MS00-033</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=261257">Q261257</ref>
<ref source="XF">ie-malformed-component-attribute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1223">1223</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0465" seq="2000-0465">
<status>Entry</status>
<desc>Internet Explorer 4.x and 5.x does properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the &quot;Frame Domain Verification&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-033.asp">MS00-033</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=251108">Q251108</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=255676">Q255676</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1224">1224</ref>
<ref source="XF">ie-frame-domain-verification</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0466" seq="2000-0466">
<status>Entry</status>
<desc>AIX cdmount allows local users to gain root privileges via shell metacharacters.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise55.php">20000620 Insecure call of external program in AIX cdmount</ref>
<ref source="XF">aix-cdmount-insecure-call</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1384">1384</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0467" seq="2000-0467">
<status>Entry</status>
<desc>Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0125.html">20000614 Splitvt exploit</ref>
<ref source="DEBIAN">20000605a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1346">1346</ref>
<ref source="XF">splitvt-screen-lock-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0468" seq="2000-0468">
<status>Entry</status>
<desc>man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.SOL.4.02.10006021014400.4779-100000@nofud.nwest.attws.com">20000601 HP Security vulnerability in the man command</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1302">1302</ref>
<ref source="XF">hp-man-file-overwrite</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0469" seq="2000-0469">
<status>Entry</status>
<desc>Selena Sol WebBanner 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-22&amp;msg=ILENKALMCAFBLHBGEOFKGEJCCAAA.jwesterink@jwesterink.daxis.nl">20000613 CGI: Selena Sol's WebBanner ( Random Banner Generator ) Vulnerability</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.2.0.58.20000620193604.00979950@mail.clark.net">20000620 Re: CGI: Selena Sol's WebBanner ( Random Banner Generator ) Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1347">1347</ref>
<ref source="XF">webbanner-input-validation-exe</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0470" seq="2000-0470">
<status>Entry</status>
<desc>Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0398.html">20000601 Hardware Exploit - Gets network Down</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1290">1290</ref>
<ref source="XF" url="http://xforce.iss.net/static/4588.php">rompager-malformed-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0471" seq="2000-0471">
<status>Entry</status>
<desc>Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0114.html">20000614 Vulnerability in Solaris ufsrestore</ref>
<ref source="SUNBUG">4339366</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/210">00210</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/36866">VU#36866</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1348">1348</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1398">1398</ref>
<ref source="XF" url="http://xforce.iss.net/static/4711.php">sol-ufsrestore-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0472" seq="2000-0472">
<status>Entry</status>
<desc>Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0003.html">20000106 innd 2.2.2 remote buffer overflow</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-016.0.txt">CSSA-2000-016.0</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0097.html">20000707 inn update</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0298.html">20000721 [ANNOUNCE] INN 2.2.3 available</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0330.html">20000722 MDKSA-2000:023 inn update</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1316">1316</ref>
<ref source="XF" url="http://xforce.iss.net/static/4615.php">innd-cancel-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0474" seq="2000-0474">
<status>Entry</status>
<desc>Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0410.html">20000601 Remote DoS attack in Real Networks Real Server (Strike #2) Vulnerability</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0427.html">20000601 Remote DoS attack in RealServer: USSR-2000043</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1288">1288</ref>
<ref source="XF" url="http://xforce.iss.net/static/4587.php">realserver-malformed-remote-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0475" seq="2000-0475">
<status>Entry</status>
<desc>Windows 2000 allows a local user process to access another user's desktop within the same windows station, aka the &quot;Desktop Separation&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-020.asp">MS00-020</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1350">1350</ref>
<ref source="XF" url="http://xforce.iss.net/static/4714.php">win2k-desktop-separation</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0477" seq="2000-0477">
<status>Entry</status>
<desc>Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0136.html">20000614 Vulnerabilities in Norton Antivirus for Exchange</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1351">1351</ref>
<ref source="XF" url="http://xforce.iss.net/static/4710.php">antivirus-nav-zip-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0478" seq="2000-0478">
<status>Entry</status>
<desc>In some cases, Norton Antivirus for Exchange (NavExchange) enters a &quot;fail-open&quot; state which allows viruses to pass through the server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0136.html">20000614 Vulnerabilities in Norton Antivirus for Exchange</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1351">1351</ref>
<ref source="XF" url="http://xforce.iss.net/static/4709.php">antivirus-nav-fail-open</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6266">6266</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0481" seq="2000-0481">
<status>Entry</status>
<desc>Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name.</desc>
<refs>
<ref source="VULN-DEV" url="http://securityfocus.com/templates/archive.pike?list=82&amp;date=2000-06-22&amp;msg=00060200422401.01667@lez">20000601 Kmail heap overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1380">1380</ref>
<ref source="XF" url="http://xforce.iss.net/static/4993.php">kde-kmail-attachment-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0482" seq="2000-0482">
<status>Entry</status>
<desc>Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0473.html">20000605 FW-1 IP Fragmentation Vulnerability</ref>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#IP_Fragmentation">http://www.checkpoint.com/techsupport/alerts/list_vun.html#IP_Fragmentation</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1312">1312</ref>
<ref source="XF" url="http://xforce.iss.net/static/4609.php">fw1-packet-fragment-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1379">1379</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0483" seq="2000-0483">
<status>Entry</status>
<desc>The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0144.html">20000615 [Brian@digicool.com: [Zope] Zope security alert and 2.1.7 update [*important*]]</ref>
<ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert">http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-038.html">RHSA-2000:038</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A38.zope.asc">FreeBSD-SA-00:38</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0412.html">20000728 MDKSA-2000:026 Zope update</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000616103807.A3768@conectiva.com.br">2000615 Conectiva Linux Security Announcement - ZOPE</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1354">1354</ref>
<ref source="XF" url="http://xforce.iss.net/static/4716.php">zope-dtml-remote-modify</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0484" seq="2000-0484">
<status>Entry</status>
<desc>Buffer overflow in Small HTTP Server allows remote attackers to cause a denial of service via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96113651713414&amp;w=2">20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=96151775004229&amp;w=2">20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1355">1355</ref>
<ref source="XF" url="http://xforce.iss.net/static/4692.php">small-http-get-overflow-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0485" seq="2000-0485">
<status>Entry</status>
<desc>Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the &quot;DTS Password&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/62771">20000530 Fw: Steal Passwords Using SQL Server EM</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-041.asp">MS00-041</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1292">1292</ref>
<ref source="XF" url="http://xforce.iss.net/static/4582.php">mssql-dts-reveal-passwords</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0486" seq="2000-0486">
<status>Entry</status>
<desc>Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0369.html">20000530 An Analysis of the TACACS+ Protocol and its Implementations</ref>
<ref source="CONFIRM" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0370.html">http://archives.neohapsis.com/archives/bugtraq/2000-05/0370.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1293">1293</ref>
<ref source="XF" url="http://xforce.iss.net/static/4985.php">tacacsplus-packet-length-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0488" seq="2000-0488">
<status>Entry</status>
<desc>Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0148.html">20000601 DST2K0007: Buffer Overrun in ITHouse Mail Server v1.04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1285">1285</ref>
<ref source="XF" url="http://xforce.iss.net/static/4580.php">ithouse-rcpt-overflow(4580)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0489" seq="2000-0489">
<status>Entry</status>
<desc>FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9908270039010.16315-100000@thetis.deor.org">19990826 Local DoS in FreeBSD</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEJLCEAA.labs@ussrback.com">20000601 Local FreeBSD, Openbsd, NetBSD, DoS Vulnerability - Mac OS X affected</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/622">622</ref>
<ref source="XF" url="http://xforce.iss.net/static/3298.php">bsd-setsockopt-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0490" seq="2000-0490">
<status>Entry</status>
<desc>Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0407.html">20000601 Netwin's Dmail package</ref>
<ref source="CONFIRM" url="http://netwinsite.com/dmail/security.htm">http://netwinsite.com/dmail/security.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1297">1297</ref>
<ref source="XF" url="http://xforce.iss.net/static/4579.php">dmail-etrn-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0493" seq="2000-0493">
<status>Entry</status>
<desc>Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string.</desc>
<refs>
<ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0843.html">20000601 Vulnerability in SNTS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1289">1289</ref>
<ref source="XF" url="http://xforce.iss.net/static/4602.php">timesync-bo-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0494" seq="2000-0494">
<status>Entry</status>
<desc>Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0151.html">20000616 Veritas Volume Manager 3.0.x hole</ref>
<ref source="CONFIRM" url="http://seer.support.veritas.com/tnotes/volumeman/230053.htm">http://seer.support.veritas.com/tnotes/volumeman/230053.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1356">1356</ref>
<ref source="XF">veritas-volume-manager</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0495" seq="2000-0495">
<status>Entry</status>
<desc>Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the &quot;Malformed Windows Media Encoder Request&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-038.asp">MS00-038</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1282">1282</ref>
<ref source="XF" url="http://xforce.iss.net/static/4585.php">ms-malformed-media-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0497" seq="2000-0497">
<status>Entry</status>
<desc>IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0263.html">20000612 IBM WebSphere JSP showcode vulnerability</ref>
<ref source="CONFIRM" url="http://www-4.ibm.com/software/webservers/appserv/efix.html">http://www-4.ibm.com/software/webservers/appserv/efix.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1328">1328</ref>
<ref source="XF">websphere-jsp-source-read</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0498" seq="2000-0498">
<status>Entry</status>
<desc>Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0250.html">20000608 Potential vulnerability in Unify eWave ServletExec</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1328">1328</ref>
<ref source="XF" url="http://xforce.iss.net/static/4649.php">ewave-servletexec-jsp-source-read(4649)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0499" seq="2000-0499">
<status>Entry</status>
<desc>The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0262.htm">20000612 BEA WebLogic JSP showcode vulnerability</ref>
<ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000612.html">http://developer.bea.com/alerts/security_000612.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1328">1328</ref>
<ref source="XF" url="http://xforce.iss.net/static/4694.php">weblogic-jsp-source-read</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0500" seq="2000-0500">
<status>Entry</status>
<desc>The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.</desc>
<refs>
<ref source="CONFIRM" url="http://www.weblogic.com/docs51/admindocs/http.html#file">http://www.weblogic.com/docs51/admindocs/http.html#file</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96161462915381&amp;w=2">20000621 BEA WebLogic /file/ showcode vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1378">1378</ref>
<ref source="XF" url="http://xforce.iss.net/static/4775.php">weblogic-file-source-read</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0501" seq="2000-0501">
<status>Entry</status>
<desc>Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command and quickly exiting the server.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0277.html">20000616 mdaemon 2.8.5.0 WinNT and Win9x remote DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1366">1366</ref>
<ref source="XF" url="http://xforce.iss.net/static/4745.php">mdaemon-pass-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0502" seq="2000-0502">
<status>Entry</status>
<desc>Mcafee VirusScan 4.03 does not properly restrict access to the alert text file before it is sent to the Central Alert Server, which allows local users to modify alerts in an arbitrary fashion.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0038.html">20000607 Mcafee Alerting DOS vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1326">1326</ref>
<ref source="XF" url="http://xforce.iss.net/static/4641.php">mcafee-alerting-dos(4641)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6287">6287</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0504" seq="2000-0504">
<status>Entry</status>
<desc>libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0170.html">20000619 XFree86: libICE DoS</ref>
<ref source="CONFIRM" url="http://www.xfree86.org/security/">http://www.xfree86.org/security/</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1369">1369</ref>
<ref source="XF">linux-libice-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0505" seq="2000-0505">
<status>Entry</status>
<desc>The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSF.4.20.0006031912360.45740-100000@alive.znep.com">20000603 Re: IBM HTTP SERVER / APACHE</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1284">1284</ref>
<ref source="XF" url="http://xforce.iss.net/static/4575.php">ibm-http-file-retrieve</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0506" seq="2000-0506">
<status>Entry</status>
<desc>The &quot;capabilities&quot; feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the &quot;Linux kernel setuid/setcap vulnerability.&quot;</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006090852340.3475-300000@alfa.elzabsoft.pl">20000609 Sendmail &amp; procmail local root exploits on Linux kernel up to 2.2.16pre5</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-037.html">RHSA-2000:037</ref>
<ref source="TURBO">TLSA2000013-1</ref>
<ref source="SGI" url="ftp://sgigate.sgi.com/security/20000802-01-P">20000802-01-P</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0062.html">20000609 Trustix Security Advisory</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0063.html">20000608 CONECTIVA LINUX SECURITY ANNOUNCEMENT - kernel</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1322">1322</ref>
<ref source="XF">linux-kernel-capabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0507" seq="2000-0507">
<status>Entry</status>
<desc>Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95990195708509&amp;w=2">20000601 DST2K0006: Denial of Service Possibility in Imate WebMail Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1286">1286</ref>
<ref source="XF" url="http://xforce.iss.net/static/4586.php">nt-webmail-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0508" seq="2000-0508">
<status>Entry</status>
<desc>rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0073.html">20000608 Remote DOS in linux rpc.lockd</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1372">1372</ref>
<ref source="XF" url="http://xforce.iss.net/static/5050.php">linux-lockd-remote-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0510" seq="2000-0510">
<status>Entry</status>
<desc>CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref>
<ref source="CONFIRM" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1373">1373</ref>
<ref source="XF" url="http://xforce.iss.net/static/4846.php">debian-cups-malformed-ipp</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0511" seq="2000-0511">
<status>Entry</status>
<desc>CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref>
<ref source="CONFIRM" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1373">1373</ref>
<ref source="XF" url="http://xforce.iss.net/static/4846.php">debian-cups-posts</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0512" seq="2000-0512">
<status>Entry</status>
<desc>CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref>
<ref source="CONFIRM" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1373">1373</ref>
<ref source="XF" url="http://xforce.iss.net/static/4846.php">debian-cups-posts</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0513" seq="2000-0513">
<status>Entry</status>
<desc>CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref>
<ref source="CONFIRM" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1373">1373</ref>
<ref source="XF" url="http://xforce.iss.net/static/4846.php">debian-cups-posts</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0514" seq="2000-0514">
<status>Entry</status>
<desc>GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=ldvsnufao18.fsf@saint-elmos-fire.mit.edu">20000614 Security Advisory: REMOTE ROOT VULNERABILITY IN GSSFTP DAEMON</ref>
<ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/ftp.txt">http://web.mit.edu/kerberos/www/advisories/ftp.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1374">1374</ref>
<ref source="XF" url="http://xforce.iss.net/static/4734.php">kerberos-gssftpd-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4885">4885</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0515" seq="2000-0515">
<status>Entry</status>
<desc>The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006070511.OAA05492@dogfoot.hackerslab.org">20000607 [ Hackerslab bug_paper ] HP-UX SNMP daemon vulnerability</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006090640.XAA00779@hpchs.cup.hp.com">20000608 Re: HP-UX SNMP daemon vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1327">1327</ref>
<ref source="XF" url="http://xforce.iss.net/static/4643.php">hpux-snmp-daemon</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0516" seq="2000-0516">
<status>Entry</status>
<desc>When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0008.html">20000606 Shiva Access Manager 5.0.0 Plaintext LDAP root password.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1329">1329</ref>
<ref source="XF" url="http://xforce.iss.net/static/4612.php ">shiva-plaintext-ldap-password</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0517" seq="2000-0517">
<status>Entry</status>
<desc>Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-08.html">CA-2000-08</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1260">1260</ref>
<ref source="XF" url="http://xforce.iss.net/static/4550.php">netscape-ssl-certificate</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0518" seq="2000-0518">
<status>Entry</status>
<desc>Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different &quot;SSL Certificate Validation&quot; vulnerabilities.</desc>
<refs>
<ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-039.asp">MS00-039</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-10.html">CA-2000-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1309">1309</ref>
<ref source="XF" url="http://xforce.iss.net/static/4624.php">ie-invalid-frame-image-certificate</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0519" seq="2000-0519">
<status>Entry</status>
<desc>Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different &quot;SSL Certificate Validation&quot; vulnerabilities.</desc>
<refs>
<ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-039.asp">MS00-039</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-10.html">CA-2000-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1309">1309</ref>
<ref source="XF" url="http://xforce.iss.net/static/4627.php">ie-revalidate-certificate</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0521" seq="2000-0521">
<status>Entry</status>
<desc>Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0469.html">20000605 MDMA Advisory #5: Reading of CGI Scripts under Savant Webserver</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1313">1313</ref>
<ref source="XF" url="http://xforce.iss.net/static/4616.php">savant-source-read</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0522" seq="2000-0522">
<status>Entry</status>
<desc>RSA ACE/Server allows remote attackers to cause a denial of service by flooding the server's authentication request port with UDP packets, which causes the server to crash.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=011a01bfd14c$3c206960$050010ac@xtranet.co.uk">20000608 Potential DoS Attack on RSA's ACE/Server</ref>
<ref source="CONFIRM" url="ftp://ftp.securid.com/support/outgoing/dos/readme.txt">ftp://ftp.securid.com/support/outgoing/dos/readme.txt</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0197.html">20000714 Re: RSA Aceserver UDP Flood Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1332">1332</ref>
<ref source="XF" url="http://xforce.iss.net/static/5053.php">aceserver-udp-packet-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0523" seq="2000-0523">
<status>Entry</status>
<desc>Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0009.html">20000606 MDMA Advisory #6: EServ Logging Heap Overflow Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1315">1315</ref>
<ref source="XF" url="http://xforce.iss.net/static/4614.php">eserv-logging-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0525" seq="2000-0525">
<status>Entry</status>
<desc>OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0065.html">20000609 OpenSSH's UseLogin option allows remote access with root privilege.</ref>
<ref source="OPENBSD" url="http://www.openbsd.org/errata.html#uselogin">20000606 The non-default UseLogin feature in /etc/sshd_config is broken and should not be used.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1334">1334</ref>
<ref source="XF" url="http://xforce.iss.net/static/4646.php">openssh-uselogin-remote-exec</ref>
<ref source="OSVDB" url="http://www.osvdb.org/341">341</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0528" seq="2000-0528">
<status>Entry</status>
<desc>Net Tools PKI Server does not properly restrict access to remote attackers when the XUDA template files do not contain absolute pathnames for other files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0166.html">20000619 Net Tools PKI server exploits</ref>
<ref source="CONFIRM" url="ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt">ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1364">1364</ref>
<ref source="XF" url="http://xforce.iss.net/static/4743.php">nettools-pki-unauthenticated-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4353">4353</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0529" seq="2000-0529">
<status>Entry</status>
<desc>Net Tools PKI Server allows remote attackers to cause a denial of service via a long HTTP request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0166.html">20000619 Net Tools PKI server exploits</ref>
<ref source="CONFIRM" url="ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt">ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1363">1363</ref>
<ref source="XF" url="http://xforce.iss.net/static/4744.php">nettools-pki-http-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4352">4352</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0530" seq="2000-0530">
<status>Entry</status>
<desc>The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0387.html">20000531 KDE::KApplication feature?</ref>
<ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-015.0.txt">CSSA-2000-015.0</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-032.html">RHSA-2000:032</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1291">1291</ref>
<ref source="XF" url="http://xforce.iss.net/static/4583.php">kde-configuration-file-creation</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0532" seq="2000-0532">
<status>Entry</status>
<desc>A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered.</desc>
<refs>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-06/0031.html">FreeBSD-SA-00:21</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1323">1323</ref>
<ref source="XF" url="http://xforce.iss.net/static/4638.php">freebsd-ssh-ports</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1387">1387</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0533" seq="2000-0533">
<status>Entry</status>
<desc>Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files.</desc>
<refs>
<ref source="SGI" url="ftp://sgigate.sgi.com/security/20000601-01-P">20000601-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1379">1379</ref>
<ref source="XF" url="http://xforce.iss.net/static/4725.php">irix-workshop-cvconnect-overwrite</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0534" seq="2000-0534">
<status>Entry</status>
<desc>The apsfilter software in the FreeBSD ports package does not properly read user filter configurations, which allows local users to execute commands as the lpd user.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-00:22</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1325">1325</ref>
<ref source="XF" url="http://xforce.iss.net/static/4617.php">apsfilter-elevate-privileges</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1389">1389</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0536" seq="2000-0536">
<status>Entry</status>
<desc>xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry.</desc>
<refs>
<ref source="CONFIRM" url="http://www.synack.net/xinetd/">http://www.synack.net/xinetd/</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000619">20000619 xinetd: bug in access control mechanism</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1381">1381</ref>
<ref source="XF" url="http://xforce.iss.net/static/4986.php">xinetd-improper-restrictions</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0537" seq="2000-0537">
<status>Entry</status>
<desc>BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0013.html">20000606 BRU Vulnerability</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-018.0.txt">CSSA-2000-018.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1321">1321</ref>
<ref source="XF" url="http://xforce.iss.net/static/4644.php">bru-execlog-env-variable</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0538" seq="2000-0538">
<status>Entry</status>
<desc>ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96045469627806&amp;w=2">20000607 New Allaire ColdFusion DoS</ref>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=16122&amp;Method=Full">ASB00-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1314">1314</ref>
<ref source="XF" url="http://xforce.iss.net/static/4611.php">coldfusion-parse-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3399">3399</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0539" seq="2000-0539">
<status>Entry</status>
<desc>Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID's via the SessionServlet servlet.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=16290&amp;Method=Full">ASB00-015</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1386">1386</ref>
<ref source="XF" url="http://xforce.iss.net/static/4774.php">jrun-read-sample-files</ref>
<ref source="OSVDB" url="http://www.osvdb.org/818">818</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0540" seq="2000-0540">
<status>Entry</status>
<desc>JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=16290&amp;Method=Full">ASB00-015</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1386">1386</ref>
<ref source="XF" url="http://xforce.iss.net/static/4774.php">jrun-read-sample-files</ref>
<ref source="OSVDB" url="http://www.osvdb.org/2713">2713</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0541" seq="2000-0541">
<status>Entry</status>
<desc>The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0164.html">20000617 Infosec.20000617.panda.a</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4707">panda-antivirus-remote-admin(4707)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1359">1359</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0542" seq="2000-0542">
<status>Entry</status>
<desc>Tigris remote access server before 11.5.4.22 does not properly record Radius accounting information when a user fails the initial login authentication but subsequently succeeds.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0104.html">20000612 ACC/Ericsson Tigris Accounting Failure</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1345">1345</ref>
<ref source="XF" url="http://xforce.iss.net/static/4705.php">tigris-radius-login-failure</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0548" seq="2000-0548">
<status>Entry</status>
<desc>Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
<ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-031.html">RHSA-2000:031</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html">CA-2000-11</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref>
<ref source="XF">kerberos-emsg-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4875">4875</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0549" seq="2000-0549">
<status>Entry</status>
<desc>Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
<ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-031.html">RHSA-2000:031</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html">CA-2000-11</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0550" seq="2000-0550">
<status>Entry</status>
<desc>Kerberos 4 KDC program improperly frees memory twice (aka &quot;double-free&quot;), which allows remote attackers to cause a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref>
<ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-031.html">RHSA-2000:031</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html">CA-2000-11</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref>
<ref source="XF">kerberos-free-memory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1465">1465</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0551" seq="2000-0551">
<status>Entry</status>
<desc>The file transfer mechanism in Danware NetOp 6.0 does not provide authentication, which allows remote attackers to access and modify arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0339.html">20000523 I think</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1263">1263</ref>
<ref source="XF" url="http://xforce.iss.net/static/4569.php">danware-netop-bypass-security(4569)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0552" seq="2000-0552">
<status>Entry</status>
<desc>ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0237.html">20000606 ICQ2000A ICQmail temparary internet link vulnearbility</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1307">1307</ref>
<ref source="XF" url="http://xforce.iss.net/static/4607.php">icq-temp-link</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0553" seq="2000-0553">
<status>Entry</status>
<desc>Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping &quot;return-rst&quot; and &quot;keep state&quot; rules, allows remote attackers to bypass access restrictions.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0326.html">20000525 Security Vulnerability in IPFilter 3.3.15 and 3.4.3</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1308">1308</ref>
<ref source="XF" url="http://xforce.iss.net/static/4994.php">ipfilter-firewall-race-condition</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1377">1377</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0555" seq="2000-0555">
<status>Entry</status>
<desc>Ceilidh allows remote attackers to cause a denial of service via a large number of POST requests.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0246.html">20000608 DST2K0010: DoS &amp; Path Revealing Vulnerability in Ceilidh v2.60a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1320">1320</ref>
<ref source="XF" url="http://xforce.iss.net/static/4622.php">ceilidh-post-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0556" seq="2000-0556">
<status>Entry</status>
<desc>Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to cause a denial of service by sending a large user name to the user dialog running on port 8002.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0248.html">20000608 DST2K0011: DoS &amp; BufferOverrun in CMail v2.4.7 WebMail</ref>
<ref source="CONFIRM" url="http://www.computalynx.net/news/Jun2000/news0806200001.html">http://www.computalynx.net/news/Jun2000/news0806200001.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1319">1319</ref>
<ref source="XF" url="http://xforce.iss.net/static/4625.php">cmail-long-username-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0557" seq="2000-0557">
<status>Entry</status>
<desc>Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0248.html">20000608 DST2K0011: DoS &amp; BufferOverrun in CMail v2.4.7 WebMail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1318">1318</ref>
<ref source="XF" url="http://xforce.iss.net/static/4626.php">cmail-get-overflow-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0558" seq="2000-0558">
<status>Entry</status>
<desc>Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0249.html">20000608 DST2K0012: BufferOverrun in HP Openview Network Node Manager v6.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1317">1317</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0561" seq="2000-0561">
<status>Entry</status>
<desc>Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0175.html">20000620 DST2K0018: Multiple BufferOverruns in WebBBS HTTP Server v1.15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1365">1365</ref>
<ref source="XF" url="http://xforce.iss.net/static/4742.php">webbbs-get-request-overflow</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3544">3544</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0565" seq="2000-0565">
<status>Entry</status>
<desc>SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0100.html">20000613 SmartFTP Daemon v0.2 Beta Build 9 - Remote Exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1344">1344</ref>
<ref source="XF" url="http://xforce.iss.net/static/4706.php">smartftp-directory-traversal</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1394">1394</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0566" seq="2000-0566">
<status>Entry</status>
<desc>makewhatis in Linux man package allows local users to overwrite files via a symlink attack.</desc>
<refs>
<ref source="ISS">20000712 Insecure temporary file handling in Linux makewhatis</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-041.html">RHSA-2000:041</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-021.0.txt">CSSA-2000-021.0</ref>
<ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:015">MDKSA-2000:015</ref>
<ref source="BUGTRAQ">20000707 [Security Announce] man update</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0390.html">20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - MAN</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1434">1434</ref>
<ref source="XF" url="http://xforce.iss.net/static/4900.php">linux-man-makewhatis-tmp</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0567" seq="2000-0567">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the &quot;Malformed E-mail Header&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-043.mspx">MS00-043</ref>
<ref source="BUGTRAQ">20000719 Buffer Overflow in MS Outlook Email Clients</ref>
<ref source="BUGTRAQ">20000719 Aaron Drew - Security Advisory: Buffer Overflow in MS Outlook &amp; Outlook Express Email Clients</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1481">1481</ref>
<ref source="XF" url="http://xforce.iss.net/static/4953.php">outlook-date-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0568" seq="2000-0568">
<status>Entry</status>
<desc>Sybergen Secure Desktop 2.1 does not properly protect against false router advertisements (ICMP type 9), which allows remote attackers to modify default routes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4125690E.00524395.00@guardianit.se">20000630 Multiple vulnerabilities in Sybergen Secure Desktop</ref>
<ref source="XF">sybergen-routing-table-modify</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1417">1417</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0569" seq="2000-0569">
<status>Entry</status>
<desc>Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface.</desc>
<refs>
<ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0189.html">20000630 Any LAN user can crash Sygate</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1420">1420</ref>
<ref source="XF" url="http://xforce.iss.net/static/5049.php">sygate-udp-packet-dos(5049)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0570" seq="2000-0570">
<status>Entry</status>
<desc>FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0295.html">20000627 DoS in FirstClass Internet Services 5.770</ref>
<ref source="XF" url="http://xforce.iss.net/static/4843.php">firstclass-large-bcc-dos(4843)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1421">1421</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5718">5718</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0571" seq="2000-0571">
<status>Entry</status>
<desc>LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-07-8&amp;msg=NCBBKFKDOLAGKIAPMILPCEIHCFAA.labs@ussrback.com">20000703 Remote DoS Attack in LocalWEB HTTP Server 1.2.0 Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1423">1423</ref>
<ref source="XF" url="http://xforce.iss.net/static/4896.php">localweb-get-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0573" seq="2000-0573">
<status>Entry</status>
<desc>The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96171893218000&amp;w=2">20000622 WuFTPD: Providing *remote* root since at least1994</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96179429114160&amp;w=2">20000623 WUFTPD 2.6.0 remote root exploit</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96299933720862&amp;w=2">20000707 New Released Version of the WuFTPD Sploit</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000623091822.3321.qmail@fiver.freemessage.com">20000623 ftpd: the advisory version</ref>
<ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2000.02">AA-2000.02</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-13.html">CA-2000-13</ref>
<ref source="DEBIAN">20000623</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-020.0.txt">CSSA-2000-020.0</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-039.html">RHSA-2000:039</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0244.html">20000723 CONECTIVA LINUX SECURITY ANNOUNCEMENT - WU-FTPD (re-release)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0017.html">20000702 [Security Announce] wu-ftpd update</ref>
<ref source="BUGTRAQ">20000929 [slackware-security] wuftpd vulnerability - Slackware 4.0, 7.0, 7.1, -current</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:29.wu-ftpd.asc.v1.1">FreeBSD-SA-00:29</ref>
<ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-009.txt.asc">NetBSD-SA2000-009</ref>
<ref source="XF">wuftp-format-string-stack-overwrite</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1387">1387</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4773">wuftp-format-string-stack-overwrite(4773)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0575" seq="2000-0575">
<status>Entry</status>
<desc>SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96256265914116&amp;w=2">20000630 Kerberos security vulnerability in SSH-1.2.27</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1426">1426</ref>
<ref source="XF" url="http://xforce.iss.net/static/4903.php">ssh-kerberos-tickets-disclosure(4903)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0576" seq="2000-0576">
<status>Entry</status>
<desc>Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0027.html">20000704 Oracle Web Listener for AIX DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1427">1427</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0577" seq="2000-0577">
<status>Entry</status>
<desc>Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211351280.23780-100000@nimue.tpi.pl">20000621 Netscape FTP Server - &quot;Professional&quot; as hell :&gt;</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0345.html">20000629 (forw) Re: Netscape ftp Server (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1411">1411</ref>
<ref source="XF">netscape-ftpserver-chroot</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0579" seq="2000-0579">
<status>Entry</status>
<desc>IRIX crontab creates temporary files with predictable file names and with the umask of the user, which could allow local users to modify another user's crontab file as it is being edited.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0204.html">20000621 Predictability Problems in IRIX Cron and Compilers</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1413">1413</ref>
<ref source="XF">irix-cron-modify-crontab</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0581" seq="2000-0581">
<status>Entry</status>
<desc>Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630161841.4619A-100000@fjord.fscinternet.com">20000630 SecureXpert Advisory [SX-20000620-1]</ref>
<ref source="XF">win2k-telnetserver-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1414">1414</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0582" seq="2000-0582">
<status>Entry</status>
<desc>Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630162106.4619C-100000@fjord.fscinternet.com">20000630 SecureXpert Advisory [SX-20000620-3]</ref>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#SMTP_Security">http://www.checkpoint.com/techsupport/alerts/list_vun.html#SMTP_Security</ref>
<ref source="XF">fw1-resource-overload-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1416">1416</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1438">1438</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0583" seq="2000-0583">
<status>Entry</status>
<desc>vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=395BD2A8.5D3396A7@secureaustin.com">20000626 vpopmail-3.4.11 problems</ref>
<ref source="CONFIRM" url="http://www.vpopmail.cx/vpopmail-ChangeLog">http://www.vpopmail.cx/vpopmail-ChangeLog</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1418">1418</ref>
<ref source="XF">vpopmail-format-string</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0584" seq="2000-0584">
<status>Entry</status>
<desc>Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.</desc>
<refs>
<ref source="MISC" url="http://shadowpenguin.backsection.net/advisories/advisory038.html">http://shadowpenguin.backsection.net/advisories/advisory038.html</ref>
<ref source="DEBIAN">20000702</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:31.canna.asc.v1.1">FreeBSD-SA-00:31</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1445">1445</ref>
<ref source="XF" url="http://xforce.iss.net/static/4912.php">canna-bin-execute-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0585" seq="2000-0585">
<status>Entry</status>
<desc>ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0247.html">20000624 Possible root exploit in ISC DHCP client.</ref>
<ref source="OPENBSD">20000624 A serious bug in dhclient(8) could allow strings from a malicious dhcp server to be executed in the shell as root.</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000628">20000628 dhcp client: remote root exploit in dhcp client </ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:34.dhclient.asc">FreeBSD-SA-00:34</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0014.html">20000702 [Security Announce] dhcp update</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_56.html">20000711 Security Hole in dhclient &lt; 2.0</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-008.txt.asc">NetBSD-SA2000-008</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1388">1388</ref>
<ref source="XF" url="http://xforce.iss.net/static/4772.php">openbsd-isc-dhcp</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0586" seq="2000-0586">
<status>Entry</status>
<desc>Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command.</desc>
<refs>
<ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/1092.html">20000628 dalnet 4.6.5 remote vulnerability</ref>
<ref source="XF">ircd-dalnet-summon-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1404">1404</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0587" seq="2000-0587">
<status>Entry</status>
<desc>The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.</desc>
<refs>
<ref source="XF">glftpd-privpath-directive</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10006261041360.31907-200000@twix.thrijswijk.nl">20000626 Glftpd privpath bugs... +fix</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0317.html">20000627 Re: Glftpd privpath bugs... +fix</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1401">1401</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0588" seq="2000-0588">
<status>Entry</status>
<desc>SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html">20000626 sawmill5.0.21 old path bug &amp; weak hash algorithm</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html">20000706 Patch for Flowerfire Sawmill Vulnerabilities Available</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1402">1402</ref>
<ref source="XF">sawmill-file-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0590" seq="2000-0590">
<status>Entry</status>
<desc>Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0076.html">20000706 Vulnerability in Poll_It cgi v2.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1431">1431</ref>
<ref source="XF" url="http://xforce.iss.net/static/4878.php">http-cgi-pollit-variable-overwrite(4878)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0591" seq="2000-0591">
<status>Entry</status>
<desc>Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0038.html">20000705 Novell BorderManager 3.0 EE - Encoded URL rule bypass</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1432">1432</ref>
<ref source="XF">bordermanager-bypass-url-restriction</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0593" seq="2000-0593">
<status>Entry</status>
<desc>WinProxy 2.0 and 2.0.1 allows remote attackers to cause a denial of service by sending an HTTP GET request without listing an HTTP version number.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006271417.GFE84146.-BJXON@lac.co.jp">20000627 [SPSadvisory #37]WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow</ref>
<ref source="XF" url="http://xforce.iss.net/static/4831.php">winproxy-get-dos(4831)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1400">1400</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0594" seq="2000-0594">
<status>Entry</status>
<desc>BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.</desc>
<refs>
<ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0018.html">20000704 BitchX /ignore bug</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0026.html">20000704 BitchX exploit possibly waiting to happen, certain DoS</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-042.html">RHSA-2000:042</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-07/0042.html">FreeBSD-SA-00:32</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-022.0.txt">CSSA-2000-022.0</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0105.html">20000707 BitchX update</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0098.html">20000707 CONECTIVA LINUX SECURITY ANNOUNCEMENT - BitchX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1436">1436</ref>
<ref source="XF" url="http://xforce.iss.net/static/4897.php">irc-bitchx-invite-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0595" seq="2000-0595">
<status>Entry</status>
<desc>libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.</desc>
<refs>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-07/0035.html">FreeBSD-SA-00:24</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1437">1437</ref>
<ref source="XF">bsd-libedit-editrc</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1446">1446</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0596" seq="2000-0596">
<status>Entry</status>
<desc>Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the &quot;IE Script&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39589359.762392DB@nat.bg">20000627 IE 5 and Access 2000 vulnerability - executing programs</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=000d01bfe0fb$418f59b0$96217aa8@src.bu.edu">20000627 FW: IE 5 and Access 2000 vulnerability - executing programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-049.asp">MS00-049</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-16.html">CA-2000-16</ref>
<ref source="XF">ie-access-vba-code-execute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1398">1398</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0597" seq="2000-0597">
<status>Entry</status>
<desc>Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the &quot;Office HTML Script&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39589349.ED9DBCAB@nat.bg">20000627 IE 5 and Excel 2000, PowerPoint 2000 vulnerability - executing programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-049.asp">MS00-049</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1399">1399</ref>
<ref source="XF">ie-powerpoint-activex-object-execute</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0598" seq="2000-0598">
<status>Entry</status>
<desc>Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0268.html">20000626 Proxy+ Telnet Gateway Problems</ref>
<ref source="MISC" url="http://www.proxyplus.cz/faq/articles/EN/art01002.htm">http://www.proxyplus.cz/faq/articles/EN/art01002.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1395">1395</ref>
<ref source="XF">fortech-proxy-telnet-gateway</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0599" seq="2000-0599">
<status>Entry</status>
<desc>Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0335.html">20000629 iMesh 1.02 vulnerability</ref>
<ref source="MISC" url="http://www.imesh.com/download/download.html">http://www.imesh.com/download/download.html</ref>
<ref source="XF">imesh-tcp-port-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1407">1407</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0600" seq="2000-0600">
<status>Entry</status>
<desc>Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0264.html">20000626 Netscape Enterprise Server for NetWare Virtual Directory Vulnerab ility</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1393">1393</ref>
<ref source="XF" url="http://xforce.iss.net/static/4780.php">netscape-virtual-directory-bo(4780)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0601" seq="2000-0601">
<status>Entry</status>
<desc>LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSF.4.10.10006252056110.74551-100000@unix.za.net">20000625 LeafChat Denial of Service</ref>
<ref source="CONFIRM" url="http://www.leafdigital.com/Software/leafChat/history.html">http://www.leafdigital.com/Software/leafChat/history.html</ref>
<ref source="XF">irc-leafchat-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1396">1396</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0602" seq="2000-0602">
<status>Entry</status>
<desc>Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211209500.22969-100000@nimue.tpi.pl">20000621 rh 6.2 - gid compromises, etc</ref>
<ref source="XF">redhat-secure-locate-path</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1385">1385</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0603" seq="2000-0603">
<status>Entry</status>
<desc>Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the &quot;Stored Procedure Permissions&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-048.asp">MS00-048</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1444">1444</ref>
<ref source="XF" url="http://xforce.iss.net/static/4921.php">mssql-procedure-perms</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0604" seq="2000-0604">
<status>Entry</status>
<desc>gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211209500.22969-100000@nimue.tpi.pl">20000621 rh 6.2 - gid compromises, etc</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1383">1383</ref>
<ref source="XF">redhat-gkermit</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0610" seq="2000-0610">
<status>Entry</status>
<desc>NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0243.html">20000623 NetWin dMailWeb Unrestricted Mail Relay</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1390">1390</ref>
<ref source="XF" url="http://xforce.iss.net/static/4770.php">netwin-dmailweb-newline</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0611" seq="2000-0611">
<status>Entry</status>
<desc>The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0243.html">20000623 NetWin dMailWeb Unrestricted Mail Relay</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1391">1391</ref>
<ref source="XF" url="http://xforce.iss.net/static/4771.php">netwin-dmailweb-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0613" seq="2000-0613">
<status>Entry</status>
<desc>Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=B3D6883199DBD311868100A0C9FC2CDC046B72@protea.citec.net">20000320 PIX DMZ Denial of Service - TCP Resets</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/pixtcpreset-pub.shtml">20000711 Cisco Secure PIX Firewall TCP Reset Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1454">1454</ref>
<ref source="XF" url="http://xforce.iss.net/static/4928.php">cisco-pix-firewall-tcp</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1457">1457</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0615" seq="2000-0615">
<status>Entry</status>
<desc>LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0117.html">20000709 LPRng lpd should not be SETUID root</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1447">1447</ref>
<ref source="XF" url="http://xforce.iss.net/static/7361.php">lpd-suid-root(7361)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0616" seq="2000-0616">
<status>Entry</status>
<desc>Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0294.html">HPSBMP0006-007</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1405">1405</ref>
<ref source="XF">hp-turboimage-dbutil</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0619" seq="2000-0619">
<status>Entry</status>
<desc>Top Layer AppSwitch 2500 allows remote attackers to cause a denial of service via malformed ICMP packets.</desc>
<refs>
<ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0680.html">20000520 TopLayer layer 7 switch Advisory</ref>
<ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0921.html">20000614 Update on TopLayer Advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1258">1258</ref>
<ref source="XF" url="http://xforce.iss.net/static/7364.php">toplayer-icmp-dos(7364)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0620" seq="2000-0620">
<status>Entry</status>
<desc>libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96146116627474&amp;w=2">20000619 XFree86: Various nasty libX11 holes</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1409">1409</ref>
<ref source="XF" url="http://xforce.iss.net/static/4996.php">libx11-infinite-loop-dos(4996)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0621" seq="2000-0621">
<status>Entry</status>
<desc>Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client's system via a malformed HTML message that stores files outside of the cache, aka the &quot;Cache Bypass&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-046.asp">MS00-046</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-14.html">CA-2000-14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1501">1501</ref>
<ref source="XF" url="http://xforce.iss.net/static/5013.php">outlook-cache-bypass</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0622" seq="2000-0622">
<status>Entry</status>
<desc>Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long &quot;keywords&quot; parameter.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/research/covert/advisories/043.asp">20000719 O'Reilly WebSite Professional Overflow</ref>
<ref source="CONFIRM" url="http://website.oreilly.com/support/software/wspro25_releasenotes.txt">http://website.oreilly.com/support/software/wspro25_releasenotes.txt</ref>
<ref source="XF" url="http://xforce.iss.net/static/4962.php">website-webfind-bo(4962)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1487">1487</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0624" seq="2000-0624">
<status>Entry</status>
<desc>Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0289.html">20000720 Winamp M3U playlist parser buffer overflow security vulnerability</ref>
<ref source="CONFIRM" url="http://www.winamp.com/getwinamp/newfeatures.jhtml">http://www.winamp.com/getwinamp/newfeatures.jhtml</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1496">1496</ref>
<ref source="XF" url="http://xforce.iss.net/static/4956.php">winamp-playlist-parser-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0627" seq="2000-0627">
<status>Entry</status>
<desc>BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0254.html">20000718 Blackboard Courseinfo v4.0 User Authentication</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000719151904.I17986@securityfocus.com">20000719 Security Fix for Blackboard CourseInfo 4.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1486">1486</ref>
<ref source="XF" url="http://xforce.iss.net/static/4946.php">blackboard-courseinfo-dbase-modification</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0628" seq="2000-0628">
<status>Entry</status>
<desc>The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0142.html">20000710 ANNOUNCE Apache::ASP v1.95 - Security Hole Fixed</ref>
<ref source="CONFIRM" url="http://www.nodeworks.com/asp/changes.html">http://www.nodeworks.com/asp/changes.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1457">1457</ref>
<ref source="XF" url="http://xforce.iss.net/static/4931.php">apache-source-asp-file-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0630" seq="2000-0630">
<status>Entry</status>
<desc>IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the &quot;File Fragment Reading via .HTR&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-044.asp">MS00-044</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1488">1488</ref>
<ref source="XF" url="http://xforce.iss.net/static/5104.php">iis-htr-obtain-code</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0631" seq="2000-0631">
<status>Entry</status>
<desc>An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the &quot;Absent Directory Browser Argument&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96390444022878&amp;w=2">20000718 ISBASE Security Advisory(SA2000-02)</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-044.asp">MS00-044</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1476">1476</ref>
<ref source="XF" url="http://xforce.iss.net/static/4951.php">iis-absent-directory-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0632" seq="2000-0632">
<status>Entry</status>
<desc>Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/43_Advisory.asp">20000717 [COVERT-2000-07] LISTSERV Web Archive Remote Overflow</ref>
<ref source="CONFIRM" url="http://www.lsoft.com/news/default.asp?item=Advisory1">http://www.lsoft.com/news/default.asp?item=Advisory1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1490">1490</ref>
<ref source="XF" url="http://xforce.iss.net/static/4952.php">lsoft-listserv-querystring-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0633" seq="2000-0633">
<status>Entry</status>
<desc>Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-053.html">RHSA-2000:053</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0251.html">20000718 MDKSA-2000:020 usermode update</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0117.html">20000812 Conectiva Linux security announcement - usermode</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1489">1489</ref>
<ref source="XF" url="http://xforce.iss.net/static/4944.php">linux-usermode-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0634" seq="2000-0634">
<status>Entry</status>
<desc>The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0223.html">20000717 S21SEC-003: Vulnerabilities in CommuniGate Pro v3.2.4</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1493">1493</ref>
<ref source="XF" url="http://xforce.iss.net/static/5105.php">communigate-pro-file-read</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5774">5774</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0635" seq="2000-0635">
<status>Entry</status>
<desc>The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0150.html">20000711 Akopia MiniVend Piped Command Execution Vulnerability</ref>
<ref source="CONFIRM" url="http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html">http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1449">1449</ref>
<ref source="XF" url="http://xforce.iss.net/static/4880.php">minivend-viewpage-sample</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0636" seq="2000-0636">
<status>Entry</status>
<desc>HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0265.html">20000719 HP Jetdirect - Invalid FTP Command DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1491">1491</ref>
<ref source="XF" url="http://xforce.iss.net/static/4947.php">hp-jetdirect-quote-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0637" seq="2000-0637">
<status>Entry</status>
<desc>Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the &quot;Excel REGISTER.ID Function&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=396B3F8F.9244D290@nat.bg">20000711 Excel 2000 vulnerability - executing programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-051.asp">MS00-051</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1451">1451</ref>
<ref source="XF" url="http://xforce.iss.net/static/5016.php">excel-register-function</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0638" seq="2000-0638">
<status>Entry</status>
<desc>bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0146.html">20000711 BIG BROTHER EXPLOIT</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0147.html">20000711 REMOTE EXPLOIT IN ALL CURRENT VERSIONS OF BIG BROTHER</ref>
<ref source="CONFIRM" url="http://bb4.com/README.CHANGES">http://bb4.com/README.CHANGES</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1455">1455</ref>
<ref source="XF" url="http://xforce.iss.net/static/4879.php">http-cgi-bigbrother-bbhostsvc</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0639" seq="2000-0639">
<status>Entry</status>
<desc>The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0171.html">20000711 Big Brother filename extension vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1494">1494</ref>
<ref source="XF" url="http://xforce.iss.net/static/5103.php">big-brother-filename-extension</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1472">1472</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0640" seq="2000-0640">
<status>Entry</status>
<desc>Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0114.html">20000708 gnu-pop3d (FTGate problem), Savant Webserver, Guild FTPd </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1452">1452</ref>
<ref source="XF" url="http://xforce.iss.net/static/4922.php">guild-ftpd-disclosure</ref>
<ref source="OSVDB" url="http://www.osvdb.org/573">573</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0641" seq="2000-0641">
<status>Entry</status>
<desc>Savant web server allows remote attackers to execute arbitrary commands via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0114.html">20000708 gnu-pop3d (FTGate problem), Savant Webserver, Guild FTPd </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1453">1453</ref>
<ref source="XF" url="http://xforce.iss.net/static/4901.php">savant-get-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0642" seq="2000-0642">
<status>Entry</status>
<desc>The default configuration of WebActive HTTP Server 1.00 stores the web access log active.log in the document root, which allows remote attackers to view the logs by directly requesting the page.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200007130827.BAA32671@Rage.Resentment.org">20000711 Lame DoS in WEBactive win65/NT server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1497">1497</ref>
<ref source="XF" url="http://xforce.iss.net/static/5184.php">webactive-active-log</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0643" seq="2000-0643">
<status>Entry</status>
<desc>Buffer overflow in WebActive HTTP Server 1.00 allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200007130827.BAA32671@Rage.Resentment.org">20000711 Lame DoS in WEBactive win65/NT server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1470">1470</ref>
<ref source="XF" url="http://xforce.iss.net/static/4949.php">webactive-long-get-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0644" seq="2000-0644">
<status>Entry</status>
<desc>WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html">20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1506">1506</ref>
<ref source="XF" url="http://xforce.iss.net/static/5003.php">wftpd-stat-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1477">1477</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0650" seq="2000-0650">
<status>Entry</status>
<desc>The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=2753">20000711 Potential Vulnerability in McAfee Netshield and VirusScan 4.5</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1458">1458</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5177">nai-virusscan-netshield-autoupgrade(5177)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1458">1458</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4200">4200</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0651" seq="2000-0651">
<status>Entry</status>
<desc>The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim's machine.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=06256915.00591E18.00@uprrsmtp2.notes.up.com">20000707 Novell Border Manger - Anyone can pose as an authenticated user</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1440">1440</ref>
<ref source="XF" url="http://xforce.iss.net/static/5186.php">novell-bordermanager-verification</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0652" seq="2000-0652">
<status>Entry</status>
<desc>IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the &quot;/servlet/file&quot; string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0342.html">20000723 IBM WebSphere default servlet handler showcode vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1500">1500</ref>
<ref source="XF" url="http://xforce.iss.net/static/5012.php">websphere-showcode</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0654" seq="2000-0654">
<status>Entry</status>
<desc>Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the &quot;DTS Password&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-041.asp">MS00-041</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1466">1466</ref>
<ref source="XF" url="http://xforce.iss.net/static/4582.php">mssql-dts-reveal-passwords</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0655" seq="2000-0655">
<status>Entry</status>
<desc>Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200007242356.DAA01274%40false.com">20000724 JPEG COM Marker Processing Vulnerability in Netscape Browsers</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-046.html">RHSA-2000:046</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_60.html">20000823 Security Hole in Netscape, Versions 4.x, possibly others</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000016.html">TLSA2000017-1</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-011.txt.asc">NetBSD-SA2000-011</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:39.netscape.asc">FreeBSD-SA-00:39</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0456.html">20000801 MDKSA-2000:027-1 netscape update</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0116.html">20000810 Conectiva Linux Security Announcement - netscape</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1503">1503</ref>
<ref source="XF">netscape-jpg-comment</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0660" seq="2000-0660">
<status>Entry</status>
<desc>The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0173.html">20000712 Infosec.20000712.worldclient.2.1</ref>
<ref source="CONFIRM" url="http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt">http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1462">1462</ref>
<ref source="XF" url="http://xforce.iss.net/static/4913.php">worldclient-dir-traverse</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1459">1459</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0661" seq="2000-0661">
<status>Entry</status>
<desc>WircSrv IRC Server 5.07s allows remote attackers to cause a denial of service via a long string to the server port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0120.html">20000710 Remote DoS Attack in WircSrv Irc Server v5.07s Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1448">1448</ref>
<ref source="XF" url="http://xforce.iss.net/static/4914.php">wircsrv-character-flood-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0662" seq="2000-0662">
<status>Entry</status>
<desc>Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=396EF9D5.62EEC625@nat.bg">20000714 IE 5.5 and 5.01 vulnerability - reading at least local and from any host text and parsed html files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1474">1474</ref>
<ref source="XF" url="http://xforce.iss.net/static/5107.php">ie-dhtmled-file-read(5107)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0663" seq="2000-0663">
<status>Entry</status>
<desc>The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the &quot;Relative Shell Path&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-052.asp">MS00-052</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=269049">Q269049</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1507">1507</ref>
<ref source="XF" url="http://xforce.iss.net/static/5040.php">explorer-relative-path-name</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0664" seq="2000-0664">
<status>Entry</status>
<desc>AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0374.html">20000726 AnalogX &quot;SimpleServer:WWW&quot; dot dot bug</ref>
<ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1508">1508</ref>
<ref source="XF" url="http://xforce.iss.net/static/4999.php">analogx-simpleserver-directory-path</ref>
<ref source="OSVDB" url="http://www.osvdb.org/388">388</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0665" seq="2000-0665">
<status>Entry</status>
<desc>GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0031.html">20000717 DoS in Gamsoft TelSrv telnet server for MS Windows 95/98/NT/2k.</ref>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0056.html">20000729 TelSrv Reveals Usernames &amp; Passwords After DoS Attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1478">1478</ref>
<ref source="XF" url="http://xforce.iss.net/static/4945.php">gamsoft-telsrv-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/373">373</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0666" seq="2000-0666">
<status>Entry</status>
<desc>rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0206.html">20000716 Lots and lots of fun with rpc.statd</ref>
<ref source="DEBIAN">20000719a</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-043.html">RHSA-2000:043</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0230.html">20000717 CONECTIVA LINUX SECURITY ANNOUNCEMENT - nfs-utils</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0236.html">20000718 Trustix Security Advisory - nfs-utils</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0260.html">20000718 [Security Announce] MDKSA-2000:021 nfs-utils update</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-025.0.txt">CSSA-2000-025.0</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-17.html">CA-2000-17</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1480">1480</ref>
<ref source="XF" url="http://xforce.iss.net/static/4939.php">linux-rpcstatd-format-overwrite</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0668" seq="2000-0668">
<status>Entry</status>
<desc>pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-044.html">RHSA-2000:044</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0398.html">20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - PAM</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0455.html">20000801 MDKSA-2000:029 pam update</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1513">1513</ref>
<ref source="XF" url="http://xforce.iss.net/static/5001.php">linux-pam-console</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0669" seq="2000-0669">
<status>Entry</status>
<desc>Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=000501bfeab5$9330c3d0$d801a8c0@dimuthu.baysidegrp.com.au">20000711 Remote Denial Of Service -- NetWare 5.0 with SP 5</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1467">1467</ref>
<ref source="XF">netware-port40193-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0670" seq="2000-0670">
<status>Entry</status>
<desc>The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0178.html">20000712 cvsweb: remote shell for cvs committers</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0196.html">20000714 MDKSA-2000:019 cvsweb update</ref>
<ref source="DEBIAN">20000719b</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:37.cvsweb.asc">FreeBSD-SA-00:37</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000015.html">TLSA2000016-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1469">1469</ref>
<ref source="XF" url="http://xforce.iss.net/static/4925.php">cvsweb-shell-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0671" seq="2000-0671">
<status>Entry</status>
<desc>Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0321.html">20000721 Roxen security alert: Problems with URLs containing null characters.</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0307.html">20000721 Roxen Web Server Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1510">1510</ref>
<ref source="XF" url="http://xforce.iss.net/static/4965.php">roxen-null-char-url</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0672" seq="2000-0672">
<status>Entry</status>
<desc>The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0309.html">20000721 Jakarta-tomcat.../admin</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1548">1548</ref>
<ref source="XF" url="http://xforce.iss.net/static/5160.php">jakarta-tomcat-admin</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0673" seq="2000-0673">
<status>Entry</status>
<desc>The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the &quot;NetBIOS Name Server Protocol Spoofing&quot; vulnerability.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/research/covert/advisories/044.asp">20000727 Windows NetBIOS Name Conflicts</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-047.asp">MS00-047</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1514">1514</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1515">1515</ref>
<ref source="XF" url="http://xforce.iss.net/static/5035.php">netbios-name-server-spoofing</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0674" seq="2000-0674">
<status>Entry</status>
<desc>ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0177.html">20000712 ftp.pl vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1471">1471</ref>
<ref source="XF" url="http://xforce.iss.net/static/5187.php">virtualvision-ftp-browser</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0675" seq="2000-0675">
<status>Entry</status>
<desc>Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=00af01bfece2$a52cbd80$367e1ec4@kungphusion">20000713 The MDMA Crew's GateKeeper Exploit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1477">1477</ref>
<ref source="XF" url="http://xforce.iss.net/static/4948.php">gatekeeper-long-string-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0676" seq="2000-0676">
<status>Entry</status>
<desc>Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the &quot;file&quot;, &quot;http&quot;, &quot;https&quot;, and &quot;ftp&quot; protocols, as demonstrated by Brown Orifice.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0019.html">20000804 Dangerous Java/Netscape Security Hole</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-054.html">RHSA-2000:054</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-027.1.txt">CSSA-2000-027.1</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:39.netscape.asc">FreeBSD-SA-00:39</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_60.html">20000823 Security Hole in Netscape, Versions 4.x, possibly others</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0115.html">20000810 MDKSA-2000:033 Netscape Java vulnerability</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0265.html">20000821 MDKSA-2000:036 - netscape update</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0236.html">20000818 Conectiva Linux Security Announcement - netscape</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-15.html">CA-2000-15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1546">1546</ref>
<ref source="XF">java-brownorifice</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0677" seq="2000-0677">
<status>Entry</status>
<desc>Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise60.php">20000907 Buffer Overflow in IBM Net.Data db2www CGI program.</ref>
<ref source="XF" url="http://xforce.iss.net/static/4976.php">ibm-netdata-db2www-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0678" seq="2000-0678">
<status>Entry</status>
<desc>PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-18.html">CA-2000-18</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1606">1606</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4354">4354</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0679" seq="2000-0679">
<status>Entry</status>
<desc>The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dhvou2daoebb.fsf%40serein.m17n.org">20000728 cvs security problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1523">1523</ref>
<ref source="XF">cvs-client-creates-file</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0681" seq="2000-0681">
<status>Entry</status>
<desc>Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0186.html">20000815 BEA Weblogic server proxy library vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1570">1570</ref>
<ref source="XF">weblogic-plugin-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0682" seq="2000-0682">
<status>Entry</status>
<desc>BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html">20000728 BEA's WebLogic force handlers show code vulnerability</ref>
<ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000731.html">http://developer.bea.com/alerts/security_000731.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1518">1518</ref>
<ref source="XF">weblogic-fileservlet-show-code</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1481">1481</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0683" seq="2000-0683">
<status>Entry</status>
<desc>BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html">20000728 BEA's WebLogic force handlers show code vulnerability</ref>
<ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000728.html">http://developer.bea.com/alerts/security_000728.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1517">1517</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1480">1480</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0684" seq="2000-0684">
<status>Entry</status>
<desc>BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html">20000731 BEA's WebLogic *.jsp/*.jhtml remote command execution</ref>
<ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000731.html">http://developer.bea.com/alerts/security_000731.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1525">1525</ref>
<ref source="XF">html-malicious-tags</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0685" seq="2000-0685">
<status>Entry</status>
<desc>BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html">20000731 BEA's WebLogic *.jsp/*.jhtml remote command execution</ref>
<ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000731.html">http://developer.bea.com/alerts/security_000731.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1525">1525</ref>
<ref source="XF">html-malicious-tags</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0693" seq="2000-0693">
<status>Entry</status>
<desc>pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the &quot;cp&quot; program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate &quot;cp&quot; program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1563">1563</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1501">1501</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0694" seq="2000-0694">
<status>Entry</status>
<desc>pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5740">5740</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0698" seq="2000-0698">
<status>Entry</status>
<desc>Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/77361">20000819 RH 6.1 / 6.2 minicom vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1599">1599</ref>
<ref source="XF" url="http://xforce.iss.net/static/5151.php">minicom-capture-groupown</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0699" seq="2000-0699">
<status>Entry</status>
<desc>Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0028.html">20000806 HPUX FTPd vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1560">1560</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0700" seq="2000-0700">
<status>Entry</status>
<desc>Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/gsraclbypassdos-pub.shtml">20000803 Possible Access Control Bypass and Denial of Service in Gigabit Switch Routers Using Gigabit Ethernet or Fast Ethernet Cards</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1541">1541</ref>
<ref source="OSVDB" url="http://www.osvdb.org/793">793</ref>
<ref source="OSVDB" url="http://www.osvdb.org/798">798</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0702" seq="2000-0702">
<status>Entry</status>
<desc>The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0261.html">20000821 [HackersLab bugpaper] HP-UX net.init rc script</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1602">1602</ref>
<ref source="XF" url="http://xforce.iss.net/static/5131.php">hp-netinit-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0703" seq="2000-0703">
<status>Entry</status>
<desc>suidperl (aka sperl) does not properly cleanse the escape sequence &quot;~!&quot; before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the &quot;interactive&quot; environmental variable and calling suidperl with a filename that contains the escape sequence.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0022.html">20000805 sperl 5.00503 (and newer ;) exploit</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_59.html">20000810 Security Hole in perl, all versions</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-026.0.txt">CSSA-2000-026.0</ref>
<ref source="DEBIAN">20000810</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-048.html">RHSA-2000:048</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000017.html">TLSA2000018-1</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0153.html">20000814 Trustix Security Advisory - perl and mailx</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0086.html">20000808 MDKSA-2000:031 perl update</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0113.html">20000810 Conectiva Linux security announcemente - PERL</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1547">1547</ref>
<ref source="XF">perl-shell-escape</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0705" seq="2000-0705">
<status>Entry</status>
<desc>ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0459.html">20000802 [ Hackerslab bug_paper ] ntop web mode vulnerabliity</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-049.html">RHSA-2000:049</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1550">1550</ref>
<ref source="XF">ntop-remote-file-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1496">1496</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0706" seq="2000-0706">
<status>Entry</status>
<desc>Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:36.ntop.asc">FreeBSD-SA-00:36</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000830">20000830 ntop: Still remotely exploitable using buffer overflows</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1576">1576</ref>
<ref source="XF">ntop-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1513">1513</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0707" seq="2000-0707">
<status>Entry</status>
<desc>PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0015.html">20000804 PCCS MySQL DB Admin Tool v1.2.3- Advisory</ref>
<ref source="CONFIRM" url="http://pccs-linux.com/public/view.php3?bn=agora_pccslinux&amp;key=965951324">http://pccs-linux.com/public/view.php3?bn=agora_pccslinux&amp;key=965951324</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1557">1557</ref>
<ref source="XF">pccs-mysql-admin-tool</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0708" seq="2000-0708">
<status>Entry</status>
<desc>Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=NTBUGTRAQ&amp;P=R4247">20000824 Remote DoS Attack in Pragma TelnetServer 2000 (Remote Execute Daemon) Vulnerability</ref>
<ref source="CONFIRM" url="http://www.pragmasys.com/TelnetServer/">http://www.pragmasys.com/TelnetServer/</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1605">1605</ref>
<ref source="XF">telnetserver-rpc-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0711" seq="2000-0711">
<status>Entry</status>
<desc>Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=3999922128E.EE84TAKAGI@java-house.etl.go.jp">20000816 JDK 1.1.x Listening Socket Vulnerability (was Re: BrownOrifice can break firewalls!)</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000805020429.11774.qmail@securityfocus.com">20000805 Dangerous Java/Netscape Security Hole</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-15.html">CA-2000-15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1545">1545</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0712" seq="2000-0712">
<status>Entry</status>
<desc>Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the security=0 boot option.</desc>
<refs>
<ref source="MISC" url="http://www.egroups.com/message/lids/1038">http://www.egroups.com/message/lids/1038</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0486.html">2000803 LIDS severe bug</ref>
<ref source="CONFIRM" url="http://www.lids.org/changelog.html">http://www.lids.org/changelog.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1549">1549</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1495">1495</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0716" seq="2000-0716">
<status>Entry</status>
<desc>WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijcak the session ID and read the user's email.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=459">20000809 Session hijacking in Alt-N's MDaemon 2.8</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1553">1553</ref>
<ref source="XF" url="http://xforce.iss.net/static/5070.php">mdaemon-session-id-hijack</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0717" seq="2000-0717">
<status>Entry</status>
<desc>GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=02ff01c0124c$e9387660$0201a8c0@aviram">20000830 [EXPL] GoodTech's FTP Server vulnerable to a DoS (RNTO)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1619">1619</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5166">ftp-goodtech-rnto-dos(5166)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0718" seq="2000-0718">
<status>Entry</status>
<desc>A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0146.html">20000812 MDKSA-2000:034 MandrakeUpdate update</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1567">1567</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0720" seq="2000-0720">
<status>Entry</status>
<desc>news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=003301c0123b$18f8c1a0$953b29d4@e8s9s4">20000829 News Publisher CGI Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1621">1621</ref>
<ref source="XF" url="http://xforce.iss.net/static/5169.php">news-publisher-add-author(5169)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0725" seq="2000-0725">
<status>Entry</status>
<desc>Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.</desc>
<refs>
<ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert">http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-052.html">RHSA-2000:052</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000821">20000821 zope: unauthorized escalation of privilege (update)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0259.html">20000821 Conectiva Linux Security Announcement - Zope</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0198.html">20000816 MDKSA-2000:035 Zope update</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1577">1577</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0726" seq="2000-0726">
<status>Entry</status>
<desc>CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000829194618.H7744@thathost.com">20000829 Stalker's CGImail Gives Read Access to All Server Files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1623">1623</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5165">mailers-cgimail-spoof(5165)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0727" seq="2000-0727">
<status>Entry</status>
<desc>xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL's, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96766355023239&amp;w=2">20000829 MDKSA-2000:041 - xpdf update</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96886599829687&amp;w=2">20000913 Conectiva Linux Security Announcement - xpdf</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000910a">20000910 xpdf: local exploit</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-060.html">RHSA-2000:060</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt">CSSA-2000-031.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1624">1624</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0728" seq="2000-0728">
<status>Entry</status>
<desc>xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96766355023239&amp;w=2">20000829 MDKSA-2000:041 - xpdf update</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96886599829687&amp;w=2">20000913 Conectiva Linux Security Announcement - xpdf</ref>
<ref source="DEBIAN">20000910a</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-060.html">RHSA-2000:060</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt">CSSA-2000-031.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1624">1624</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0729" seq="2000-0729">
<status>Entry</status>
<desc>FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.</desc>
<refs>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0337.html">FreeBSD-SA-00:41</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1625">1625</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5967">freebsd-elf-dos(5967)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1534">1534</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0730" seq="2000-0730">
<status>Entry</status>
<desc>Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html">HPSBUX0008-118</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1580">1580</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0731" seq="2000-0731">
<status>Entry</status>
<desc>Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0111.html">20000825 DST2K0023: Directory Traversal Possible &amp; Denial of Service in Wo rm HTTP Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1626">1626</ref>
<ref source="XF" url="http://xforce.iss.net/static/5148.php">wormhttp-dir-traverse(5148)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1535">1535</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0732" seq="2000-0732">
<status>Entry</status>
<desc>Worm HTTP server allows remote attackers to cause a denial of service via a long URL.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0111.html">20000825 DST2K0023: Directory Traversal Possible &amp; Denial of Service in Wo rm HTTP Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1626">1626</ref>
<ref source="XF" url="http://xforce.iss.net/static/5149.php">wormhttp-filename-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0733" seq="2000-0733">
<status>Entry</status>
<desc>Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0154.html">20000814 [LSD] IRIX telnetd remote vulnerability</ref>
<ref source="SGI" url="ftp://sgigate.sgi.com/security/20000801-02-P">20000801-02-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1572">1572</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0737" seq="2000-0737">
<status>Entry</status>
<desc>The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the &quot;Service Control Manager Named Pipe Impersonation&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-053.asp">MS00-053</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1535">1535</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0738" seq="2000-0738">
<status>Entry</status>
<desc>WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0101.html">20000818 WebShield SMTP infinite loop DoS Attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1589">1589</ref>
<ref source="XF" url="http://xforce.iss.net/static/5100.php">webshield-smtp-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0739" seq="2000-0739">
<status>Entry</status>
<desc>Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html">20000802 NAI Net Tools PKI Server vulnerabilities</ref>
<ref source="CONFIRM" url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1537">1537</ref>
<ref source="XF" url="http://xforce.iss.net/static/5066.php">nettools-pki-dir-traverse(5066)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1489">1489</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0740" seq="2000-0740">
<status>Entry</status>
<desc>Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html">20000802 NAI Net Tools PKI Server vulnerabilities</ref>
<ref source="CONFIRM" url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1536">1536</ref>
<ref source="XF" url="http://xforce.iss.net/static/5026.php">nai-nettools-strong-bo(5026)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1488">1488</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0741" seq="2000-0741">
<status>Entry</status>
<desc>Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html">20000802 NAI Net Tools PKI Server vulnerabilities</ref>
<ref source="CONFIRM" url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1538">1538</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1490">1490</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0742" seq="2000-0742">
<status>Entry</status>
<desc>The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the &quot;Malformed IPX Ping Packet&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;mid=63120">20000602 ipx storm</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-054.asp">MS00-054</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1544">1544</ref>
<ref source="XF" url="http://xforce.iss.net/static/5079.php">win-ipx-ping-packet(5079)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0743" seq="2000-0743">
<status>Entry</status>
<desc>Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0112.html">20000810 Remote vulnerability in Gopherd 2.x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1569">1569</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0744" seq="2000-0744">
<status>Entry</status>
<desc>DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-2000-0743.</desc>
<refs>
</refs>
</item>

<item type="CVE" name="CVE-2000-0745" seq="2000-0745">
<status>Entry</status>
<desc>admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0243.html">20000821 Vuln. in all sites using PHP-Nuke, versions less than 3</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1592">1592</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1521">1521</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0747" seq="2000-0747">
<status>Entry</status>
<desc>The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0379.html">20000726 CONECTIVA LINUX SECURITY ANNOUNCEMENT - OPENLDAP</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5036">openldap-logrotate-script-dos(5036)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0749" seq="2000-0749">
<status>Entry</status>
<desc>Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.</desc>
<refs>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0338.html">FreeBSD-SA-00:42</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1628">1628</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5968">freebsd-linux-module-bo(5968)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1536">1536</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0750" seq="2000-0750">
<status>Entry</status>
<desc>Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0064.html">20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0336.html">FreeBSD-SA-00:40</ref>
<ref source="OPENBSD" url="http://www.openbsd.org/errata.html#mopd">20000705 Mopd contained a buffer overflow.</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-050.html">RHSA-2000:050</ref>
<ref source="MISC" url="http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h">http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1558">1558</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0751" seq="2000-0751">
<status>Entry</status>
<desc>mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0064.html">20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0336.html">FreeBSD-SA-00:40</ref>
<ref source="OPENBSD" url="http://www.openbsd.org/errata.html#mopd">20000705 Mopd contained a buffer overflow.</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-050.html">RHSA-2000:050</ref>
<ref source="MISC" url="http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h">http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1559">1559</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0753" seq="2000-0753">
<status>Entry</status>
<desc>The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/78240">20000824 Outlook winmail.dat</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201422">20010802 Outlook 2000 Rich Text information disclosure</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1631">1631</ref>
<ref source="XF" url="http://xforce.iss.net/static/5508.php">outlook-reveal-path(5508)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0754" seq="2000-0754">
<status>Entry</status>
<desc>Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html">HPSBUX0008-119</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1581">1581</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0758" seq="2000-0758">
<status>Entry</status>
<desc>The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0149.html">20000811 Lyris List Manager Administration Hole</ref>
<ref source="CONFIRM" url="http://www.lyris.com/lm/lm_updates.html">http://www.lyris.com/lm/lm_updates.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1584">1584</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0761" seq="2000-0761">
<status>Entry</status>
<desc>OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0166.html">20000815 OS/2 Warp 4.5 FTP Server DoS</ref>
<ref source="CONFIRM" url="ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/README">ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/README</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1582">1582</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0762" seq="2000-0762">
<status>Entry</status>
<desc>The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=004601c003a1$ba473260$ddeaa2cd@itradefair.net">20000811 eTrust Access Control - Root compromise for default install</ref>
<ref source="CONFIRM" url="http://support.ca.com/techbases/eTrust/etrust_access_control-response.html">http://support.ca.com/techbases/eTrust/etrust_access_control-response.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1583">1583</ref>
<ref source="XF" url="http://xforce.iss.net/static/5076.php">etrust-access-control-default</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1517">1517</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0763" seq="2000-0763">
<status>Entry</status>
<desc>xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privileges via the -d option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000815231724.A14694@subterrain.net">20000816 xlock vulnerability</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000816">20000816 xlockmore: possible shadow file compromise</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0340.html">FreeBSD-SA-00:44.xlockmore</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0212.html">20000817 Conectiva Linux Security Announcement - xlockmore</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0294.html">20000823 MDKSA-2000:038 - xlockmore update</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1585">1585</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0764" seq="2000-0764">
<status>Entry</status>
<desc>Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0338.html">20000828 Intel Express Switch 500 series DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1609">1609</ref>
<ref source="XF" url="http://xforce.iss.net/static/5154.php">intel-express-switch-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0765" seq="2000-0765">
<status>Entry</status>
<desc>Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the &quot;Microsoft Office HTML Object Tag&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-056.asp">MS00-056</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1561">1561</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0766" seq="2000-0766">
<status>Entry</status>
<desc>Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008270354.UAA10952@user4.hushmail.com">20000819 D.o.S Vulnerability in vqServer</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1610">1610</ref>
<ref source="XF" url="http://xforce.iss.net/static/5152.php">vqserver-get-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0767" seq="2000-0767">
<status>Entry</status>
<desc>The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the &quot;Scriptlet Rendering&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-055.asp">MS00-055</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1564">1564</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0768" seq="2000-0768">
<status>Entry</status>
<desc>A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the &quot;Frame Domain Verification&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-055.asp">MS00-055</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1564">1564</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0770" seq="2000-0770">
<status>Entry</status>
<desc>IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the &quot;File Permission Canonicalization&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-057.asp">MS00-057</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1565">1565</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0771" seq="2000-0771">
<status>Entry</status>
<desc>Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the &quot;Local Security Policy Corruption&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-062.asp">MS00-062</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1613">1613</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0773" seq="2000-0773">
<status>Entry</status>
<desc>Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a &quot;....&quot;, a variant of the dot dot directory traversal attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html">20000731 Two security flaws in Bajie Webserver</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1522">1522</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5021">bajie-view-arbitrary-files(5021)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0776" seq="2000-0776">
<status>Entry</status>
<desc>Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0118.html">20000810 [DeepZone Advisory] Statistics Server 5.02x stack overflow (Win2k remote exploit)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1568">1568</ref>
<ref source="XF" url="http://xforce.iss.net/static/5113.php">mediahouse-stats-livestats-bo(5113)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0777" seq="2000-0777">
<status>Entry</status>
<desc>The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the &quot;Money Password&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-061.asp">MS00-061</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1615">1615</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0778" seq="2000-0778">
<status>Entry</status>
<desc>IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a &quot;Translate: f&quot; header, aka the &quot;Specialized Header&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-058.asp">MS00-058</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=080D5336D882D211B56B0060080F2CD696A7C9@beta.mia.cz">20000815 Translate:f summary, history and thoughts</ref>
<ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5212">20000816 Translate: f</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1578">1578</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:927">oval:org.mitre.oval:def:927</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0779" seq="2000-0779">
<status>Entry</status>
<desc>Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.</desc>
<refs>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Improper_stderr">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Improper_stderr</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1534">1534</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1487">1487</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0780" seq="2000-0780">
<status>Entry</status>
<desc>The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96767207207553&amp;w=2">20000830 Vulnerability Report On IPSWITCH's IMail</ref>
<ref source="CONFIRM" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1617">1617</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0781" seq="2000-0781">
<status>Entry</status>
<desc>uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary file before it is moved.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0431.html">20000728 Client Agent 6.62 for Unix Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1519">1519</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5023">arcserveit-clientagent-temp-file(5023)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0782" seq="2000-0782">
<status>Entry</status>
<desc>netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NEBBJCLKGNOGCOIOBJNAGEHLCPAA.marc@eeye.com">20000817 Netauth: Web Based Email Management System</ref>
<ref source="CONFIRM" url="http://netwinsite.com/netauth/updates.htm">http://netwinsite.com/netauth/updates.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1587">1587</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5090">netwin-netauth-dir-traverse(5090)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0783" seq="2000-0783">
<status>Entry</status>
<desc>Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0162.html">20000815 Watchguard Firebox Authentication DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1573">1573</ref>
<ref source="XF" url="http://xforce.iss.net/static/5098.php">firebox-url-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0786" seq="2000-0786">
<status>Entry</status>
<desc>GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0389.html">20000726 userv security boundary tool 1.0.1 (SECURITY FIX)</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000727">20000727 userv: local exploit</ref>
<ref source="CONFIRM" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96473640717095&amp;w=2">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96473640717095&amp;w=2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1516">1516</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0787" seq="2000-0787">
<status>Entry</status>
<desc>IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0215.html"> 20000817 XChat URL handler vulnerabilty</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1601">1601</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-055.html">RHSA-2000:055</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0301.html">20000824 MDKSA-2000:039 - xchat update</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0305.html">20000825 Conectiva Linux Security Announcement - xchat</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0788" seq="2000-0788">
<status>Entry</status>
<desc>The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=398EB9CA.27E03A9C@nat.bg">20000807 MS Word and MS Access vulnerability - executing arbitrary programs, may be exploited by IE/Outlook</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-071.asp">MS00-071</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1566">1566</ref>
<ref source="XF" url="http://xforce.iss.net/static/5322.php">word-mail-merge(5322)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0790" seq="2000-0790">
<status>Entry</status>
<desc>The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=3998370D.732A03F1@nat.bg">20000828 IE 5.5/5.x for Win98 may execute arbitrary files that can be accessed thru Microsoft Networking. Also local Administrator compromise at least on default Windows 2000.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1571">1571</ref>
<ref source="XF" url="http://xforce.iss.net/static/5097.php">ie-folder-remote-exe(5097)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0792" seq="2000-0792">
<status>Entry</status>
<desc>Gnome Lokkit firewall package before 0.41 does not properly restrict access to some ports, even if a user does not make any services available.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0252.html">20000819 Security update for Gnome-Lokkit</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1590">1590</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1520">1520</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0795" seq="2000-0795">
<status>Entry</status>
<desc>Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">20000802 [LSD] some unpublished LSD exploit codes</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1529">1529</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1485">1485</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0796" seq="2000-0796">
<status>Entry</status>
<desc>Buffer overflow in dmplay in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long command line option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">20000802 [LSD] some unpublished LSD exploit codes</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1528">1528</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1484">1484</ref>
<ref source="XF" url="http://xforce.iss.net/static/5064.php">irix-dmplay-bo(5064)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0797" seq="2000-0797">
<status>Entry</status>
<desc>Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">20000802 [LSD] some unpublished LSD exploit codes</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040104-01-P.asc">20040104-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1526">1526</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5062">irix-grosview-bo(5062)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3815">3815</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0799" seq="2000-0799">
<status>Entry</status>
<desc>inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a symlink attack on the .ilmpAAA temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">20000802 [LSD] some unpublished LSD exploit codes</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I">20001101-01-I</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1530">1530</ref>
<ref source="XF" url="http://xforce.iss.net/static/5065.php">irix-inpview-symlink(5065)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0803" seq="2000-0803">
<status>Entry</status>
<desc>GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.</desc>
<refs>
<ref source="ISS">20001004 GNU Groff utilities read untrusted commands from current working directory</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5280">gnu-groff-utilities(5280)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0804" seq="2000-0804">
<status>Entry</status>
<desc>Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka &quot;One-way Connection Enforcement Bypass.&quot;</desc>
<refs>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-way_Connection">http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-way_Connection</ref>
<ref source="XF" url="http://xforce.iss.net/static/5468.php">fw1-remote-bypass</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4419">4419</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0805" seq="2000-0805">
<status>Entry</status>
<desc>Check Point VPN-1/FireWall-1 4.1 and earlier improperly retransmits encapsulated FWS packets, even if they do not come from a valid FWZ client, aka &quot;Retransmission of Encapsulated Packets.&quot;</desc>
<refs>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Retransmission_of">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Retransmission_of</ref>
<ref source="XF" url="http://xforce.iss.net/static/5469.php">fw1-client-spoof</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4415">4415</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0806" seq="2000-0806">
<status>Entry</status>
<desc>The inter-module authentication mechanism (fwa1) in Check Point VPN-1/FireWall-1 4.1 and earlier may allow remote attackers to conduct a denial of service, aka &quot;Inter-module Communications Bypass.&quot;</desc>
<refs>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Inter-module_Communications">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Inter-module_Communications</ref>
<ref source="XF" url="http://xforce.iss.net/static/5162.php">fw1-fwa1-auth-replay</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4413">4413</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0807" seq="2000-0807">
<status>Entry</status>
<desc>The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the &quot;OPSEC Authentication Vulnerability.&quot;</desc>
<refs>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#OPSEC_Authentication">http://www.checkpoint.com/techsupport/alerts/list_vun.html#OPSEC_Authentication</ref>
<ref source="XF" url="http://xforce.iss.net/static/5471.php">fw1-opsec-auth-spoof</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4420">4420</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0808" seq="2000-0808">
<status>Entry</status>
<desc>The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication via a brute force attack, aka &quot;One-time (s/key) Password Authentication.&quot;</desc>
<refs>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-time_Password">http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-time_Password</ref>
<ref source="XF" url="http://xforce.iss.net/static/5137.php">fw1-localhost-auth</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4421">4421</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0809" seq="2000-0809">
<status>Entry</status>
<desc>Buffer overflow in Getkey in the protocol checker in the inter-module communication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to cause a denial of service.</desc>
<refs>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Getkey_Buffer">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Getkey_Buffer</ref>
<ref source="XF" url="http://xforce.iss.net/static/5139.php">fw1-getkey-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4422">4422</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0810" seq="2000-0810">
<status>Entry</status>
<desc>Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">20001016 File deletion and other bugs in Auction Weaver LITE 1.0 - 1.04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1782">1782</ref>
<ref source="XF" url="http://xforce.iss.net/static/5371.php">auction-weaver-delete-files</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1600">1600</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0811" seq="2000-0811">
<status>Entry</status>
<desc>Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.</desc>
<refs>
<ref source="BUGTRAQ">20001016 File deletion and other bugs in Auction Weaver LITE 1.0 - 1.04</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1783">1783</ref>
<ref source="XF" url="http://xforce.iss.net/static/5372.php">auction-weaver-username-bidfile</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4053">4053</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0813" seq="2000-0813">
<status>Entry</status>
<desc>Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to redirect FTP connections to other servers (&quot;FTP Bounce&quot;) via invalid FTP commands that are processed improperly by FireWall-1, aka &quot;FTP Connection Enforcement Bypass.&quot;</desc>
<refs>
<ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#FTP_Connection">http://www.checkpoint.com/techsupport/alerts/list_vun.html#FTP_Connection</ref>
<ref source="XF" url="http://xforce.iss.net/static/5474.php">fw1-ftp-redirect</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4434">4434</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0816" seq="2000-0816">
<status>Entry</status>
<desc>Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise64.php">20001006 Insecure call of external programs in Red Hat Linux tmpwatch</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-080.html">RHSA-2000:080</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-056.php3?dis=7.1">MDKSA-2000:056</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1785">1785</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5320">linux-tmpwatch-fuser(5320)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0818" seq="2000-0818">
<status>Entry</status>
<desc>The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise66.php">20001025 Vulnerability in the Oracle Listener Program</ref>
<ref source="CONFIRM" url="http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf">http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5380">oracle-listener-connect-statements(5380)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0824" seq="2000-0824">
<status>Entry</status>
<desc>The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93760201002154&amp;w=2">19990917 A few bugs...</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/79537">20000831 glibc unsetenv bug</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-028.0.txt">CSSA-2000-028.0</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000902">20000902 glibc: local root exploit</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-040.php3">MDKSA-2000:040</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-045.php3">MDKSA-2000:045</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-057.html">RHSA-2000:057</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000020.html">TLSA2000020-1</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html">20000924 glibc locale security problem</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html">20000902 Conectiva Linux Security Announcement - glibc</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0509.html">20000905 Conectiva Linux Security Announcement - glibc</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0525.html">20000906 [slackware-security]: glibc 2.1.3 vulnerabilities patched</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/648">648</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1639">1639</ref>
<ref source="XF" url="http://xforce.iss.net/static/5173.php">glibc-ld-unsetenv</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0825" seq="2000-0825">
<status>Entry</status>
<desc>Ipswitch Imail 6.0 allows remote attackers to cause a denial of service via a large number of connections in which a long Host: header is sent, which causes a thread to crash.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96659012127444&amp;w=2">20000817 Imail Web Service Remote DoS Attack v.2</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=96654521004571&amp;w=2">20000817 Imail Web Service Remote DoS Attack v.2</ref>
<ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0071.html">20000817 Imail Web Service Remote DoS Attack v.2</ref>
<ref source="XF" url="http://xforce.iss.net/static/5475.php">ipswitch-imail-remote-dos(5475)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2011">2011</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0829" seq="2000-0829">
<status>Entry</status>
<desc>The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/81364">20000909 tmpwatch: local DoS : fork()bomb as root</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-080.html">RHSA-2000:080</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1664">1664</ref>
<ref source="XF" url="http://xforce.iss.net/static/5217.php">linux-tmpwatch-fork-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0830" seq="2000-0830">
<status>Entry</status>
<desc>annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/81852">20000913 trivial DoS in webTV</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-074.asp">MS00-074</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1671">1671</ref>
<ref source="XF" url="http://xforce.iss.net/static/5216.php">webtv-udp-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0834" seq="2000-0834">
<status>Entry</status>
<desc>The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the &quot;Windows 2000 Telnet Client NTLM Authentication&quot; vulnerability.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a091400-1.txt">A091400-1</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-067.asp">MS00-067</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1683">1683</ref>
<ref source="XF" url="http://xforce.iss.net/static/5242.php">win2k-telnet-ntlm-authentication</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0837" seq="2000-0837">
<status>Entry</status>
<desc>FTP Serv-U 2.5e allows remote attackers to cause a denial of service by sending a large number of null bytes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/73843">20000804 FTP Serv-U 2.5e vulnerability.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1543">1543</ref>
<ref source="XF" url="http://xforce.iss.net/static/5029.php">servu-null-character-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0838" seq="2000-0838">
<status>Entry</status>
<desc>Fastream FUR HTTP server 1.0b allows remote attackers to cause a denial of service via a long GET request.</desc>
<refs>
<ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0111.html">20000914 DST2K0028: DoS in FUR HTTP Server v1.0b</ref>
<ref source="XF" url="http://xforce.iss.net/static/5237.php">fur-get-dos(5237)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0839" seq="2000-0839">
<status>Entry</status>
<desc>WinCOM LPD 1.00.90 allows remote attackers to cause a denial of service via a large number of LPD options to the LPD port (515).</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0212.html">20000919 VIGILANTE-2000013: WinCOM LPD DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1701">1701</ref>
<ref source="XF" url="http://xforce.iss.net/static/5258.php">wincom-lpd-dos(5258)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0844" seq="2000-0844">
<status>Entry</status>
<desc>Some functions that implement the locale subsystem on Unix do not  properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0457.html">20000904 UNIX locale format string vulnerability</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000902">20000902 glibc: local root exploit</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-030.0.txt">CSSA-2000-030.0</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-057.html">RHSA-2000:057</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html">20000906 glibc locale security problem</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000020.html">TLSA2000020-1</ref>
<ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0427.html">IY13753</ref>
<ref source="COMPAQ" url="http://archives.neohapsis.com/archives/tru64/2000-q4/0000.html">SSRT0689U</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P">20000901-01-P</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html">20000902 Conectiva Linux Security Announcement - glibc</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1634">1634</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5176">unix-locale-format-string(5176)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0846" seq="2000-0846">
<status>Entry</status>
<desc>Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0256.html">20000821 Darxite daemon remote exploit/DoS problem</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1598">1598</ref>
<ref source="XF" url="http://xforce.iss.net/static/5134.php">darxite-login-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0847" seq="2000-0847">
<status>Entry</status>
<desc>Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0425.html">20000901 UW c-client library vulnerability</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0437.html">20000901 More about UW c-client library</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0108.html">FreeBSD-SA-00:47.pine</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1646">1646</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1687">1687</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5223">c-client-dos(5223)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0848" seq="2000-0848">
<status>Entry</status>
<desc>Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host:  request header.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0192.html">20000915 WebSphere application server plugin issue &amp; vendor fix</ref>
<ref source="MISC" url="http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security">http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1691">1691</ref>
<ref source="XF" url="http://xforce.iss.net/static/5252.php">websphere-header-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0849" seq="2000-0849">
<status>Entry</status>
<desc>Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the &quot;Unicast Service Race Condition&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-064.asp">MS00-064</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1655">1655</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5193">unicast-service-dos(5193)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0850" seq="2000-0850">
<status>Entry</status>
<desc>Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending &quot;$/FILENAME.ext&quot; (where ext is .ccc, .class, or .jpg) to the requested URL.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a091100-1.txt">A091100-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1681">1681</ref>
<ref source="XF" url="http://xforce.iss.net/static/5230.php">siteminder-bypass-authentication</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0851" seq="2000-0851">
<status>Entry</status>
<desc>Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the &quot;Still Image Service Privilege Escalation&quot; vulnerability.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090700-1.txt">A090700-1</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-065.asp">MS00-065</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1651">1651</ref>
<ref source="XF" url="http://xforce.iss.net/static/5203.php">w2k-still-image-service</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0852" seq="2000-0852">
<status>Entry</status>
<desc>Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges.</desc>
<refs>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0110.html">FreeBSD-SA-00:49</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1686">1686</ref>
<ref source="XF" url="http://xforce.iss.net/static/5248.php">freebsd-eject-port</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1559">1559</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0853" seq="2000-0853">
<status>Entry</status>
<desc>YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0072.html">20000909 YaBB 1.9.2000 Vulnerabilitie</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1668">1668</ref>
<ref source="XF" url="http://xforce.iss.net/static/5254.php">yabb-file-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0854" seq="2000-0854">
<status>Entry</status>
<desc>When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.</desc>
<refs>
<ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0117.html">20000918 Double clicking on MS Office documents from Windows Explorer may execute arbitrary programs in some cases</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0277.html">20000922 Eudora + riched20.dll affects WinZip v8.0 as well</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1699">1699</ref>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0155.html">20000921 Mitigators for possible exploit of Eudora via Guninski #21,2000</ref>
<ref source="XF" url="http://xforce.iss.net/static/5263.php">office-dll-execution(5263)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0856" seq="2000-0856">
<status>Entry</status>
<desc>Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0408.html">20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1638">1638</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0858" seq="2000-0858">
<status>Entry</status>
<desc>Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the &quot;Invalid URL&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/80413">20000906 VIGILANTE-2000009: &quot;Invalid URL&quot; DoS</ref>
<ref source="MS" url="http://archives.neohapsis.com/archives/vendor/2000-q3/0065.html">MS00-063</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1642">1642</ref>
<ref source="XF" url="http://xforce.iss.net/static/5202.php">iis-invald-url-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0859" seq="2000-0859">
<status>Entry</status>
<desc>The web configuration server for NTMail V5 and V6 allows remote attackers to cause a denial of service via a series of partial HTTP requests.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0471.html">20000904 VIGILANTE-2000008: NTMail Configuration Service DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1640">1640</ref>
<ref source="XF" url="http://xforce.iss.net/static/5182.php">ntmail-incomplete-http-requests</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0860" seq="2000-0860">
<status>Entry</status>
<desc>The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0455.html">20000903 (SRADV00001) Arbitrary file disclosure through PHP file upload</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0477.html">20000904 Re: [PHP-DEV] RE: (SRADV00001) Arbitrary file disclosure through PHP file upload</ref>
<ref source="CONFIRM" url="http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&amp;tr1=1.1&amp;r2=text&amp;tr2=1.45&amp;diff_format=u">http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&amp;tr1=1.1&amp;r2=text&amp;tr2=1.45&amp;diff_format=u</ref>
<ref source="MANDRAKE" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0150.html">MDKSA-2000:048</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1649">1649</ref>
<ref source="XF" url="http://xforce.iss.net/static/5190.php">php-file-upload</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0861" seq="2000-0861">
<status>Entry</status>
<desc>Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0040.html">20000907 Mailman 1.1 + external archiver vulnerability</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0112.html">FreeBSD-SA-00:51</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1667">1667</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5493">mailman-execute-external-commands(5493)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0862" seq="2000-0862">
<status>Entry</status>
<desc>Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.</desc>
<refs>
<ref source="ALLAIRE" url="http://archives.neohapsis.com/archives/vendor/2000-q3/0059.html">ASB00-23</ref>
<ref source="XF" url="http://xforce.iss.net/static/5466.php">allaire-spectra-admin-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0863" seq="2000-0863">
<status>Entry</status>
<desc>Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges.</desc>
<refs>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0111.html">FreeBSD-SA-00:50</ref>
<ref source="XF" url="http://xforce.iss.net/static/5503.php">listmanager-port-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0864" seq="2000-0864">
<status>Entry</status>
<desc>Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a  symlink attack.</desc>
<refs>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0365.html">FreeBSD-SA-00:45</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0095.html">20000911 Patch for esound-0.2.19</ref>
<ref source="MANDRAKE" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0328.htm">MDKSA-2000:051</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-077.html">RHSA-2000:077</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001008">20001008 esound: race condition</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0118.html">20001006 Immunix OS Security Update for esound</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/esound_daemon_race_condition.html">20001012 esound daemon race condition</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1659">1659</ref>
<ref source="XF" url="http://xforce.iss.net/static/5213.php">gnome-esound-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0865" seq="2000-0865">
<status>Entry</status>
<desc>Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0185.html">20000916 Advisory: Tridia DoubleVision / SCO UnixWare</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1697">1697</ref>
<ref source="XF" url="http://xforce.iss.net/static/5261.php">doublevision-dvtermtype-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0867" seq="2000-0867">
<status>Entry</status>
<desc>Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0193.html">20000917 klogd format bug</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-061.html">RHSA-2000:061</ref>
<ref source="DEBIAN">20000919</ref>
<ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:050">MDKSA-2000:050</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-032.0.txt">CSSA-2000-032.0</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000023.html">TLSA2000022-2</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv9_draht_syslogd_txt.html">20000920 syslogd + klogd format string parsing error</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97726239017741&amp;w=2">20000918 Conectiva Linux Security Announcement - sysklogd</ref>
<ref source="XF" url="http://xforce.iss.net/static/5259.php">klogd-format-string</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5824">5824</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0868" seq="2000-0868">
<status>Entry</status>
<desc>The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090700-2.txt">A090700-2</ref>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html">20000907</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1658">1658</ref>
<ref source="XF" url="http://xforce.iss.net/static/5197.php">suse-apache-cgi-source-code</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0869" seq="2000-0869">
<status>Entry</status>
<desc>The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090700-3.txt">A090700-3</ref>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html">20000907</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1656">1656</ref>
<ref source="XF" url="http://xforce.iss.net/static/5204.php">apache-webdav-directory-listings</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0870" seq="2000-0870">
<status>Entry</status>
<desc>Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0089.html">20000911[EXPL] EFTP vulnerable to two DoS attacks</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1675">1675</ref>
<ref source="XF" url="http://xforce.iss.net/static/5219.php">eftp-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1555">1555</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0871" seq="2000-0871">
<status>Entry</status>
<desc>Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0089.html">20000911[EXPL] EFTP vulnerable to two DoS attacks</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1677">1677</ref>
<ref source="XF" url="http://xforce.iss.net/static/5220.php">eftp-newline-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/409">409</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0873" seq="2000-0873">
<status>Entry</status>
<desc>netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0454.html">20000903 aix allows clearing the interface stats</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1660">1660</ref>
<ref source="XF" url="http://xforce.iss.net/static/5214.php">aix-clear-netstat</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0874" seq="2000-0874">
<status>Entry</status>
<desc>Eudora mail client includes the absolute path of the sender's host within a virtual card (VCF).</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/80888">20000907 Eudora disclosure</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1653">1653</ref>
<ref source="XF" url="http://xforce.iss.net/static/5206.php">eudora-path-disclosure</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1545">1545</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0875" seq="2000-0875">
<status>Entry</status>
<desc>WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.html">20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities</ref>
<ref source="CONFIRM" url="http://www.wftpd.com/bug_gpf.htm">http://www.wftpd.com/bug_gpf.htm</ref>
<ref source="XF" url="http://xforce.iss.net/static/5194.php">wftpd-long-string-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0876" seq="2000-0876">
<status>Entry</status>
<desc>WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the  full pathname of the server via a &quot;%C&quot; command, which generates an error message that includes the pathname.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.html">20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities</ref>
<ref source="XF" url="http://xforce.iss.net/static/5196.php">wftpd-path-disclosure</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5829">5829</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0877" seq="2000-0877">
<status>Entry</status>
<desc>mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0092.html">20000911 Unsafe passing of variables to mailform.pl in MailForm V2.0</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1670">1670</ref>
<ref source="XF" url="http://xforce.iss.net/static/5224.php">mailform-attach-file</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0878" seq="2000-0878">
<status>Entry</status>
<desc>The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0088.html">20000911 Fwd: Poor variable checking in mailto.cgi</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1669">1669</ref>
<ref source="XF" url="http://xforce.iss.net/static/5241.php">mailto-piped-address</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0883" seq="2000-0883">
<status>Entry</status>
<desc>The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.</desc>
<refs>
<ref source="MANDRAKE" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0111.html">MDKSA-2000:046</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1678">1678</ref>
<ref source="XF" url="http://xforce.iss.net/static/5257.php">linux-mod-perl</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0884" seq="2000-0884">
<status>Entry</status>
<desc>IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the &quot;Web Server Folder Traversal&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ">20001017 IIS %c1%1c remote command execution</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-078.asp">MS00-078</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1806">1806</ref>
<ref source="XF" url="http://xforce.iss.net/static/5377.php">iis-unicode-translation</ref>
<ref source="OSVDB" url="http://www.osvdb.org/436">436</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:44">oval:org.mitre.oval:def:44</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0886" seq="2000-0886">
<status>Entry</status>
<desc>IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the &quot;Web Server File Request Parsing&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?mid=143604&amp;list=1&amp;fromthread=0&amp;end=2000-11-11&amp;threads=0&amp;start=2000-11-05&amp;">20001107 NSFOCUS SA2000-07 : Microsoft IIS 4.0/5.0 CGI File Name Inspection Vulnerability</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-086.asp">MS00-086</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1912">1912</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5470">iis-invalid-filename-passing(5470)</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:191">oval:org.mitre.oval:def:191</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0887" seq="2000-0887">
<status>Entry</status>
<desc>named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the &quot;zxfr bug.&quot;</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/143843">20001107 BIND 8.2.2-P5 Possible DOS</ref>
<ref source="VULN-DEV">20001107 Possible DOS in Bind 8.2.2-P5</ref>
<ref source="VULN-DEV">20001109 Re: Possible DOS in Bind 8.2.2-P5</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-20.html">CA-2000-20</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-107.html">RHSA-2000:107</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001112">20001112 bind: remote Denial of Service</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0217.html">20001115 Trustix Security Advisory - bind and openssh (and modutils)</ref>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0657.html">SuSE-SA:2000:45</ref>
<ref source="IBM">ERS-SVA-E01-2000:005.1</ref>
<ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:067">MDKSA-2000:067</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000338">CLSA-2000:338</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000339">CLSA-2000:339</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1923">1923</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5540">bind-zxfr-dos(5540)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0888" seq="2000-0888">
<status>Entry</status>
<desc>named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the &quot;srv bug.&quot;</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-20.html">CA-2000-20</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-107.html">RHSA-2000:107</ref>
<ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:067">MDKSA-2000:067</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000338">CLSA-2000:338</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000339">CLSA-2000:339</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001112">20001112 bind: remote Denial of Service</ref>
<ref source="IBM">ERS-SVA-E01-2000:005.1</ref>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0657.html">SuSE-SA:2000:45</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5814">bind-srv-dos(5814)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0890" seq="2000-0890">
<status>Entry</status>
<desc>periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/626919">VU#626919</ref>
<ref source="FREEBSD">FreeBSD-SA-01:12</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6047">periodic-temp-file-symlink(6047)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2325">2325</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1754">1754</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0891" seq="2000-0891">
<status>Entry</status>
<desc>A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email.</desc>
<refs>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/5962">VU#5962</ref>
<ref source="CONFIRM" url="http://www.notes.net/R5FixList.nsf/Search!SearchView&amp;Query=CBAT45TU9S">http://www.notes.net/R5FixList.nsf/Search!SearchView&amp;Query=CBAT45TU9S</ref>
<ref source="XF" url="http://xforce.iss.net/static/5045.php">lotus-notes-bypass-ecl(5045)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0892" seq="2000-0892">
<status>Entry</status>
<desc>Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.</desc>
<refs>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/22404">VU#22404</ref>
<ref source="XF" url="http://xforce.iss.net/static/6644.php">telnet-obtain-env-variable(6644)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0894" seq="2000-0894">
<status>Entry</status>
<desc>HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise70.php">20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5554">watchguard-soho-web-auth(5554)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2119">2119</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4404">4404</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0895" seq="2000-0895">
<status>Entry</status>
<desc>Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise70.php">20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2114">2114</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5218">watchguard-soho-web-dos(5218)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4403">4403</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0896" seq="2000-0896">
<status>Entry</status>
<desc>WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise70.php">20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref>
<ref source="XF" url="http://xforce.iss.net/static/5749.php">watchguard-soho-fragmented-packets</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2113">2113</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1690">1690</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0897" seq="2000-0897">
<status>Entry</status>
<desc>Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97421834001092&amp;w=2">20001114 Vulnerabilites in SmallHTTP Server</ref>
<ref source="CONFIRM" url="http://home.lanck.net/mf/srv/index.htm">http://home.lanck.net/mf/srv/index.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1941">1941</ref>
<ref source="XF" url="http://xforce.iss.net/static/5524.php">small-http-nofile-dos(5524)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0900" seq="2000-0900">
<status>Entry</status>
<desc>Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a &quot;%2e%2e&quot; string, a variation of the .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0025.html">20001002 thttpd ssi: retrieval of arbitrary world-readable files</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:73.thttpd.asc">FreeBSD-SA-00:73</ref>
<ref source="XF" url="http://xforce.iss.net/static/5313.php">acme-thttpd-ssi</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1737">1737</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0901" seq="2000-0901">
<status>Entry</status>
<desc>Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0530.html">20000906 Screen-3.7.6 local compromise</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/80178">20000905 screen 3.9.5 root vulnerability</ref>
<ref source="DEBIAN">20000902a</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-044.php3">MDKSA-2000:044</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv6_draht_screen_txt.html">20000906 screen format string parsing security problem</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-058.html">RHSA-2000:058</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:46.screen.asc">FreeBSD-SA-00:46</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1641">1641</ref>
<ref source="XF" url="http://xforce.iss.net/static/5188.php">screen-format-string</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0908" seq="2000-0908">
<status>Entry</status>
<desc>BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME headers in the HTTP request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96956211605302&amp;w=2">20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H)</ref>
<ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0128.html">20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H)</ref>
<ref source="CONFIRM" url="http://www.netcplus.com/browsegate.htm#BGLatest">http://www.netcplus.com/browsegate.htm#BGLatest</ref>
<ref source="XF" url="http://xforce.iss.net/static/5270.php">browsegate-http-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1702">1702</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0909" seq="2000-0909">
<status>Entry</status>
<desc>Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/84901">20000922  [ no subject ]</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0441.html">20001031 FW: Pine 4.30 now available</ref>
<ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:59.pine.asc">FreeBSD-SA-00:59</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-102.html">RHSA-2000:102</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-073.php3">MDKSA-2000:073</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1709">1709</ref>
<ref source="XF" url="http://xforce.iss.net/static/5283.php">pine-check-mail-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0910" seq="2000-0910">
<status>Entry</status>
<desc>Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the &quot;from&quot; address.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0051.html">20000908 horde library bug - unchecked from-address</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20000910">20000910 imp: remote compromise</ref>
<ref source="CONFIRM" url="http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch">http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1674">1674</ref>
<ref source="XF" url="http://xforce.iss.net/static/5278.php">horde-imp-sendmail-command</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0911" seq="2000-0911">
<status>Entry</status>
<desc>IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/82088">20000912  (SRADV00003) Arbitrary file disclosure through IMP </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1679">1679</ref>
<ref source="XF" url="http://xforce.iss.net/static/5227.php">imp-attach-file</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0912" seq="2000-0912">
<status>Entry</status>
<desc>MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the &quot;multi&quot; parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0146.html">20000913 MultiHTML vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/5285.php">http-cgi-multihtml</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0913" seq="2000-0913">
<status>Entry</status>
<desc>mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0352.html">20000929 Security vulnerability in Apache mod_rewrite</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-060-2.php3?dis=7.1">MDKSA-2000:060</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-088.html">RHSA-2000:088</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-095.html">RHSA-2000:095</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-035.0.txt">CSSA-2000-035.0</ref>
<ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0021.html">HPSBUX0010-126</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0174.html">20001011 Conectiva Linux Security Announcement - apache</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1728">1728</ref>
<ref source="XF" url="http://xforce.iss.net/static/5310.php">apache-rewrite-view-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0914" seq="2000-0914">
<status>Entry</status>
<desc>OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0078.html">20001005 obsd_fun.c</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1759">1759</ref>
<ref source="XF" url="http://xforce.iss.net/static/5340.php">bsd-arp-request-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1592">1592</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0915" seq="2000-0915">
<status>Entry</status>
<desc>fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0017.html">20001002 [sa2c@and.or.jp: bin/21704: enabling fingerd makes files world readable]</ref>
<ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:54.fingerd.asc">FreeBSD-SA-00:54</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1803">1803</ref>
<ref source="XF" url="http://xforce.iss.net/static/5385.php">freebsd-fingerd-files</ref>
<ref source="OSVDB" url="http://www.osvdb.org/433">433</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0917" seq="2000-0917">
<status>Entry</status>
<desc>Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0293.html">20000925 Format strings: bug #2: LPRng</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2000-22.html">CA-2000-22</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-033.0.txt">CSSA-2000-033.0</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-065.html">RHSA-2000:065</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:56.lprng.asc">FreeBSD-SA-00:56</ref>
<ref source="XF" url="http://xforce.iss.net/static/5287.php">lprng-format-string</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1712">1712</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0919" seq="2000-0919">
<status>Entry</status>
<desc>Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0117.html">20001007 PHPix advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1773">1773</ref>
<ref source="XF" url="http://xforce.iss.net/static/5331.php">phpix-dir-traversal</ref>
<ref source="OSVDB" url="http://www.osvdb.org/472">472</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0920" seq="2000-0920">
<status>Entry</status>
<desc>Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a &quot;%2E&quot; instead of a &quot;.&quot;</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0092.html">20001006 Vulnerability in BOA web server v0.94.8.2</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:60.boa.asc">FreeBSD-SA-00:60</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001009">20001009 boa: exposes contents of local files</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1770">1770</ref>
<ref source="XF" url="http://xforce.iss.net/static/5330.php">boa-webserver-get-dir-traversal</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0921" seq="2000-0921">
<status>Entry</status>
<desc>Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0115.html">20001007 Security Advisory: Hassan Consulting's shop.cgi Directory Traversal Vulnerability.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1777">1777</ref>
<ref source="XF" url="http://xforce.iss.net/static/5342.php">hassan-shopping-cart-dir-traversal</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1596">1596</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0922" seq="2000-0922">
<status>Entry</status>
<desc>Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0120.html">20001008 Security Advisory: Bytes Interactive's Web Shopper (shopper.cgi) Directory Traversal Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1776">1776</ref>
<ref source="XF" url="http://xforce.iss.net/static/5351.php">web-shopper-directory-traversal</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0923" seq="2000-0923">
<status>Entry</status>
<desc>authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0107.html">20001006 Fwd: APlio PRO web shell</ref>
<ref source="XF" url="http://xforce.iss.net/static/5333.php">uclinux-apliophone-bin-execute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1784">1784</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0924" seq="2000-0924">
<status>Entry</status>
<desc>Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the &quot;catigory&quot; parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0141.html">20001009 Master Index traverse advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1772">1772</ref>
<ref source="XF" url="http://xforce.iss.net/static/5355.php">master-index-directory-traversal</ref>
<ref source="OSVDB" url="http://www.osvdb.org/461">461</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0925" seq="2000-0925">
<status>Entry</status>
<desc>The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97050819812055&amp;w=2">20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2</ref>
<ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0001.html">20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1734">1734</ref>
<ref source="XF" url="http://xforce.iss.net/static/5318.php">cyberoffice-world-readable-directory</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0926" seq="2000-0926">
<status>Entry</status>
<desc>SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the &quot;Price&quot; hidden form variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97050627707128&amp;w=2">20001002 DST2K0036: Price modification possible in CyberOffice Shopping Cart</ref>
<ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0000.html">20001002 DST2K0036: Price modification possible in CyberOffice Shopping Ca rt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1733">1733</ref>
<ref source="XF" url="http://xforce.iss.net/static/5319.php">cyberoffice-price-modification</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0927" seq="2000-0927">
<status>Entry</status>
<desc>WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0173.html">20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas.</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09//0331.html">20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1724">1724</ref>
<ref source="XF" url="http://xforce.iss.net/static/5302.php">quotaadvisor-quota-bypass</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0928" seq="2000-0928">
<status>Entry</status>
<desc>WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0091.html">20001006 DST2K0040: QuotaAdvisor 4.1 by WQuinn susceptible to any user bei ng able to list (not read) all files on any server running QuotaAdvisor.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1765">1765</ref>
<ref source="XF" url="http://xforce.iss.net/static/5327.php">quotaadvisor-list-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0929" seq="2000-0929">
<status>Entry</status>
<desc>Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the &quot;OCX Attachment&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97024839222747&amp;w=2">20000929 Malformed Embedded Windows Media Player 7 &quot;OCX Attachment&quot;</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-068.asp">MS00-068</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1714">1714</ref>
<ref source="XF" url="http://xforce.iss.net/static/5309.php">mediaplayer-outlook-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0930" seq="2000-0930">
<status>Entry</status>
<desc>Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0039.html">20001003 Pegasus mail file reading vulnerability</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0436.html">20001030 Pegasus Mail file reading vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1738">1738</ref>
<ref source="XF" url="http://xforce.iss.net/static/5326.php">pegasus-file-forwarding</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0932" seq="2000-0932">
<status>Entry</status>
<desc>MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0181.html">20000926 FW: DOS for Content Technologies' MAILsweeper for SMTP.</ref>
<ref source="XF" url="http://xforce.iss.net/static/5641.php">mailsweeper-smtp-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0933" seq="2000-0933">
<status>Entry</status>
<desc>The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the &quot;Simplified Chinese IME State Recognition&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-069.asp">MS00-069</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1729">1729</ref>
<ref source="XF" url="http://xforce.iss.net/static/5301.php">win2k-simplified-chinese-ime</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0934" seq="2000-0934">
<status>Entry</status>
<desc>Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-062.html">RHSA-2000:062</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1703">1703</ref>
<ref source="XF" url="http://xforce.iss.net/static/5271.php">glint-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0935" seq="2000-0935">
<status>Entry</status>
<desc>Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1872">1872</ref>
<ref source="XF" url="http://xforce.iss.net/static/5443.php">samba-swat-logging-sym-link</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0936" seq="2000-0936">
<status>Entry</status>
<desc>Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1874">1874</ref>
<ref source="XF" url="http://xforce.iss.net/static/5445.php">samba-swat-logfile-info</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0937" seq="2000-0937">
<status>Entry</status>
<desc>Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1873">1873</ref>
<ref source="XF" url="http://xforce.iss.net/static/5442.php">samba-swat-brute-force</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0938" seq="2000-0938">
<status>Entry</status>
<desc>Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html">20001030 Samba 2.0.7 SWAT vulnerabilities</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5442">samba-swat-brute-force(5442)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0941" seq="2000-0941">
<status>Entry</status>
<desc>Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the &quot;whois&quot; parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html">20001029 Remote command execution via KW Whois 1.0</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0420.html">20001029 Re: Remote command execution via KW Whois 1.0 (addition)</ref>
<ref source="MISC" url="http://www.kootenayweb.bc.ca/scripts/whois.txt">http://www.kootenayweb.bc.ca/scripts/whois.txt</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1883">1883</ref>
<ref source="XF" url="http://xforce.iss.net/static/5438.php">kw-whois-meta</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0942" seq="2000-0942">
<status>Entry</status>
<desc>The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the &quot;Indexing Services Cross Site Scripting&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141903">20001028 IIS 5.0 cross site scripting vulnerability - using .htw</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-084.asp">MS00-084</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1861">1861</ref>
<ref source="XF" url="http://xforce.iss.net/static/5441.php">iis-htw-cross-scripting</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0943" seq="2000-0943">
<status>Entry</status>
<desc>Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0397.html">20001027 Potential Security Problem in bftpd-1.0.11</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1858">1858</ref>
<ref source="XF" url="http://xforce.iss.net/static/5426.php">bftpd-user-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0944" seq="2000-0944">
<status>Entry</status>
<desc>CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0402.html">20001027 CGI-Bug: News Update 1.1 administration password bug</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1881">1881</ref>
<ref source="XF" url="http://xforce.iss.net/static/5433.php">news-update-bypass-password</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0945" seq="2000-0945">
<status>Entry</status>
<desc>The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0380.html">20001026 Advisory def-2000-02: Cisco Catalyst remote command execution</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0194.html">20001113 Re: 3500XL</ref>
<ref source="XF" url="http://xforce.iss.net/static/5415.php">cisco-catalyst-remote-commands(5415)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1846">1846</ref>
<ref source="OSVDB" url="http://www.osvdb.org/444">444</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0946" seq="2000-0946">
<status>Entry</status>
<desc>Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0023.html">20001012 Security issue with Compaq Easy Access Keyboard software</ref>
<ref source="CONFIRM" url="http://www5.compaq.com/support/files/desktops/us/revision/1723.html">http://www5.compaq.com/support/files/desktops/us/revision/1723.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/5718.php">compaq-ea-elevate-privileges</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5831">5831</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0947" seq="2000-0947">
<status>Entry</status>
<desc>Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0004.html">20001002 Very probable remote root vulnerability in cfengine</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-061.php3?dis=7.1">MDKSA-2000:061</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-013.txt.asc">NetBSD-SA2000-013</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1757">1757</ref>
<ref source="XF" url="http://xforce.iss.net/static/5630.php">cfengine-cfd-format-string</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0948" seq="2000-0948">
<status>Entry</status>
<desc>GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/136866">20001002 GnoRPM local /tmp vulnerability</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0043.html">20001003 Conectiva Linux Security Announcement - gnorpm</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-055.php3?dis=7.0">MDKSA-2000:055</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-072.html">RHSA-2000:072</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0184.html">20001011 Immunix OS Security Update for gnorpm package</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1761">1761</ref>
<ref source="XF" url="http://xforce.iss.net/static/5317.php">gnorpm-temp-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0949" seq="2000-0949">
<status>Entry</status>
<desc>Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0344.html">20000928 Very interesting traceroute flaw</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-034.0.txt">CSSA-2000-034.0</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-053.php3?dis=7.1">MDKSA-2000:053</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-078.html">RHSA-2000:078</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001013">20001013 traceroute: local root exploit</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-October/000025.html">TLSA2000023-1</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0357.html">20000930 Conectiva Linux Security Announcement - traceroute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1739">1739</ref>
<ref source="XF" url="http://xforce.iss.net/static/5311.php">traceroute-heap-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0951" seq="2000-0951">
<status>Entry</status>
<desc>A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100400-1.txt">A100400-1</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=272079">Q272079</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1756">1756</ref>
<ref source="XF" url="http://xforce.iss.net/static/5335.php">iis-index-dir-traverse</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0952" seq="2000-0952">
<status>Entry</status>
<desc>global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-00:64</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-014.txt.asc">NetBSD-SA2000-014</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6486">6486</ref>
<ref source="XF" url="http://xforce.iss.net/static/5424.php">global-execute-remote-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0953" seq="2000-0953">
<status>Entry</status>
<desc>Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0134.html">20001009 Shambala 4.5 vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1778">1778</ref>
<ref source="XF" url="http://xforce.iss.net/static/5345.php">shambala-connection-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0956" seq="2000-0956">
<status>Entry</status>
<desc>cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-094.html">RHSA-2000:094</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1875">1875</ref>
<ref source="XF" url="http://xforce.iss.net/static/5427.php">cyrus-sasl-gain-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0957" seq="2000-0957">
<status>Entry</status>
<desc>The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0374.html">20001026 (SRADV00004) Remote and local vulnerabilities in pam_mysql</ref>
<ref source="XF" url="http://xforce.iss.net/static/5447.php">pammysql-auth-input</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0958" seq="2000-0958">
<status>Entry</status>
<desc>HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0349.html">20001025 HotJava Browser 3.0 JavaScript security vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/5428.php">hotjava-browser-dom-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0959" seq="2000-0959">
<status>Entry</status>
<desc>glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/85028">20000926 ld.so bug - LD_DEBUG_OUTPUT follows symlinks</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1719">1719</ref>
<ref source="XF" url="http://xforce.iss.net/static/5299.php">glibc-unset-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0960" seq="2000-0960">
<status>Entry</status>
<desc>The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97138100426121&amp;w=2">20001011 Netscape Messaging server 4.15 poor error strings</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1787">1787</ref>
<ref source="XF" url="http://xforce.iss.net/static/5364.php">netscape-messaging-email-verify</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0961" seq="2000-0961">
<status>Entry</status>
<desc>Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0334.html">20000928 commercial products and security [ + new bug ]</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1721">1721</ref>
<ref source="XF" url="http://xforce.iss.net/static/5292.php">netscape-messaging-list-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0962" seq="2000-0962">
<status>Entry</status>
<desc>The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0299.html">20000925 Nmap Protocol Scanning DoS against OpenBSD IPSEC</ref>
<ref source="OPENBSD">20000918 Bad ESP/AH packets could cause a crash under certain conditions.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1723">1723</ref>
<ref source="XF" url="http://xforce.iss.net/static/5634.php">openbsd-nmap-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1574">1574</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0964" seq="2000-0964">
<status>Entry</status>
<desc>Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0336.html">20000928 Another thingy.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1727">1727</ref>
<ref source="XF" url="http://xforce.iss.net/static/5298.php">hinet-ipphone-get-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0965" seq="2000-0965">
<status>Entry</status>
<desc>The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/static/5361.php">hp-virtualvault-nsapi-dos</ref>
<ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0012.html">HPSBUX0010-124</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0966" seq="2000-0966">
<status>Entry</status>
<desc>Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0020.html">HPSBUX0010-125</ref>
<ref source="XF" url="http://xforce.iss.net/static/5379.php">hp-lpspooler-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7244">7244</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0967" seq="2000-0967">
<status>Entry</status>
<desc>PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a101200-1.txt">A101200-1</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-062.php3?dis=7.1">MDKSA-2000:062</ref>
<ref source="DEBIAN">20001014a</ref>
<ref source="DEBIAN">20001014b</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-037.0.txt">CSSA-2000-037.0</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:75.php.asc">FreeBSD-SA-00:75</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-088.html">RHSA-2000:088</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-095.html">RHSA-2000:095</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0204.html">20001012 Conectiva Linux Security Announcement - mod_php3</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1786">1786</ref>
<ref source="XF" url="http://xforce.iss.net/static/5359.php">php-logging-format-string</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0968" seq="2000-0968">
<status>Entry</status>
<desc>Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html">20001016 Half-Life Dedicated Server Vulnerability</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141060">20001024 Tamandua Sekure Labs Security Advisory 2000-01</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html">20001027 Re: Half Life dedicated server Patch</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1799">1799</ref>
<ref source="XF" url="http://xforce.iss.net/static/5375.php">halflife-server-changelevel-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0969" seq="2000-0969">
<status>Entry</status>
<desc>Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html">20001016 Half-Life Dedicated Server Vulnerability</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141060">20001024 Tamandua Sekure Labs Security Advisory 2000-01</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html">20001027 Re: Half Life dedicated server Patch</ref>
<ref source="XF" url="http://xforce.iss.net/static/5413.php">halflife-rcon-format-string</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6983">6983</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0970" seq="2000-0970">
<status>Entry</status>
<desc>IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the &quot;Session ID Cookie Marking&quot; vulnerability.</desc>
<refs>
<ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-080.asp">MS00-080</ref>
<ref source="XF" url="http://xforce.iss.net/static/5396.php">session-cookie-remote-retrieval</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7265">7265</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0972" seq="2000-0972">
<status>Entry</status>
<desc>HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0317.html">20001020 [ Hackerslab bug_paper ] HP-UX crontab temporary file symbolic link vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/5410.php">hp-crontab-read-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0973" seq="2000-0973">
<status>Entry</status>
<desc>Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.</desc>
<refs>
<ref source="DEBIAN">20001013a</ref>
<ref source="REDHAT" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0331.html">RHBA-2000:092-01</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:72.curl.asc">FreeBSD-SA-00:72</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1804">1804</ref>
<ref source="XF" url="http://xforce.iss.net/static/5374.php">curl-error-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0974" seq="2000-0974">
<status>Entry</status>
<desc>GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0201.html">20001011 GPG 1.0.3 doesn't detect modifications to files with multiple signatures</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001111">20001111 gnupg: incorrect signature verification</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:67.gnupg.asc">FreeBSD-SA-00:67</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-089.html">RHSA-2000:089</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-038.0.txt">CSSA-2000-038.0</ref>
<ref source="MANDRAKE">MDKSA-2000:063-1</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000334">CLSA-2000:334</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0361.html">20001025 Immunix OS Security Update for gnupg package</ref>
<ref source="XF" url="http://xforce.iss.net/static/5386.php">gnupg-message-modify</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1797">1797</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1608">1608</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0975" seq="2000-0975">
<status>Entry</status>
<desc>Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0210.html">20001012 Anaconda Advisory</ref>
<ref source="XF" url="http://xforce.iss.net/static/5750.php">anaconda-apexec-directory-traversal</ref>
<ref source="OSVDB" url="http://www.osvdb.org/435">435</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0976" seq="2000-0976">
<status>Entry</status>
<desc>Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0211.html">20001012 another Xlib buffer overflow</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20020502-01-I">20020502-01-I</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1805">1805</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/5751.php">xfree-xlib-bo(5751)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0977" seq="2000-0977">
<status>Entry</status>
<desc>mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the &quot;filename&quot; parameter in a POST request, which is then sent by email to the address specified in the &quot;email&quot; parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0172.html">20001011 Mail File POST Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1807">1807</ref>
<ref source="XF" url="http://xforce.iss.net/static/5358.php">mailfile-post-file-read</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0978" seq="2000-0978">
<status>Entry</status>
<desc>bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the &quot;&amp;&quot; shell metacharacter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0162.html">20001010 Big Brother Systems and Network Monitor vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1779">1779</ref>
<ref source="XF" url="http://xforce.iss.net/static/5719.php">bb4-netmon-execute-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0979" seq="2000-0979">
<status>Entry</status>
<desc>File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the &quot;Share Level Password&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97147777618139&amp;w=2">20001012 NSFOCUS SA2000-05: Microsoft Windows 9x NETBIOS password</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-072.asp">MS00-072</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1780">1780</ref>
<ref source="XF" url="http://xforce.iss.net/static/5395.php">win9x-share-level-password</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:996">oval:org.mitre.oval:def:996</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0980" seq="2000-0980">
<status>Entry</status>
<desc>NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-073.asp">MS00-073</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1781">1781</ref>
<ref source="XF" url="http://xforce.iss.net/static/5357.php">win-nmpi-packet-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0981" seq="2000-0981">
<status>Entry</status>
<desc>MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0318.html">20001023 [CORE SDI ADVISORY] MySQL weak authentication</ref>
<ref source="CONFIRM" url="http://www.mysql.com/documentation/mysql/commented/manual.php?section=Security">http://www.mysql.com/documentation/mysql/commented/manual.php?section=Security</ref>
<ref source="XF" url="http://xforce.iss.net/static/5409.php">mysql-authentication</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0982" seq="2000-0982">
<status>Entry</status>
<desc>Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the &quot;Cached Web Credentials&quot; vulnerability.</desc>
<refs>
<ref source="MISC" url="http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt">http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-076.asp">MS00-076</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1793">1793</ref>
<ref source="XF" url="http://xforce.iss.net/static/5367.php">ie-cache-info</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0983" seq="2000-0983">
<status>Entry</status>
<desc>Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the &quot;NetMeeting Desktop Sharing&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/140341">20001018 Denial of Service attack against computers running Microsoft NetMeeting</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-077.asp">MS00-077</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q273854">Q273854</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1798">1798</ref>
<ref source="XF" url="http://xforce.iss.net/static/5368.php">netmeeting-desktop-sharing-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0984" seq="2000-0984">
<status>Entry</status>
<desc>The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a &quot;?/&quot; string.</desc>
<refs>
<ref source="BUGTRAQ">20001026 [CORE SDI ADVISORY] Cisco IOS HTTP server DoS</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/ioshttpserverquery-pub.shtml">20001025 Cisco IOS HTTP Server Query Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1838">1838</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5412">cisco-ios-query-dos(5412)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0989" seq="2000-0989">
<status>Entry</status>
<desc>Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0293.html">20001020 DoS in Intel corporation 'InBusiness eMail Station'</ref>
<ref source="XF" url="http://xforce.iss.net/static/5414.php">intel-email-username-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6488">6488</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0990" seq="2000-0990">
<status>Entry</status>
<desc>cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an &quot;SMTP AUTH&quot; command with an unknown username.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0258.html">20001016 Authentication failure in cmd5checkpw 0.21</ref>
<ref source="CONFIRM" url="http://members.elysium.pl/brush/cmd5checkpw/changes.html">http://members.elysium.pl/brush/cmd5checkpw/changes.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1809">1809</ref>
<ref source="XF" url="http://xforce.iss.net/static/5382.php">cmd5checkpw-qmail-bypass-authentication</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0991" seq="2000-0991">
<status>Entry</status>
<desc>Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the &quot;HyperTerminal Buffer Overflow&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-079.asp">MS00-079</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1815">1815</ref>
<ref source="XF" url="http://xforce.iss.net/static/5387.php">win-hyperterminal-telnet-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0992" seq="2000-0992">
<status>Entry</status>
<desc>Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0359.html">20000930 scp file transfer hole</ref>
<ref source="BUGTRAQ">20001001 openssh2.2.p1 - Re: scp file transfer hole</ref>
<ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:057">MDKSA-2000:057</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1742">1742</ref>
<ref source="XF" url="http://xforce.iss.net/static/5312.php">scp-overwrite-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0993" seq="2000-0993">
<status>Entry</status>
<desc>Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.org/errata27.html#pw_error">20001003 A format string vulnerability exists in the pw_error(3) function.</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-015.txt.asc">NetBSD-SA2000-015</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:58.chpass.asc">FreeBSD-SA-00:58</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97068555106135&amp;w=2">20001004 Re: OpenBSD Security Advisory</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1744">1744</ref>
<ref source="XF" url="http://xforce.iss.net/static/5339.php">bsd-libutil-format</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0994" seq="2000-0994">
<status>Entry</status>
<desc>Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97068555106135&amp;w=2">20001004 Re: OpenBSD Security Advisory</ref>
<ref source="OPENBSD">20001006 There are printf-style format string bugs in several privileged programs.</ref>
<ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1746">1746</ref>
<ref source="XF" url="http://xforce.iss.net/static/5338.php">bsd-fstat-format</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0995" seq="2000-0995">
<status>Entry</status>
<desc>Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.</desc>
<refs>
<ref source="OPENBSD">20001006 There are printf-style format string bugs in several privileged programs.</ref>
<ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
<ref source="XF" url="http://xforce.iss.net/static/5635.php">bsd-yp-passwd-format</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6125">6125</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-0996" seq="2000-0996">
<status>Entry</status>
<desc>Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.</desc>
<refs>
<ref source="OPENBSD">20001006 There are printf-style format string bugs in several privileged programs. </ref>
<ref source="MISC" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref>
<ref source="XF" url="http://xforce.iss.net/static/5636.php">bsd-su-format</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6124">6124</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1000" seq="2000-1000">
<status>Entry</status>
<desc>Format string vulnerability in AOL Instant Messenger (AIM) 4.1.2010 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by transferring a file whose name includes format characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/137374">20001003 AOL Instant Messenger DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1747">1747</ref>
<ref source="XF" url="http://xforce.iss.net/static/5314.php">aim-file-transfer-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1001" seq="2000-1001">
<status>Entry</status>
<desc>add_2_basket.asp in Element InstantShop allows remote attackers to modify price information via the &quot;price&quot; hidden form variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97240616129614&amp;w=2">20001024 Price modification in Element InstantShop</ref>
<ref source="XF" url="http://xforce.iss.net/static/5402.php">instantshop-modify-price</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6487">6487</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1002" seq="2000-1002">
<status>Entry</status>
<desc>POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/139523">20001012 Re: Netscape Messaging server 4.15 poor error strings</ref>
<ref source="XF" url="http://xforce.iss.net/static/5363.php">communigate-email-verify</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1792">1792</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1003" seq="2000-1003">
<status>Entry</status>
<desc>NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/139511">20001012 NSFOCUS SA2000-04: Microsoft Win9x client driver type comparing vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1794">1794</ref>
<ref source="XF" url="http://xforce.iss.net/static/5370.php">win-netbios-driver-type-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1004" seq="2000-1004">
<status>Entry</status>
<desc>Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97068555106135&amp;w=2">20001004 Re: OpenBSD Security Advisory</ref>
<ref source="XF" url="http://xforce.iss.net/static/5336.php">bsd-photurisd-format</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6123">6123</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1005" seq="2000-1005">
<status>Entry</status>
<desc>Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/138495">20001009 Security Advisory : eXtropia WebStore (web_store.cgi) Directory Traversal Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1774">1774</ref>
<ref source="XF" url="http://xforce.iss.net/static/5347.php">extropia-webstore-fileread</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1006" seq="2000-1006">
<status>Entry</status>
<desc>Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset=&quot;&quot; command, aka the &quot;Malformed MIME Header&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-082.asp">MS00-082</ref>
<ref source="XF" url="http://xforce.iss.net/static/5448.php">ms-exchange-mime-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1869">1869</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1007" seq="2000-1007">
<status>Entry</status>
<desc>I-gear 3.5.7 and earlier does not properly process log entries in which a URL is longer than 255 characters, which allows an attacker to cause reporting errors.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0048.html">20001025 I-gear 3.5.x for Microsoft Proxy logging vulnerability + temporary fix.</ref>
<ref source="XF" url="http://xforce.iss.net/static/5791.php">igear-invalid-log(5791)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1010" seq="2000-1010">
<status>Entry</status>
<desc>Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/137890">20001006 talkd [WAS: Re: OpenBSD Security Advisory]</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1764">1764</ref>
<ref source="XF" url="http://xforce.iss.net/static/5344.php">linux-talkd-overwrite-root</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1011" seq="2000-1011">
<status>Entry</status>
<desc>Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc">FreeBSD-SA-00:53</ref>
<ref source="XF" url="http://xforce.iss.net/static/5638.php">freebsd-catopen-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6070">6070</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1014" seq="2000-1014">
<status>Entry</status>
<desc>Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0325.html">20000927 Unixware SCOhelp http server format string vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1717">1717</ref>
<ref source="XF" url="http://xforce.iss.net/static/5291.php">unixware-scohelp-format</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3240">3240</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1016" seq="2000-1016">
<status>Entry</status>
<desc>The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/84360">20000921 httpd.conf in Suse 6.4</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1707">1707</ref>
<ref source="XF" url="http://xforce.iss.net/static/5276.php">suse-installed-packages-exposed</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1018" seq="2000-1018">
<status>Entry</status>
<desc>shred 1.0 file wiping utility does not properly open a file for overwriting or flush its buffers, which prevents shred from properly replacing the file's data and allows local users to recover the file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119799515246&amp;w=2">20001010 Shred 1.0 Bug Report</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97131166004145&amp;w=2 ">20001011 Shred v1.0 Fix</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1788">1788</ref>
<ref source="XF" url="http://xforce.iss.net/static/5722.php">shred-recover-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1019" seq="2000-1019">
<status>Entry</status>
<desc>Search engine in Ultraseek 3.1 and 3.1.10 (aka Inktomi Search) allows remote attackers to cause a denial of service via a malformed URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97301487015664&amp;w=2">20001030 Ultraseek 3.1.x Remote DoS Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1866">1866</ref>
<ref source="XF" url="http://xforce.iss.net/static/5439.php">ultraseek-malformed-url-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1022" seq="2000-1022">
<status>Entry</status>
<desc>The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0222.html">20000919 Cisco PIX Firewall (smtp content filtering hack)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0241.html">20000920 Re: Cisco PIX Firewall (smtp content filtering hack) - Version 4.2(1) not exploitable</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/PIXfirewallSMTPfilter-pub.shtml">20001005 Cisco Secure PIX Firewall Mailguard Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1698">1698</ref>
<ref source="XF" url="http://xforce.iss.net/static/5277.php">cisco-pix-smtp-filtering</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1024" seq="2000-1024">
<status>Entry</status>
<desc>eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97306581513537&amp;w=2">20001101 Unify eWave ServletExec upload</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1876">1876</ref>
<ref source="XF" url="http://xforce.iss.net/static/5450.php">ewave-servletexec-file-upload</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1026" seq="2000-1026">
<status>Entry</status>
<desc>Multiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:61.tcpdump.v1.1.asc">FreeBSD-SA-00:61</ref>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0681.html">SuSE-SA:2000:46</ref>
<ref source="DEBIAN">20001120a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1870">1870</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5480">tcpdump-afs-packet-overflow(5480)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1027" seq="2000-1027">
<status>Entry</status>
<desc>Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97059440000367&amp;w=2">20001003 Cisco PIX Firewall allow external users to discover internal IPs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1877">1877</ref>
<ref source="XF" url="http://xforce.iss.net/static/5646.php">cisco-pix-reveal-address</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1623">1623</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1031" seq="2000-1031">
<status>Entry</status>
<desc>Buffer overflow in dtterm in HP-UX 11.0 and HP Tru64 UNIX 4.0f through 5.1a allows local users to execute arbitrary code via a long -tn option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/75188">20000810 Re: Possible vulnerability in HPUX ( Add vulnerability List )</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/290115">20020902 Happy Labor Day from Snosoft</ref>
<ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html">20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html">20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification</ref>
<ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0034.html">HPSBUX0011-128</ref>
<ref source="HP" url="http://wwss1pro.compaq.com/support/reference_library/viewdocument.asp?source=SRB0039W.xml&amp;dt=11">SSRT2275</ref>
<ref source="HP">SSRT2280</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/320067">VU#320067</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1889">1889</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5461">hp-dtterm(5461)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1032" seq="2000-1032">
<status>Entry</status>
<desc>The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/142808">20001101 Re: Samba 2.0.7 SWAT vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1890">1890</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5816">fw1-login-response(5816)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1632">1632</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1034" seq="2000-1034">
<status>Entry</status>
<desc>Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the &quot;ActiveX Parameter Validation&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349782305448&amp;w=2">20001106 System Monitor ActiveX Buffer Overflow Vulnerability</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-085.asp">MS00-085</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1899">1899</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5467">system-monitor-activex-bo(5467)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1036" seq="2000-1036">
<status>Entry</status>
<desc>Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0252.html">20000920 Extent RBS directory Transversal.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1704">1704</ref>
<ref source="XF" url="http://xforce.iss.net/static/5275.php">rbs-isp-directory-traversal</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1038" seq="2000-1038">
<status>Entry</status>
<desc>The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request.</desc>
<refs>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=SA90544&amp;apar=only">SA90544</ref>
<ref source="CONFIRM" url="http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument">http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument</ref>
<ref source="XF" url="http://xforce.iss.net/static/5266.php">as400-firewall-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1040" seq="2000-1040">
<status>Entry</status>
<desc>Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001014">20001014 nis: local exploit</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1">MDKSA-2000:064</ref>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html">SuSE-SA:2000:042</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-086.html">RHSA-2000:086</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-039.0.txt">CSSA-2000-039.0</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0356.html">20001025 Immunix OS Security Update for ypbind package</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html">20001030 Trustix Security Advisory - ping gnupg ypbind</ref>
<ref source="XF" url="http://xforce.iss.net/static/5394.php">ypbind-printf-format-string</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1820">1820</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1041" seq="2000-1041">
<status>Entry</status>
<desc>Buffer overflow in ypbind 3.3 possibly allows an attacker to gain root privileges.</desc>
<refs>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1">MDKSA-2000:064</ref>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html">SuSE-SA:2000:042</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-039.0.txt">CSSA-2000-039.0</ref>
<ref source="XF" url="http://xforce.iss.net/static/5759.php">ypbind-remote-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1042" seq="2000-1042">
<status>Entry</status>
<desc>Buffer overflow in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.</desc>
<refs>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1">MDKSA-2000:064</ref>
<ref source="XF" url="http://xforce.iss.net/static/5730.php">linux-ypserv-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1043" seq="2000-1043">
<status>Entry</status>
<desc>Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.</desc>
<refs>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1">MDKSA-2000:064</ref>
<ref source="XF" url="http://xforce.iss.net/static/5731.php">linux-ypserv-format-string</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1044" seq="2000-1044">
<status>Entry</status>
<desc>Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.</desc>
<refs>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html">SuSE-SA:2000:042</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1820">1820</ref>
<ref source="XF" url="http://xforce.iss.net/static/5394.php">ypbind-printf-format-string</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1045" seq="2000-1045">
<status>Entry</status>
<desc>nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-024.html">RHSA-2000:024</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-066-1.php3">MDKSA-2000-066</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1863">1863</ref>
<ref source="XF" url="http://xforce.iss.net/static/5449.php">nssldap-nscd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1047" seq="2000-1047">
<status>Entry</status>
<desc>Buffer overflow in SMTP service of Lotus Domino 5.0.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long ENVID keyword in the &quot;MAIL FROM&quot; command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/143071">20001103 [SAFER] Buffer overflow in Lotus Domino SMTP Server</ref>
<ref source="XF" url="http://xforce.iss.net/static/5488.php">lotus-domino-smtp-envid(5488)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1905">1905</ref>
<ref source="OSVDB" url="http://www.osvdb.org/442">442</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1049" seq="2000-1049">
<status>Entry</status>
<desc>Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of &quot;.&quot; characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97310314724964&amp;w=2">20001101 Allaire's JRUN DoS</ref>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=18085&amp;Method=Full">ASB00-030</ref>
<ref source="XF" url="http://xforce.iss.net/static/5452.php">allaire-jrun-servlet-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1050" seq="2000-1050">
<status>Entry</status>
<desc>Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra &quot;/&quot; in the beginning of the request (aka the &quot;extra leading slash&quot;).</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236316510117&amp;w=2">20001023 Allaire's JRUN Unauthenticated Access to WEB-INF directory</ref>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=17966&amp;Method=Full">ASB00-027</ref>
<ref source="XF" url="http://xforce.iss.net/static/5407.php">allaire-jrun-webinf-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/500">500</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1051" seq="2000-1051">
<status>Entry</status>
<desc>Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236692714978&amp;w=2">20001023 Allaire JRUN 2.3 Arbitrary File Retrieval</ref>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=17968&amp;Method=Full">ASB00-028</ref>
<ref source="XF" url="http://xforce.iss.net/static/5405.php">allaire-jrun-ssifilter-url</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1054" seq="2000-1054">
<status>Entry</status>
<desc>Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml">20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1705">1705</ref>
<ref source="XF" url="http://xforce.iss.net/static/5272.php">ciscosecure-csadmin-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1055" seq="2000-1055">
<status>Entry</status>
<desc>Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml">20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1706">1706</ref>
<ref source="XF" url="http://xforce.iss.net/static/5273.php">ciscosecure-tacacs-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1569">1569</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1056" seq="2000-1056">
<status>Entry</status>
<desc>CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml">20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1708">1708</ref>
<ref source="XF" url="http://xforce.iss.net/static/5274.php">ciscosecure-ldap-bypass-authentication</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1057" seq="2000-1057">
<status>Entry</status>
<desc>Vulnerabilities in database configuration scripts in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows local users to gain privileges, possibly via insecure permissions.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0140.html">HPSBUX0009-120</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1682">1682</ref>
<ref source="XF" url="http://xforce.iss.net/static/5229.php">hp-openview-nnm-scripts</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1058" seq="2000-1058">
<status>Entry</status>
<desc>Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, in the SNMP service (snmp.exe), aka the &quot;Java SNMP MIB Browser Object ID parsing problem.&quot;</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97004856403173&amp;w=2">20000926 DST2K0014: BufferOverrun in HP Openview Network Node Manager v6.1 (Round2)</ref>
<ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0274.html">HPSBUX0009-121</ref>
<ref source="XF" url="http://xforce.iss.net/static/5282.php">openview-nmm-snmp-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1059" seq="2000-1059">
<status>Entry</status>
<desc>The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an &quot;xhost + localhost&quot; command, which allows local users to sniff X Windows events and gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/136495">20000929 Mandrake 7.1 bypasses Xauthority X session security.</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-052.php3">MDKSA-2000:052</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1735">1735</ref>
<ref source="XF" url="http://xforce.iss.net/static/5305.php">xinitrc-bypass-xauthority</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1060" seq="2000-1060">
<status>Entry</status>
<desc>The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an &quot;xhost + localhost&quot; command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0022.html">20001002 Local vulnerability in XFCE 3.5.1</ref>
<ref source="FREEBSD">FreeBSD-SA-00:65</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1736">1736</ref>
<ref source="XF" url="http://xforce.iss.net/static/5305.php">xinitrc-bypass-xauthority</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1061" seq="2000-1061">
<status>Entry</status>
<desc>Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer's security settings and execute arbitrary commands via a malicious web page or email, aka the &quot;Microsoft VM ActiveX Component&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-075.asp">MS00-075</ref>
<ref source="XF" url="http://xforce.iss.net/static/5127.php">java-vm-applet</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1068" seq="2000-1068">
<status>Entry</status>
<desc>pollit.cgi in Poll It 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the poll_options parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236719315352&amp;w=2">20001023 Re: Poll It v2.0 cgi (again)</ref>
<ref source="CONFIRM" url="http://www.cgi-world.com/pollit.html">http://www.cgi-world.com/pollit.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/5792.php">pollit-polloptions-execute-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1069" seq="2000-1069">
<status>Entry</status>
<desc>pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236719315352&amp;w=2">20001023 Re: Poll It v2.0 cgi (again)</ref>
<ref source="XF" url="http://xforce.iss.net/static/5419.php">pollit-admin-password-var</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1070" seq="2000-1070">
<status>Entry</status>
<desc>pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236719315352&amp;w=2">20001023 Re: Poll It v2.0 cgi (again)</ref>
<ref source="XF" url="http://xforce.iss.net/static/5794.php">pollit-webroot-gain-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1071" seq="2000-1071">
<status>Entry</status>
<desc>The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an &quot;xhost +&quot; command, which allows remote attackers to monitor X Windows events and gain privileges.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt">A100900-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1767">1767</ref>
<ref source="XF" url="http://xforce.iss.net/static/5752.php">ical-xhost-gain-privileges</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7213">7213</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1072" seq="2000-1072">
<status>Entry</status>
<desc>iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt">A100900-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1768">1768</ref>
<ref source="XF" url="http://xforce.iss.net/static/5756.php">ical-iplncal-gain-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7212">7212</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1073" seq="2000-1073">
<status>Entry</status>
<desc>csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt">A100900-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1769">1769</ref>
<ref source="XF" url="http://xforce.iss.net/static/5757.php">ical-csstart-gain-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7210">7210</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1074" seq="2000-1074">
<status>Entry</status>
<desc>csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt">A100900-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1769">1769</ref>
<ref source="XF" url="http://xforce.iss.net/static/5757.php">ical-csstart-gain-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7209">7209</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1075" seq="2000-1075">
<status>Entry</status>
<desc>Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html">20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug</ref>
<ref source="CONFIRM" url="http://www.iplanet.com/downloads/patches/0122.html">http://www.iplanet.com/downloads/patches/0122.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1839">1839</ref>
<ref source="XF" url="http://xforce.iss.net/static/5421.php">iplanet-netscape-directory-traversal</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4086">4086</ref>
<ref source="OSVDB" url="http://www.osvdb.org/486">486</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1077" seq="2000-1077">
<status>Entry</status>
<desc>Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141435">20001026 Buffer overflow in iPlanet Web Server 4 server side SHTML parsing module</ref>
<ref source="XF" url="http://xforce.iss.net/static/5446.php">iplanet-web-server-shtml-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1080" seq="2000-1080">
<status>Entry</status>
<desc>Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97318797630246&amp;w=2">20001102 dos on quake1 servers</ref>
<ref source="CONFIRM" url="http://proquake.ai.mit.edu/">http://proquake.ai.mit.edu/</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1900">1900</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5527">quake-empty-udp-dos(5527)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1089" seq="2000-1089">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the &quot;Phone Book Service Buffer Overflow&quot; vulnerability.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.stake.com/research/advisories/2000/a120400-1.txt">A120400-1</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-094.asp">MS00-094</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2048">2048</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5623">phone-book-service-bo(5623)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1094" seq="2000-1094">
<status>Entry</status>
<desc>Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a &quot;buddyicon&quot; command with a long &quot;src&quot; argument.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a121200-1.txt">A121200-1</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97668265628917&amp;w=2">20001213 Administrivia &amp; AOL IM Advisory</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97683774417132&amp;w=2">20001214 Re: AIM &amp; @stake's advisory</ref>
<ref source="XF">aolim-buddyicon-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1692">1692</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1095" seq="2000-1095">
<status>Entry</status>
<desc>modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0179.html">20001112 RedHat 7.0 (and SuSE): modutils + netkit = root compromise. (fwd)</ref>
<ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0596.html">SuSE-SA:2000:44</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-071-1.php3?dis=7.1">MDKSA-2000:071</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-108.html">RHSA-2000:108</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001120">20001120 modutils: local exploit</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000340">CLSA-2000:340</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1936">1936</ref>
<ref source="XF" url="http://xforce.iss.net/static/5516.php">linux-modprobe-execute-code</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1096" seq="2000-1096">
<status>Entry</status>
<desc>crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0237.html">20001116 vixie cron...</ref>
<ref source="DEBIAN">20001118a</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1960">1960</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5543">vixie-cron-execute-commands(5543)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1097" seq="2000-1097">
<status>Entry</status>
<desc>The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username in the authentication page.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0406.html">20001129 DoS in Sonicwall SOHO firewall</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0435.html">20001201 FW: SonicWALL SOHO Vulnerability (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2013">2013</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5596">sonicwall-soho-dos(5596)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1667">1667</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1099" seq="2000-1099">
<status>Entry</status>
<desc>Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/199&amp;type=0&amp;nav=sec.sba">00199</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0011-132">HPSBUX0011-132</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5605">jdk-untrusted-java-class(5605)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7255">7255</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1101" seq="2000-1101">
<status>Entry</status>
<desc>Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the &quot;Restrict to home directory&quot; option enabled allows local users to escape the home directory via a &quot;/../&quot; string, a variation of the .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0386.html">20001127 Vulnerability in Winsock FTPD 2.41/3.00 (Pro)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2005">2005</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/5608.php">wftpd-dir-traverse(5608)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1106" seq="2000-1106">
<status>Entry</status>
<desc>Trend Micro InterScan VirusWall creates an &quot;Intscan&quot; share to the &quot;InterScan&quot; directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/147563">20001128 TrendMicro InterScan VirusWall shared folder problem</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0016.html">20001201 Responding to BugTraq ID 2014 - &quot;Trend Micro InterScan VirusWall Shared Directory Vulnerability&quot;</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2014">2014</ref>
<ref source="XF" url="http://xforce.iss.net/static/5606.php">interscan-viruswall-unauth-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1107" seq="2000-1107">
<status>Entry</status>
<desc>in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0387.html">20001128 SuSE Linux 6.x 7.0 Ident buffer overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2015">2015</ref>
<ref source="XF" url="http://xforce.iss.net/static/5590.php">linux-ident-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1108" seq="2000-1108">
<status>Entry</status>
<desc>cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0192.html">20001113 Problems with cons.saver</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001125">20001125 mc: local DoS</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-078.php3">MDKSA-2000:078</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1945">1945</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5519">midnight-commander-conssaver-symlink(5519)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1109" seq="2000-1109">
<status>Entry</status>
<desc>Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0373.html">20001127 Midnight Commander</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-036">DSA-036</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_011_mc.html">SuSE-SA:2001:11</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2016">2016</ref>
<ref source="XF" url="http://xforce.iss.net/static/5929.php">midnight-commander-elevate-privileges(5929)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1111" seq="2000-1111">
<status>Entry</status>
<desc>Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/147914">20001129 Windows 2000 Telnet Service DoS </ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2018">2018</ref>
<ref source="XF" url="http://xforce.iss.net/static/5598.php">win2k-telnet-dos(5598)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1112" seq="2000-1112">
<status>Entry</status>
<desc>Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the &quot;.WMS Script Execution&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-090.asp">MS00-090</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1976">1976</ref>
<ref source="XF" url="http://xforce.iss.net/static/5575.php">mediaplayer-wms-script-exe</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1113" seq="2000-1113">
<status>Entry</status>
<desc>Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the &quot;.ASX Buffer Overrun&quot; vulnerability.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a112300-1.txt">A112300-1</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-090.asp">MS00-090</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1980">1980</ref>
<ref source="XF" url="http://xforce.iss.net/static/5574.php">mediaplayer-asx-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1115" seq="2000-1115">
<status>Entry</status>
<desc>Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0299.html">20001122 602Pro Lan Suite Web Admin Overflow</ref>
<ref source="CONFIRM" url="http://www.software602.com/products/ls/support/newbuild.html">http://www.software602.com/products/ls/support/newbuild.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1979">1979</ref>
<ref source="XF" url="http://xforce.iss.net/static/5583.php">software602-lan-suite-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1119" seq="2000-1119">
<status>Entry</status>
<desc>Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long &quot;x=&quot; argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities </ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08812&amp;apar=only">IY08812</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY10721&amp;apar=only">IY10721</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2032">2032</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5621">aix-setsenv-bo(5621)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1676">1676</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1120" seq="2000-1120">
<status>Entry</status>
<desc>Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08143&amp;apar=only">IY08143</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08287&amp;apar=only">IY08287</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2033">2033</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5620">aix-digest-bo(5620)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1121" seq="2000-1121">
<status>Entry</status>
<desc>Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08143&amp;apar=only">IY08143</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08287&amp;apar=only">IY08287</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2034">2034</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5619">aix-enq-bo(5619)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1122" seq="2000-1122">
<status>Entry</status>
<desc>Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY07831&amp;apar=only">IY07831</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY07790&amp;apar=only">IY07790</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2035">2035</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1123" seq="2000-1123">
<status>Entry</status>
<desc>Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY12638&amp;apar=only">IY12638</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2036">2036</ref>
<ref source="XF" url="http://xforce.iss.net/static/5617.php">aix-pioout-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1124" seq="2000-1124">
<status>Entry</status>
<desc>Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">20001201 Fixed local AIX V43 vulnerabilities</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY12638&amp;apar=only">IY12638</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2037">2037</ref>
<ref source="XF" url="http://xforce.iss.net/static/5616.php">aix-piobe-bo(5616)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1131" seq="2000-1131">
<status>Entry</status>
<desc>Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0144.html">20001110 [hacksware] gbook.cgi remote command execution vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1940">1940</ref>
<ref source="XF" url="http://xforce.iss.net/static/5509.php">gbook-cgi-remote-execution</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1132" seq="2000-1132">
<status>Entry</status>
<desc>DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed &quot;forum&quot; variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0218.html">20001114 Cgisecurity.com advisory on dcforum</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1951">1951</ref>
<ref source="CONFIRM" url="http://www.dcscripts.com/dcforum/dcfNews/124.html#1">http://www.dcscripts.com/dcforum/dcfNews/124.html#1</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5533">dcforum-cgi-view-files(5533)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1646">1646</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1135" seq="2000-1135">
<status>Entry</status>
<desc>fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001130">20001130 DSA-002-1 fsh: symlink attack</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5633">linux-fsh-symlink(5633)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7208">7208</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1136" seq="2000-1136">
<status>Entry</status>
<desc>elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97502995616099&amp;w=2">20001122 New version of elvis-tiny released</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1984">1984</ref>
<ref source="XF" url="http://xforce.iss.net/static/5632.php">linux-tinyelvis-tmpfiles</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1137" seq="2000-1137">
<status>Entry</status>
<desc>GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001129">20001129 DSA-001-1 ed: symlink attack</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-076.php3">MDKSA-2000:076</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-123.html">RHSA-2000:123</ref>
<ref source="BUGTRAQ">20001211 Immunix OS Security update for ed</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000359">CLA-2000:359-2</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5723">gnu-ed-symlink(5723)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6491">6491</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1139" seq="2000-1139">
<status>Entry</status>
<desc>The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the &quot;Exchange User Account&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-088.asp">MS00-088</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1958">1958</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5537">ms-exchange-username-pwd(5537)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1140" seq="2000-1140">
<status>Entry</status>
<desc>Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they are in a honeypot system by comparing the results from kill commands with the process listing in the /proc filesystem.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1908">1908</ref>
<ref source="XF" url="http://xforce.iss.net/static/5473.php">mantrap-hidden-processes</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1141" seq="2000-1141">
<status>Entry</status>
<desc>Recourse ManTrap 1.6 modifies the kernel so that &quot;..&quot; does not appear in the /proc listing, which allows attackers to determine that they are in a honeypot system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="XF" url="http://xforce.iss.net/static/5473.php">mantrap-hidden-processes</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1142" seq="2000-1142">
<status>Entry</status>
<desc>Recourse ManTrap 1.6 generates an error when an attacker cd's to /proc/self/cwd and executes the pwd command, which allows attackers to determine that they are in a honeypot system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="XF" url="http://xforce.iss.net/static/5949.php">mantrap-pwd-reveal-information</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1143" seq="2000-1143">
<status>Entry</status>
<desc>Recourse ManTrap 1.6 hides the first 4 processes that run on a Solaris system, which allows attackers to determine that they are in a honeypot system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="XF" url="http://xforce.iss.net/static/5473.php">mantrap-hidden-processes</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1144" seq="2000-1144">
<status>Entry</status>
<desc>Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting &quot;/&quot; file system is higher than normal, which allows attackers to determine that they are in a chroot environment.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1909">1909</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="XF" url="http://xforce.iss.net/static/5472.php">mantrap-inode-disclosure</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1145" seq="2000-1145">
<status>Entry</status>
<desc>Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/mem and raw disk devices to identify ManTrap processes or modify arbitrary data files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="XF" url="http://xforce.iss.net/static/5950.php">mantrap-identify-processes</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1146" seq="2000-1146">
<status>Entry</status>
<desc>Recourse ManTrap 1.6 allows attackers to cause a denial of service via a sequence of commands that navigate into and out of the /proc/self directory and executing various commands such as ls or pwd.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1913">1913</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref>
<ref source="XF" url="http://xforce.iss.net/static/5528.php">mantrap-dir-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1148" seq="2000-1148">
<status>Entry</status>
<desc>The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0072.html">20001104 Filesystem Access + VolanoChat = VChat admin (fwd)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0085.html">20001106 Re: FW: Filesystem Access + VolanoChat = VChat admin (fwd)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1906">1906</ref>
<ref source="XF" url="http://xforce.iss.net/static/5465.php">volanochatpro-plaintext-password</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1149" seq="2000-1149">
<status>Entry</status>
<desc>Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the &quot;Terminal Server Login Buffer Overflow&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/143991">20001108 [CORE SDI ADVISORY] MS NT4.0 Terminal Server Edition GINA buffer overflow </ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-087.asp">MS00-087</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1924">1924</ref>
<ref source="XF" url="http://xforce.iss.net/static/5489.php">nt-termserv-gina-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1162" seq="2000-1162">
<status>Entry</status>
<desc>ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.</desc>
<refs>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-041.0.txt">CSSA-2000-041</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-074.php3">MDKSA-2000:074</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000343">CLSA-2000:343</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-114.html">RHSA-2000:114</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001123">20001123 ghostscript: symlink attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1990">1990</ref>
<ref source="XF" url="http://xforce.iss.net/static/5563.php">ghostscript-sym-link</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1163" seq="2000-1163">
<status>Entry</status>
<desc>ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.</desc>
<refs>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-041.0.txt">CSSA-2000-041</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-074.php3">MDKSA-2000:074</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000343">CLSA-2000:343</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001123">20001123 ghostscript: symlink attack</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1991">1991</ref>
<ref source="XF" url="http://xforce.iss.net/static/5564.php">ghostscript-env-variable</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1164" seq="2000-1164">
<status>Entry</status>
<desc>WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0253.html">20001118 WinVNC 3.3.x</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1961">1961</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5545">winvnc-modify-registry(5545)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1165" seq="2000-1165">
<status>Entry</status>
<desc>Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing &gt; in the priority specifier.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0300.html">20001122 DoS possibility in syslog-ng</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:02.syslog-ng.asc">FreeBSD-SA-01:02</ref>
<ref source="CONFIRM" url="http://www.balabit.hu/products/syslog-ng/">http://www.balabit.hu/products/syslog-ng/</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1981">1981</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5576">balabit-syslog-ng-dos(5576)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1166" seq="2000-1166">
<status>Entry</status>
<desc>Twig webmail system does not properly set the &quot;vhosts&quot; variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0351.html">20001124 Security problems with TWIG webmail system</ref>
<ref source="CONFIRM" url="http://twig.screwdriver.net/file.php3?file=CHANGELOG">http://twig.screwdriver.net/file.php3?file=CHANGELOG</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1998">1998</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5581">twig-php3-script-execute(5581)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1167" seq="2000-1167">
<status>Entry</status>
<desc>ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the &quot;nat deny_incoming&quot; command, which allows remote attackers to connect to the target system.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:70.ppp-nat.asc">FreeBSD-SA-00:70</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1974">1974</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5584">freebsd-ppp-bypass-gateway(5584)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1655">1655</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1169" seq="2000-1169">
<status>Entry</status>
<desc>OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0195.html">20001123 OpenSSH Security Advisory (adv.fwd)</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-068.php3">MDKSA-2000:068</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0217.html">20001115 Trustix Security Advisory - bind and openssh (and modutils)</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001118">20001118 openssh: possible remote exploit</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000345">CLSA-2000:345</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-111.html">RHSA-2000:111</ref>
<ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2000-Nov/0004.html">SuSE-SA:2000:47</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1949">1949</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5517">openssh-unauthorized-access(5517)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/2114">2114</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6248">6248</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1170" seq="2000-1170">
<status>Entry</status>
<desc>Buffer overflow in Netsnap webcam HTTP server before 1.2.9 allows remote attackers to execute arbitrary commands via a long GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97439536016554&amp;w=2">20001115 Netsnap Webcam Software Remote Overflow</ref>
<ref source="CONFIRM" url="http://www.netsnap.com/new.htm">http://www.netsnap.com/new.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1956">1956</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5534">netsnap-remote-bo(5534)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1171" seq="2000-1171">
<status>Entry</status>
<desc>Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in the &quot;thesection&quot; parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0263.html">20001120 CGIForum 1.0 Vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5553">cgiforum-view-files(5553)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1963">1963</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1174" seq="2000-1174">
<status>Entry</status>
<desc>Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a long username.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0251.html">20001118 [hacksware] Ethereal 0.8.13 AFS ACL parsing buffer overflow bug</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001122a">20001121 ethereal: remote exploit</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000342">CLSA-2000:342</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-116.html">RHSA-2000:116</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:81.ethereal.asc">FreeBSD-SA-00:81</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5557">ethereal-afs-bo(5557)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1972">1972</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1178" seq="2000-1178">
<status>Entry</status>
<desc>Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0227.html">20001116 Joe's Own Editor File Link Vulnerability</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-110.html">RHSA-2000:110</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-072.php3">MDKSA-2000:072</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000356">CLA-2000:356</ref>
<ref source="DEBIAN">20001122</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001201">20001201 DSA-003-1 joe: symlink attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97500174210821&amp;w=2">20001121 Immunix OS Security update for joe</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1959">1959</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5546">joe-symlink-corruption(5546)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1179" seq="2000-1179">
<status>Entry</status>
<desc>Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97440068130051&amp;w=2">20001115 Netopia ISDN Router 650-ST: Viewing of all system logs without login</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1952">1952</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5536">netopia-view-system-log(5536)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1180" seq="2000-1180">
<status>Entry</status>
<desc>Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97474521003453&amp;w=2">20001120 vulnerability in Connection Manager Control binary in Oracle</ref>
<ref source="BUGTRAQ">20010118 Patch for Potential Security Vulnerability in Oracle Connection Manager Control</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1968">1968</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5551">oracle-cmctl-bo(5551)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1181" seq="2000-1181">
<status>Entry</status>
<desc>Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0236.html">20001116 [CORE SDI ADVISORY] RealServer memory contents disclosure</ref>
<ref source="CONFIRM" url="http://service.real.com/help/faq/security/memory.html">http://service.real.com/help/faq/security/memory.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1957">1957</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5538">realserver-gain-access(5538)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1182" seq="2000-1182">
<status>Entry</status>
<desc>WatchGuard Firebox II allows remote attackers to cause a denial of service by flooding the Firebox with a large number of FTP or SMTP requests, which disables proxy handling.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0224.html">20001116 Possible Watchguard Firebox II DoS</ref>
<ref source="CONFIRM" url="https://www.watchguard.com/support/patches.html">https://www.watchguard.com/support/patches.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1953">1953</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5535">watchguard-firebox-ftp-dos(5535)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1184" seq="2000-1184">
<status>Entry</status>
<desc>telnetd in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service by specifying an arbitrary large file in the TERMCAP environmental variable, which consumes resources as the server processes the file.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:69.telnetd.v1.1.asc">FreeBSD-SA-00:69</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5959">telnetd-termcap-dos(5959)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6083">6083</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1187" seq="2000-1187">
<status>Entry</status>
<desc>Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-109.html">RHSA-2000:109</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000344">CLSA-2000:344</ref>
<ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2000-Nov/0005.html">SuSE-SA:2000:48</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:66.netscape.asc">FreeBSD-SA-00:66</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97500270012529&amp;w=2">20001121 Immunix OS Security update for netscape</ref>
<ref source="XF" url="http://xforce.iss.net/static/5542.php">netscape-client-html-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7207">7207</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1189" seq="2000-1189">
<status>Entry</status>
<desc>Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-120.html">RHSA-2000:120</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000358">CLA-2000:358</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-082.php3">MDKSA-2000:082-1</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5747">pam-localuser-bo(5747)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1190" seq="2000-1190">
<status>Entry</status>
<desc>imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95984116811100&amp;w=2">20000531 Re: strike#2</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-016.html">RHSA-2000:016</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/4941.php">linux-imwheel-symlink(4941)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1193" seq="2000-1193">
<status>Entry</status>
<desc>Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html">20000412 Performance Copilot for IRIX 6.5</ref>
<ref source="XF" url="http://xforce.iss.net/static/4284.php">irix-pcp-pmcd-dos(4284)</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20020407-01-I">20020407-01-I</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1195" seq="2000-1195">
<status>Entry</status>
<desc>telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.</desc>
<refs>
<ref source="CALDERA" url="http://www.caldera.com/support/security/advisories/CSSA-2000-008.0.txt">CSSA-2000-008.0</ref>
<ref source="XF" url="http://xforce.iss.net/static/4225.php">telnetd-login-bypass(4225)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1196" seq="2000-1196">
<status>Entry</status>
<desc>PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.</desc>
<refs>
<ref source="CONFIRM" url="http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html">http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html</ref>
<ref source="MISC" url="http://packetstormsecurity.org/0004-exploits/ooo1.txt">http://packetstormsecurity.org/0004-exploits/ooo1.txt</ref>
<ref source="XF" url="http://xforce.iss.net/static/7362.php">publishingxpert-pscoerrpage-url(7362)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1200" seq="2000-1200">
<status>Entry</status>
<desc>Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/44430">20000201 Windows NT and account list leak ! A new SID usage</ref>
<ref source="XF" url="http://xforce.iss.net/static/4015.php">nt-lsa-domain-sid(4015)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/959">959</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1203" seq="2000-1203">
<status>Entry</status>
<desc>Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.</desc>
<refs>
<ref source="VULN-DEV" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=95886062521327&amp;w=2">20000520 Infinite loop in LOTUS NOTE 5.0.3. SMTP SERVER</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/cgi-bin/archive.pl?id=1&amp;start=2002-01-21&amp;end=2002-01-27&amp;mid=209116&amp;threads=1">20010820 Lotus Domino DoS</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/209754">20010823 Lotus Domino DoS solution</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/3212">3212</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7012">lotus-domino-bounced-message-dos(7012)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1210" seq="2000-1210">
<status>Entry</status>
<desc>Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95371672300045&amp;w=2">20000322 Security bug in Apache project: Jakarta Tomcat</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/4205.php">apache-tomcat-file-contents(4205)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1211" seq="2000-1211">
<status>Entry</status>
<desc>Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.</desc>
<refs>
<ref source="BUGTRAQ">20001222 Zope DTML Role Issue</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-125.html">RHSA-2000:125</ref>
<ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert">http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3">MDKSA-2000:083</ref>
<ref source="XF" url="http://www.iss.net/security_center/static/5824.php">zope-legacy-names(5824)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6282">6282</ref>
</refs>
</item>

<item type="CVE" name="CVE-2000-1212" seq="2000-1212">
<status>Entry</status>
<desc>Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.</desc>
<refs>
<ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:086">MDKSA-2000:086</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000365">CLA-2000:365</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-007">DSA-007</ref>
<ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert">http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-135.html">RHSA-2000:135</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5778">zope-image-file(5778)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6283">6283</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0001" seq="2001-0001">
<status>Entry</status>
<desc>cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0257.html">20010213 RFP2101: RFPlutonium to fuel your PHP-Nuke</ref>
<ref source="XF" url="http://xforce.iss.net/static/6183.php">php-nuke-elevate-privileges(6183)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0002" seq="2001-0002">
<status>Entry</status>
<desc>Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp">MS01-015</ref>
<ref source="BUGTRAQ">20001120 IE 5.x/Outlook allows executing arbitrary programs using .chm files and temporary internet files folder</ref>
<ref source="MISC" url="http://www.guninski.com/chmtempmain.html">http://www.guninski.com/chmtempmain.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2456">2456</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7823">7823</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:920">oval:org.mitre.oval:def:920</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5567">ie-chm-execute-files(5567)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0003" seq="2001-0003">
<status>Entry</status>
<desc>Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the &quot;Web Client NTLM Authentication&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-001.asp">MS01-001</ref>
<ref source="XF" url="http://xforce.iss.net/static/5920.php">wec-ntlm-authentication</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2199">2199</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0004" seq="2001-0004">
<status>Entry</status>
<desc>IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending &quot;%3F+.htr&quot; to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the &quot;File Fragment Reading via .HTR&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97897954625305&amp;w=2">20010108 IIS 5.0 allows viewing files using %3F+.htr</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-004.asp">MS01-004</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2313">2313</ref>
<ref source="XF" url="http://xforce.iss.net/static/5903.php">iis-read-files(5903)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0005" seq="2001-0005">
<status>Entry</status>
<desc>Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a012301-1.txt">A012301-1</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-002.asp">MS01-002</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5996">powerpoint-execute-code(5996)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0006" seq="2001-0006">
<status>Entry</status>
<desc>The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to &quot;No Access&quot; and disable Winsock network connectivity to cause a denial of service, aka the &quot;Winsock Mutex&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98075221915234&amp;w=2">20010126 ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-003.asp">MS01-003</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6006">winnt-mutex-dos(6006)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0007" seq="2001-0007">
<status>Entry</status>
<desc>Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/155149">20010109 NSFOCUS SA2001-01: NetScreen Firewall WebUI Buffer Overflow vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2176">2176</ref>
<ref source="XF" url="http://xforce.iss.net/static/5908.php">netscreen-webui-bo(5908)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1707">1707</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0008" seq="2001-0008">
<status>Entry</status>
<desc>Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2001-01.html">CA-2001-01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2192">2192</ref>
<ref source="XF" url="http://xforce.iss.net/static/5911.php">interbase-backdoor-account(5911)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0009" seq="2001-0009">
<status>Entry</status>
<desc>Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/154537">20010105 Lotus Domino 5.0.5 Web Server vulnerability - reading files outside the web root</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/155124">20010109 bugtraq id 2173 Lotus Domino Server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2173">2173</ref>
<ref source="XF" url="http://xforce.iss.net/static/5899.php">lotus-domino-directory-traversal(5899)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1703">1703</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0010" seq="2001-0010">
<status>Entry</status>
<desc>Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html">CA-2001-02</ref>
<ref source="IBM">ERS-SVA-E01-2001:002.1</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-026">DSA-026</ref>
<ref source="MANDRAKE">MDKSA-2001-017</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref>
<ref source="CONECTIVA">000377</ref>
<ref source="FREEBSD">FreeBSD-SA-01:18</ref>
<ref source="XF">bind-tsig-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2302">2302</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0011" seq="2001-0011">
<status>Entry</status>
<desc>Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html">CA-2001-02</ref>
<ref source="IBM">ERS-SVA-E01-2001:002.1</ref>
<ref source="MANDRAKE">MDKSA-2001-017</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref>
<ref source="CONECTIVA">000377</ref>
<ref source="FREEBSD">FreeBSD-SA-01:18</ref>
<ref source="XF">bind-complain-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2307">2307</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0012" seq="2001-0012">
<status>Entry</status>
<desc>BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html">CA-2001-02</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-026">DSA-026</ref>
<ref source="IBM">ERS-SVA-E01-2001:002.1</ref>
<ref source="MANDRAKE">MDKSA-2001-017</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref>
<ref source="CONECTIVA">000377</ref>
<ref source="FREEBSD">FreeBSD-SA-01:18</ref>
<ref source="XF">bind-inverse-query-disclosure</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2321">2321</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0013" seq="2001-0013">
<status>Entry</status>
<desc>Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html">CA-2001-02</ref>
<ref source="IBM">ERS-SVA-E01-2001:002.1</ref>
<ref source="MANDRAKE">MDKSA-2001-017</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref>
<ref source="CONECTIVA">000377</ref>
<ref source="FREEBSD">FreeBSD-SA-01:18</ref>
<ref source="XF">bind-complain-format-string</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2309">2309</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0014" seq="2001-0014">
<status>Entry</status>
<desc>Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the &quot;Invalid RDP Data&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-006.asp">MS01-006</ref>
<ref source="XF">win2k-rdp-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2326">2326</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0015" seq="2001-0015">
<status>Entry</status>
<desc>Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a &quot;WM_COPYDATA&quot; message to an invisible window that is running with the privileges of the WINLOGON process.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a020501-1.txt">A020501-1</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-007.asp">MS01-007</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2341">2341</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6062">win-dde-elevate-privileges(6062)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0016" seq="2001-0016">
<status>Entry</status>
<desc>NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.</desc>
<refs>
<ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_NTLMSSP.html">20010207 Local promotion vulnerability in NT4's NTLM Security Support Provider</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms01-008.asp">MS01-008</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2348">2348</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6076">ntlm-ssp-elevate-privileges(6076)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0017" seq="2001-0017">
<status>Entry</status>
<desc>Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the &quot;Malformed PPTP Packet Stream&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-009.asp">MS01-009</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2368">2368</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6103">winnt-pptp-dos(6103)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0018" seq="2001-0018">
<status>Entry</status>
<desc>Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.</desc>
<refs>
<ref source="VULN-DEV" url="http://online.securityfocus.com/archive/82/148411">20001202 UDP Ping-pong in Win2k</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms01-011.asp">MS01-011</ref>
<ref source="XF" url="http://xforce.iss.net/static/6136.php">win2k-domain-controller-dos(6136)</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-049.shtml">L-049</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0020" seq="2001-0020">
<status>Entry</status>
<desc>Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a013101-1.txt">A013101-1</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml">20010131 Cisco Content Services Switch Vulnerability</ref>
<ref source="XF" url="http://xforce.iss.net/static/6031.php">cisco-ccs-file-access(6031)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2331">2331</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1757">1757</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0021" seq="2001-0021">
<status>Entry</status>
<desc>MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0057.html">20001206 (SRADV00005) Remote command execution vulnerabilities in MailMan Webmail</ref>
<ref source="CONFIRM" url="http://www.endymion.com/products/mailman/history.htm">http://www.endymion.com/products/mailman/history.htm</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2063">2063</ref>
<ref source="XF" url="http://xforce.iss.net/static/5649.php">mailman-alternate-templates</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0026" seq="2001-0026">
<status>Entry</status>
<desc>rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0134.html">20001211 DoS vulnerability in rp-pppoe versions &lt;= 2.4</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000357">CLA-2000:357</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-084.php3">MDKSA-2000:084</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-130.html">RHSA-2000:130</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2098">2098</ref>
<ref source="XF" url="http://xforce.iss.net/static/5727.php">rppppoe-zero-length-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0028" seq="2001-0028">
<status>Entry</status>
<desc>Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of &quot; (quotation) characters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0127.html">20001211 [pkc] remote heap buffer overflow in oops</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-12/0418.html">FreeBSD-SA-00:79</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2099">2099</ref>
<ref source="XF" url="http://xforce.iss.net/static/5725.php">oops-ftputils-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0033" seq="2001-0033">
<status>Entry</status>
<desc>KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html">20001208 Vulnerabilities in KTH Kerberos IV</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html">20001210 KTH upgrade and FIX</ref>
<ref source="XF" url="http://xforce.iss.net/static/5738.php">kerberos4-user-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0034" seq="2001-0034">
<status>Entry</status>
<desc>KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html">20001208 Vulnerabilities in KTH Kerberos IV</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html">20001210 KTH upgrade and FIX</ref>
<ref source="XF" url="http://xforce.iss.net/static/5733.php">kerberos4-arbitrary-proxy</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0035" seq="2001-0035">
<status>Entry</status>
<desc>Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html">20001208 Vulnerabilities in KTH Kerberos IV</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html">20001210 KTH upgrade and FIX</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0511.html">20010130 Buffer overflow in old ssh-1.2.2x-afs-kerberosv4 patches</ref>
<ref source="XF" url="http://xforce.iss.net/static/5734.php">kerberos4-auth-packet-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0036" seq="2001-0036">
<status>Entry</status>
<desc>KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html">20001208 Vulnerabilities in KTH Kerberos IV</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html">20001210 KTH upgrade and FIX</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-025.html">RHSA-2001:025</ref>
<ref source="XF" url="http://xforce.iss.net/static/5754.php">kerberos4-tmpfile-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0039" seq="2001-0039">
<status>Entry</status>
<desc>IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0071.html">20001206 DoS by SMTP AUTH command in IPSwitch IMail server</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2083">2083</ref>
<ref source="CONFIRM" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/5674.php">imail-smtp-auth-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0040" seq="2001-0040">
<status>Entry</status>
<desc>APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0066.html">20001206 apcupsd 3.7.2 Denial of Service</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-077.php3">MDKSA-2000:077</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2070">2070</ref>
<ref source="XF" url="http://xforce.iss.net/static/5654.php">apc-apcupsd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0041" seq="2001-0041">
<status>Entry</status>
<desc>Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/catalyst-memleak-pub.shtml">20001206 Cisco Catalyst Memory Leak Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2072">2072</ref>
<ref source="XF" url="http://xforce.iss.net/static/5656.php">cisco-catalyst-telnet-dos</ref>
<ref source="OSVDB" url="http://www.osvdb.org/801">801</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0042" seq="2001-0042">
<status>Entry</status>
<desc>PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing &quot;%5c&quot; (encoded backslash) sequences.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/149210">20001206 CHINANSL Security Advisory(CSA-200011)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2060">2060</ref>
<ref source="XF" url="http://xforce.iss.net/static/5659.php">apache-php-disclose-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0043" seq="2001-0043">
<status>Entry</status>
<desc>phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0053.html">20001206 (SRADV00006) Remote command execution vulnerabilities in phpGroupWare</ref>
<ref source="MISC" url="http://sourceforge.net/project/shownotes.php?release_id=17604">http://sourceforge.net/project/shownotes.php?release_id=17604</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2069">2069</ref>
<ref source="XF" url="http://xforce.iss.net/static/5650.php">phpgroupware-include-files</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1682">1682</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0050" seq="2001-0050">
<status>Entry</status>
<desc>Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0081.html">20001207 BitchX DNS Overflow Patch</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0086.html">20001207 bitchx/ircd DNS overflow demonstration</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-126.html">RHSA-2000:126</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-079.php3">MDKSA-2000:079</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:78.bitchx.v1.1.asc">FreeBSD-SA-00:78</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000364">CLA-2000:364</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2087">2087</ref>
<ref source="XF" url="http://xforce.iss.net/static/5701.php">irc-bitchx-dns-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0053" seq="2001-0053">
<status>Entry</status>
<desc>One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.</desc>
<refs>
<ref source="OPENBSD" url="http://www.openbsd.org/advisories/ftpd_replydirname.txt">20001218</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc">NetBSD-SA2000-018</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0275.html">20001218 Trustix Security Advisory - ed, tcsh, and ftpd-BSD</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2124">2124</ref>
<ref source="XF" url="http://xforce.iss.net/static/5776.php">bsd-ftpd-replydirname-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0054" seq="2001-0054">
<status>Entry</status>
<desc>Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as &quot;/..%20.&quot; to a CD command, a variant of a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97604119024280&amp;w=2">20001205 Serv-U FTP directory traversal vunerability (all versions)</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0043.html">20001205 (no subject)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2052">2052</ref>
<ref source="XF" url="http://xforce.iss.net/static/5639.php">ftp-servu-homedir-travers</ref>
<ref source="OSVDB" url="http://www.osvdb.org/464">464</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0055" seq="2001-0055">
<status>Entry</status>
<desc>CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml">20001204 Multiple Vulnerabilities in CBOS</ref>
<ref source="XF" url="http://xforce.iss.net/static/5627.php">cisco-cbos-syn-packets</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0056" seq="2001-0056">
<status>Entry</status>
<desc>The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml">20001204 Multiple Vulnerabilities in CBOS</ref>
<ref source="XF" url="http://xforce.iss.net/static/5628.php">cisco-cbos-invalid-login</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0057" seq="2001-0057">
<status>Entry</status>
<desc>Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml">20001204 Multiple Vulnerabilities in CBOS</ref>
<ref source="XF" url="http://xforce.iss.net/static/5629.php">cisco-cbos-icmp-echo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0058" seq="2001-0058">
<status>Entry</status>
<desc>The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml">20001204 Multiple Vulnerabilities in CBOS</ref>
<ref source="XF" url="http://xforce.iss.net/static/5626.php">cisco-cbos-web-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/460">460</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0059" seq="2001-0059">
<status>Entry</status>
<desc>patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97720205217707&amp;w=2">20001218 Solaris patchadd(1)  (3) symlink vulnerabilty</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2127">2127</ref>
<ref source="XF" url="http://xforce.iss.net/static/5789.php">solaris-patchadd-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0060" seq="2001-0060">
<status>Entry</status>
<desc>Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/151719">20001218 Stunnel format bug</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-129.html">RHSA-2000:129</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000363">CLA-2000:363</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0337.html">20001209 Trustix Security Advisory - stunnel</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-009">DSA-009</ref>
<ref source="FREEBSD">FreeBSD-SA-01:05</ref>
<ref source="XF" url="http://xforce.iss.net/static/5807.php">stunnel-format-logfile</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2128">2128</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0061" seq="2001-0061">
<status>Entry</status>
<desc>procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains access to the child's address space.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc">FreeBSD-SA-00:77</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2130">2130</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6106">procfs-elevate-privileges(6106)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1697">1697</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0062" seq="2001-0062">
<status>Entry</status>
<desc>procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to hang.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc">FreeBSD-SA-00:77</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2131">2131</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6107">procfs-mmap-dos(6107)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1698">1698</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6082">6082</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0063" seq="2001-0063">
<status>Entry</status>
<desc>procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc">FreeBSD-SA-00:77</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2132">2132</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6108">procfs-access-control-bo(6108)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1691">1691</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0066" seq="2001-0066">
<status>Entry</status>
<desc>Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0356.html">20001126 [MSY] S(ecure)Locate heap corruption vulnerability</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001217a">DSA-005-1</ref>
<ref source="DEBIAN">20001217a</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-085.php3">MDKSA-2000:085</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-128.html">RHSA-2000:128</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000369">CLA-2001:369</ref>
<ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2001-February/000144.html">TLSA2001002-1</ref>
<ref source="XF" url="http://xforce.iss.net/static/5594.php">slocate-heap-execute-code(5594)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2004">2004</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0069" seq="2001-0069">
<status>Entry</status>
<desc>dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001225">DSA-008-1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2151">2151</ref>
<ref source="XF" url="http://xforce.iss.net/static/5809.php">dialog-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0071" seq="2001-0071">
<status>Entry</status>
<desc>gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-131.html">RHSA-2000:131</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3">MDKSA-2000-087</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001225b">DSA-010-1</ref>
<ref source="XF" url="http://xforce.iss.net/static/5802.php">gnupg-detached-sig-modify</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000368">CLA-2000:368</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2141">2141</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/152197">20001220 Trustix Security Advisory - gnupg, ftpd-BSD</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1699">1699</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0072" seq="2001-0072">
<status>Entry</status>
<desc>gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.</desc>
<refs>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-131.html">RHSA-2000:131</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3">MDKSA-2000-087</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001225b">DSA-010-1</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000368">CLA-2000:368</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/152197">20001220 Trustix Security Advisory - gnupg, ftpd-BSD</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2153">2153</ref>
<ref source="XF" url="http://xforce.iss.net/static/5803.php">gnupg-reveal-private</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1702">1702</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0077" seq="2001-0077">
<status>Entry</status>
<desc>The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html">20001212 Two Holes in Sun Cluster 2.x</ref>
<ref source="XF" url="http://xforce.iss.net/static/6123.php">clustmon-no-authentication(6123)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0078" seq="2001-0078">
<status>Entry</status>
<desc>in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html">20001212 Two Holes in Sun Cluster 2.x</ref>
<ref source="XF" url="http://xforce.iss.net/static/6125.php">ha-nfs-symlink(6125)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6437">6437</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0080" seq="2001-0080">
<status>Entry</status>
<desc>Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/707/catalyst-ssh-protocolmismatch-pub.shtml">20001213 Cisco Catalyst SSH Protocol Mismatch Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2117">2117</ref>
<ref source="XF" url="http://xforce.iss.net/static/5760.php">cisco-catalyst-ssh-mismatch</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0081" seq="2001-0081">
<status>Entry</status>
<desc>swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0152.html">20001212 nCipher Security Advisory: Operator Cards unexpectedly recoverable</ref>
<ref source="CONFIRM" url="http://active.ncipher.com/updates/advisory.txt">http://active.ncipher.com/updates/advisory.txt</ref>
<ref source="XF" url="http://xforce.iss.net/static/5999.php">ncipher-recover-operator-cards(5999)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4849">4849</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0083" seq="2001-0083">
<status>Entry</status>
<desc>Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the &quot;Severed Windows Media Server Connection&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-097.asp">MS00-097</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q281256">Q281256</ref>
<ref source="XF" url="http://xforce.iss.net/static/5785.php">mediaservices-dropped-connection-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0085" seq="2001-0085">
<status>Entry</status>
<desc>Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0083.html">HPSBUX0012-135</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2170">2170</ref>
<ref source="XF" url="http://xforce.iss.net/static/5793.php">hpux-kermit-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0089" seq="2001-0089">
<status>Entry</status>
<desc>Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the &quot;File Upload via Form&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp">MS00-093</ref>
<ref source="XF" url="http://xforce.iss.net/static/5615.php">ie-form-file-upload</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0090" seq="2001-0090">
<status>Entry</status>
<desc>The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the &quot;Browser Print Template&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp">MS00-093</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2046">2046</ref>
<ref source="XF" url="http://xforce.iss.net/static/5614.php">ie-print-template(5614)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0091" seq="2001-0091">
<status>Entry</status>
<desc>The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the &quot;Scriptlet Rendering&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp">MS00-093</ref>
<ref source="XF" url="http://xforce.iss.net/static/6085.php">ie-scriptlet-rendering-read-files(6085)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7820">7820</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0092" seq="2001-0092">
<status>Entry</status>
<desc>A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the &quot;Frame Domain Verification&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp">MS00-093</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6086">ie-frame-verification-read-files(6086)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7817">7817</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0094" seq="2001-0094">
<status>Entry</status>
<desc>Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.</desc>
<refs>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-017.txt.asc">NetBSD-SA2000-017</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:25.kerberosIV.asc">FreeBSD-SA-01:25</ref>
<ref source="XF" url="http://xforce.iss.net/static/5734.php">kerberos4-auth-packet-overflow(5734)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0095" seq="2001-0095">
<status>Entry</status>
<desc>catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0313.html">20001218 Catman file clobbering vulnerability Solaris 2.x</ref>
<ref source="SUNBUG">4392144</ref>
<ref source="XF" url="http://xforce.iss.net/static/5788.php">solaris-catman-symlink(5788)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6024">6024</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0096" seq="2001-0096">
<status>Entry</status>
<desc>FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the &quot;Malformed Web Form Submission&quot; vulnerability.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-100.asp">MS00-100</ref>
<ref source="XF" url="http://xforce.iss.net/static/5823.php">iis-web-form-submit</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0099" seq="2001-0099">
<status>Entry</status>
<desc>bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html">20001221 BS Scripts Vulnerabilities</ref>
<ref source="MISC" url="http://www.stanback.net/">http://www.stanback.net/</ref>
<ref source="XF" url="http://xforce.iss.net/static/5796.php">bsguest-cgi-execute-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0100" seq="2001-0100">
<status>Entry</status>
<desc>bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html">20001221 BS Scripts Vulnerabilities</ref>
<ref source="MISC" url="http://www.stanback.net/">http://www.stanback.net/</ref>
<ref source="XF" url="http://xforce.iss.net/static/5797.php">bslist-cgi-execute-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0105" seq="2001-0105">
<status>Entry</status>
<desc>Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the &quot;sys&quot; group.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0079.html">HPSBUX0012-134</ref>
<ref source="XF" url="http://xforce.iss.net/static/5773.php">hp-top-sys-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0106" seq="2001-0106">
<status>Entry</status>
<desc>Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the &quot;swait&quot; state is used by a server.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0009.html">HPSBUX0101-136</ref>
<ref source="XF" url="http://xforce.iss.net/static/5904.php">hp-inetd-swait-dos(5904)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0108" seq="2001-0108">
<status>Entry</status>
<desc>PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97957961212852">20010112 PHP Security Advisory - Apache Module bugs</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-013.php3">MDKSA-2001:013</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000373">CLA-2001:373</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-020">DSA-020</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-136.html">RHSA-2000:136</ref>
<ref source="XF" url="http://xforce.iss.net/static/5940.php">php-htaccess-unauth-access(5940)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2206">2206</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0109" seq="2001-0109">
<status>Entry</status>
<desc>rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0226.html">20010113 Serious security flaw in SuSE rctab</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0272.html">20010117 Re: Serious security flaw in SuSE rctab</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2207">2207</ref>
<ref source="XF" url="http://xforce.iss.net/static/5945.php">rctab-elevate-privileges(5945)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0110" seq="2001-0110">
<status>Entry</status>
<desc>Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0228.html">20010114 Vulnerability in jaZip.</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-017">DSA-017</ref>
<ref source="XF" url="http://xforce.iss.net/static/5942.php">jazip-display-bo(5942)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2209">2209</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0111" seq="2001-0111">
<status>Entry</status>
<desc>Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958269320974&amp;w=2">20010114 [MSY] Multiple vulnerabilities in splitvt</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-014">DSA-014-1</ref>
<ref source="XF" url="http://xforce.iss.net/static/5948.php">splitvt-perserc-format-string(5948)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2210">2210</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0115" seq="2001-0115">
<status>Entry</status>
<desc>Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97934312727101&amp;w=2">20010111 Solaris Arp Vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97957435729702&amp;w=2">20010112 arp exploit</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/200&amp;type=0&amp;nav=sec.sba">00200</ref>
<ref source="XF" url="http://xforce.iss.net/static/5928.php">solaris-arp-bo(5928)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2193">2193</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0116" seq="2001-0116">
<status>Entry</status>
<desc>gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-006.php3">MDKSA-2001:006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2188">2188</ref>
<ref source="XF" url="http://xforce.iss.net/static/5917.php">linux-gpm-symlink(5917)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0117" seq="2001-0117">
<status>Entry</status>
<desc>sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2000-70-028-01">IMNX-2000-70-028-01</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-008.php3">MDKSA-2001:008-1</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-116.html">RHSA-2001:116</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/579928">VU#579928</ref>
<ref source="XF" url="http://xforce.iss.net/static/5914.php">linux-diffutils-sdiff-symlink(5914)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2191">2191</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0118" seq="2001-0118">
<status>Entry</status>
<desc>rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-005.php3">MDKSA-2001-005</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2195">2195</ref>
<ref source="XF" url="http://xforce.iss.net/static/5925.php">rdist-symlink(5925)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0119" seq="2001-0119">
<status>Entry</status>
<desc>getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-004.php3">MDKSA-2001:004</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2194">2194</ref>
<ref source="XF" url="http://xforce.iss.net/static/5924.php">gettyps-symlink(5924)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0120" seq="2001-0120">
<status>Entry</status>
<desc>useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-007.php3">MDKSA-2001:007</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2196">2196</ref>
<ref source="XF" url="http://xforce.iss.net/static/5927.php">shadow-utils-useradd-symlink(5927)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0121" seq="2001-0121">
<status>Entry</status>
<desc>ImageCast Control Center 4.1.0 allows remote attackers to cause a denial of service (resource exhaustion or system crash) via a long string to port 12002.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0071.html">20010108 def-2001-01: ImageCast IC3 Control Center DoS</ref>
<ref source="XF" url="http://xforce.iss.net/static/5901.php">storagesoft-imagecast-dos(5901)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2174">2174</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0122" seq="2001-0122">
<status>Entry</status>
<desc>Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a &quot;bad request&quot; error.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0079.html">20010108 def-2001-02: IBM Websphere 3.52 Kernel Leak DoS </ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0061.html">20010307 def-2001-02: IBM HTTP Server Kernel Leak DoS (re-release)</ref>
<ref source="CONFIRM" url="http://www-4.ibm.com/software/webservers/security.html">http://www-4.ibm.com/software/webservers/security.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2175">2175</ref>
<ref source="XF" url="http://xforce.iss.net/static/5900.php">ibm-websphere-dos(5900)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0123" seq="2001-0123">
<status>Entry</status>
<desc>Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97905792214999&amp;w=2">20010107 Cgisecurity.com Advisory #3.1</ref>
<ref source="CONFIRM" url="http://www.extropia.com/hacks/bbs_security.html">http://www.extropia.com/hacks/bbs_security.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2177">2177</ref>
<ref source="XF" url="http://xforce.iss.net/static/5906.php">http-cgi-bbs-forum(5906)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3546">3546</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0124" seq="2001-0124">
<status>Entry</status>
<desc>Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97908386502156&amp;w=2">20010109 Solaris /usr/lib/exrecover buffer overflow</ref>
<ref source="SUNBUG">4161925</ref>
<ref source="XF" url="http://xforce.iss.net/static/5913.php">solaris-exrecover-bo(5913)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2179">2179</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0125" seq="2001-0125">
<status>Entry</status>
<desc>exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97846489313059&amp;w=2">20001231 Advisory: exmh symlink vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958594330100&amp;w=2">20010112 exmh security vulnerability</ref>
<ref source="CONFIRM" url="http://www.beedub.com/exmh/symlink.html">http://www.beedub.com/exmh/symlink.html</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-01/0543.html">FreeBSD-SA-01:17</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-015.php3">MDKSA-2001:015</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-022">DSA-022</ref>
<ref source="XF" url="http://xforce.iss.net/static/5829.php">exmh-error-symlink</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0126" seq="2001-0126">
<status>Entry</status>
<desc>Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97906670012796&amp;w=2">20010109 Oracle XSQL servlet and xml-stylesheet allow executing java on the web server </ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98027700625521&amp;w=2">20010123 Patch for Potential Vulnerability in Oracle XSQL Servlet</ref>
<ref source="XF" url="http://xforce.iss.net/static/5905.php">oracle-xsql-execute-code(5905)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0128" seq="2001-0128">
<status>Entry</status>
<desc>Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.</desc>
<refs>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-083.php3">MDKSA-2000-083</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000365">CLA-2000:365</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-127.html">RHSA-2000:127</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2000/20001219">DSA-006-1</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:06.zope.asc">FreeBSD-SA-01:06</ref>
<ref source="XF" url="http://xforce.iss.net/static/5777.php">zope-calculate-roles</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6284">6284</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0129" seq="2001-0129">
<status>Entry</status>
<desc>Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97975486527750&amp;w=2">20010117 [pkc] remote heap overflow in tinyproxy</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-018">DSA-018</ref>
<ref source="FREEBSD">FreeBSD-SA-01:15</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2217">2217</ref>
<ref source="XF" url="http://xforce.iss.net/static/5954.php">tinyproxy-remote-bo(5954)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0130" seq="2001-0130">
<status>Entry</status>
<desc>Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier.</desc>
<refs>
<ref source="MISC" url="http://service1.symantec.com/sarc/sarc.nsf/info/html/Lotus.Domino.Denial.of.Service.Malformed.HTML.Email.html">http://service1.symantec.com/sarc/sarc.nsf/info/html/Lotus.Domino.Denial.of.Service.Malformed.HTML.Email.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/6207.php">lotus-html-bo(6207)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0136" seq="2001-0136">
<status>Entry</status>
<desc>Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/152206">20001220 ProFTPD 1.2.0 Memory leakage - denial of service</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0122.html">20010109 Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code) </ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0132.html">20010110 Re: Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code) </ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3">MDKSA-2001:021</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-029">DSA-029</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000380">CLA-2001:380</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html">20010213 Trustix Security Advisory - proftpd, kernel</ref>
<ref source="XF" url="http://xforce.iss.net/static/5801.php">proftpd-size-memory-leak</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0137" seq="2001-0137">
<status>Entry</status>
<desc>Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958100816503&amp;w=2">20010115 Windows Media Player 7 and IE java vulnerability - executing arbitrary programs </ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-010.asp">MS01-010</ref>
<ref source="XF" url="http://xforce.iss.net/static/5937.php">win-mediaplayer-arbitrary-code(5937)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2203">2203</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0138" seq="2001-0138">
<status>Entry</status>
<desc>privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-001.php3">MDKSA-2001-001</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-016">DSA-016</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2189">2189</ref>
<ref source="XF" url="http://xforce.iss.net/static/5915.php">linux-wuftpd-privatepw-symlink(5915)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0139" seq="2001-0139">
<status>Entry</status>
<desc>inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-010.php3">MDKSA-2001:010</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-001.0.txt">CSSA-2001-001.0</ref>
<ref source="XF" url="http://xforce.iss.net/static/5916.php">linux-inn-symlink(5916)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2190">2190</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0140" seq="2001-0140">
<status>Entry</status>
<desc>arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-002.php3">MDKSA-2001:002</ref>
<ref source="XF" url="http://xforce.iss.net/static/5922.php">tcpdump-arpwatch-symlink(5922)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2183">2183</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0141" seq="2001-0141">
<status>Entry</status>
<desc>mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-009.php3">MDKSA-2001:009</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-011">DSA-011</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-002.0.txt">CSSA-2001-002.0</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-050.html">RHSA-2001:050</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2187">2187</ref>
<ref source="XF" url="http://xforce.iss.net/static/5918.php">linux-mgetty-symlink(5918)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0142" seq="2001-0142">
<status>Entry</status>
<desc>squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0212.html">20010112 Trustix Security Advisory - diffutils squid</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-003.php3">MDKSA-2001:003</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-019">DSA-019</ref>
<ref source="XF" url="http://xforce.iss.net/static/5921.php">squid-email-symlink(5921)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2184">2184</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0143" seq="2001-0143">
<status>Entry</status>
<desc>vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-011.php3">MDKSA-2001:011</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2186">2186</ref>
<ref source="XF" url="http://xforce.iss.net/static/5923.php">linuxconf-vpop3d-symlink(5923)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0144" seq="2001-0144">
<status>Entry</status>
<desc>CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.</desc>
<refs>
<ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_ssh1crc.html">20010208 Remote vulnerability in SSH daemon crc32 compensation attack detector</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98168366406903&amp;w=2">20010208 [CORE SDI ADVISORY] SSH1 CRC-32 compensation attack detector</ref>
<ref source="BUGTRAQ">20011122 Secure Computing SafeWord uses vulnerable ssh server</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2001-35.html">CA-2001-35</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2347">2347</ref>
<ref source="OSVDB" url="http://www.osvdb.org/503">503</ref>
<ref source="OSVDB" url="http://www.osvdb.org/795">795</ref>
<ref source="XF" url="http://xforce.iss.net/static/6083.php">ssh-deattack-overwrite-memory(6083)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0147" seq="2001-0147">
<status>Entry</status>
<desc>Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-013.asp">MS01-013</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0148" seq="2001-0148">
<status>Entry</status>
<desc>The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the &quot;Frame Domain Verification&quot; vulnerability.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0000.html">20010101 Windows Media Player 7 and IE vulnerability - executing arbitrary programs</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp">MS01-015</ref>
<ref source="XF" url="http://xforce.iss.net/static/6227.php">media-player-execute-commands(6227)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0149" seq="2001-0149">
<status>Entry</status>
<desc>Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0305.html">20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=96999020527583&amp;w=2">20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp">MS01-015</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1718">1718</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5293">ie-getobject-expose-files(5293)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0150" seq="2001-0150">
<status>Entry</status>
<desc>Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.</desc>
<refs>
<ref source="BUGTRAQ">20010313 Internet Explorer and Services for Unix 2.0 Telnet Client</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp">MS01-015</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2463">2463</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7816">7816</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6230">ie-telnet-execute-commands(6230)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0151" seq="2001-0151">
<status>Entry</status>
<desc>IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-016.asp">MS01-016</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6205">iis-webdav-dos(6205)</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:90">oval:org.mitre.oval:def:90</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0152" seq="2001-0152">
<status>Entry</status>
<desc>The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms01-019.asp">MS01-019</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0153" seq="2001-0153">
<status>Entry</status>
<desc>Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_vbtsql.html">20010327 Remote buffer overflow in DCOM VB T-SQL debugger</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-018.asp">MS01-018</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0154" seq="2001-0154">
<status>Entry</status>
<desc>HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98596775905044&amp;w=2">20010330 Incorrect MIME Header Can Cause IE to Execute E-mail Attachment</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-020.asp">MS01-020</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2001-06.html">CA-2001-06</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-066.shtml">L-066</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2524">2524</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7806">7806</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:141">oval:org.mitre.oval:def:141</ref>
<ref source="SECTRACK" url="http://securitytracker.com/id?1001197">1001197</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6306">ie-mime-execute-code(6306)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0155" seq="2001-0155">
<status>Entry</status>
<desc>Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a021601-1.txt">A021601-1</ref>
<ref source="CONFIRM" url="http://www.vandyke.com/products/vshell/security102.html">http://www.vandyke.com/products/vshell/security102.html</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0156" seq="2001-0156">
<status>Entry</status>
<desc>VShell SSH gateway 1.0.1 and earlier has a default port forwarding rule of 0.0.0.0/0.0.0.0, which could allow local users conduct arbitrary port forwarding to other systems.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a021601-1.txt">A021601-1</ref>
<ref source="CONFIRM" url="http://www.vandyke.com/products/vshell/security102.html">http://www.vandyke.com/products/vshell/security102.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/6148.php">vshell-port-forwarding-rule(6148)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2402">2402</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0157" seq="2001-0157">
<status>Entry</status>
<desc>Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even if the system lockout mechanism is enabled.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a030101-1.txt">A030101-1</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6196">palm-debug-bypass-password(6196)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0164" seq="2001-0164">
<status>Entry</status>
<desc>Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field.</desc>
<refs>
<ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2001/a030701-1.txt">A030701-1</ref>
<ref source="XF" url="http://xforce.iss.net/static/6233.php">netscape-directory-server-bo(6233)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0165" seq="2001-0165">
<status>Entry</status>
<desc>Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long &quot;arg0&quot; (process name) argument.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0517.html">20010131 [SPSadvisory#40]Solaris7/8 ximp40 shared library buffer overflow</ref>
<ref source="SUNBUG">4409148</ref>
<ref source="XF" url="http://xforce.iss.net/static/6039.php">solaris-ximp40-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2322">2322</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0166" seq="2001-0166">
<status>Entry</status>
<desc>Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0491.html">20001229 Shockwave Flash buffer overflow</ref>
<ref source="XF" url="http://xforce.iss.net/static/5826.php">shockwave-flash-swf-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0169" seq="2001-0169">
<status>Entry</status>
<desc>When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.</desc>
<refs>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-012.php3?dis=7.2">MDKSA-2001:012</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_001_glibc_txt.html">SuSE-SA:2001:01</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-007.0.txt">CSSA-2001-007</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-002.html">RHSA-2001:002</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-039">DSA-039</ref>
<ref source="TURBO" url="http://archives.neohapsis.com/archives/linux/turbolinux/2001-q1/0004.html">TLSA2000021-2</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/157650">20010121 Trustix Security Advisory - glibc</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2223">2223</ref>
<ref source="XF" url="http://xforce.iss.net/static/5971.php">linux-glibc-preload-overwrite</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0170" seq="2001-0170">
<status>Entry</status>
<desc>glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0131.html">20010110 Glibc Local Root Exploit</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0186.html">20010110 [slackware-security] glibc 2.2 local vulnerability on setuid binaries</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-001.html">RHSA-2001:001</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2181">2181</ref>
<ref source="XF" url="http://xforce.iss.net/static/5907.php">linux-glibc-read-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0174" seq="2001-0174">
<status>Entry</status>
<desc>Buffer overflow in Trend Micro Virus Buster 2001 8.00 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a large &quot;To&quot; address.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0500.html">20010130 Security hole in Virus Buster 2001</ref>
<ref source="XF" url="http://xforce.iss.net/static/6034.php">virusbuster-mua-bo(6034)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6138">6138</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0175" seq="2001-0175">
<status>Entry</status>
<desc>The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98021351718874&amp;w=2">20010122 def-2001-05: Netscape Fasttrack Server Caching DoS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98035833331446&amp;w=2">20010124 iPlanet FastTrack/Enterprise 4.1 DoS clarifications</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2273">2273</ref>
<ref source="XF" url="http://xforce.iss.net/static/5985.php">netscape-fasttrack-cache-dos(5985)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0176" seq="2001-0176">
<status>Entry</status>
<desc>The setuid doroot program in Voyant Sonata 3.x executes arbitrary command line arguments, which allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0278.html">20001218 More Sonata Conferencing software vulnerabilities.</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2125">2125</ref>
<ref source="XF" url="http://xforce.iss.net/static/5787.php">sonata-command-execute(5787)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0178" seq="2001-0178">
<status>Entry</status>
<desc>kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.</desc>
<refs>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-018.php3?dis=7.2">MDKSA-2001:018</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt">CSSA-2001-005.0</ref>
<ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_002_kdesu_txt.html">SuSE-SA:2001:02</ref>
<ref source="XF" url="http://xforce.iss.net/static/5995.php">kde2-kdesu-retrieve-passwords</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0179" seq="2001-0179">
<status>Entry</status>
<desc>Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a &quot;.&quot;</desc>
<refs>
<ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=19546&amp;Method=Full">ASB01-02</ref>
<ref source="XF" url="http://xforce.iss.net/static/6008.php">jrun-webinf-file-retrieval</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0182" seq="2001-0182">
<status>Entry</status>
<desc>FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0298.html">20010117 Licensing Firewall-1 DoS Attack</ref>
<ref source="XF" url="http://xforce.iss.net/static/5966.php">fw1-limited-license-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2238">2238</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1733">1733</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0183" seq="2001-0183">
<status>Entry</status>
<desc>ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/2001-01/0424.html">20010125 ecepass - proof of concept code for FreeBSD ipfw bypass</ref>
<ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:08.ipfw.asc">FreeBSD-SA-01:08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-029.shtml">L-029</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2293">2293</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1743">1743</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5998">ipfw-bypass-firewall(5998)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0185" seq="2001-0185">
<status>Entry</status>
<desc>Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a crash.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/157952">20010123 Make The Netopia R9100 Router To Crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2287">2287</ref>
<ref source="XF" url="http://xforce.iss.net/static/6001.php">netopia-telnet-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0187" seq="2001-0187">
<status>Entry</status>
<desc>Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-016">DSA-016</ref>
<ref source="CONFIRM" url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000443">CLA-2001:443</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2296">2296</ref>
<ref source="XF" url="http://xforce.iss.net/static/6020.php">wuftp-debug-format-string</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0189" seq="2001-0189">
<status>Entry</status>
<desc>Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP GET request.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0346.html">20010119 LocalWEB2000 Directory Traversal Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2268">2268</ref>
<ref source="XF" url="http://xforce.iss.net/static/5982.php">localweb2k-directory-traversal</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0190" seq="2001-0190">
<status>Entry</status>
<desc>Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97983943716311&amp;w=2">20010117 Solaris /usr/bin/cu Vulnerability</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98028642319440&amp;w=2">20010123 Solaris /usr/bin/cu Vulnerability</ref>
<ref source="SUNBUG">4406722</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6224">cu-argv-bo(6224)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0191" seq="2001-0191">
<status>Entry</status>
<desc>gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0030.html">20010202 Remote vulnerability in gnuserv/XEmacs</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-010.html">RHSA-2001:010</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-011.html">RHSA-2001:011</ref>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-019.php3">MDKSA-2001:019</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6056">gnuserv-tcp-cookie-overflow(6056)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0193" seq="2001-0193">
<status>Entry</status>
<desc>Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98096782126481&amp;w=2">20010131 SuSe / Debian man package format string vulnerability</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-028">DSA-028</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2327">2327</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6059">man-i-format-string(6059)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0194" seq="2001-0194">
<status>Entry</status>
<desc>Buffer overflow in httpGets function in CUPS 1.1.5 allows remote attackers to execute arbitrary commands via a long input line.</desc>
<refs>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-020.php3">MDKSA-2001:020-1</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6043">cups-httpgets-dos(6043)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6064">6064</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0195" seq="2001-0195">
<status>Entry</status>
<desc>sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-015">DSA-015</ref>
<ref source="XF" url="http://xforce.iss.net/static/5994.php">linux-sash-shadow-readable</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0196" seq="2001-0196">
<status>Entry</status>
<desc>inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.</desc>
<refs>
<ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:11.inetd.v1.1.asc">FreeBSD-SA-01:11</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2324">2324</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6052">inetd-ident-read-files(6052)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1753">1753</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0197" seq="2001-0197">
<status>Entry</status>
<desc>Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0348.html">20010121 [pkc] format bugs in icecast 1.3.8b2 and prior</ref>
<ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000374">CLA-2001:374</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-004.html">RHSA-2001:004</ref>
<ref source="XF" url="http://xforce.iss.net/static/5978.php">icecast-format-string</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2264">2264</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0203" seq="2001-0203">
<status>Entry</status>
<desc>Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0342.html">20010120 Watchguard Firewall Elevated Privilege Vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2284">2284</ref>
<ref source="XF" url="http://xforce.iss.net/static/5979.php">watchguard-firebox-obtain-passphrase</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0204" seq="2001-0204">
<status>Entry</status>
<desc>Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/162965">20010214 def-2001-07: Watchguard Firebox II PPTP DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2369">2369</ref>
<ref source="XF" url="http://xforce.iss.net/static/6109.php">firebox-pptp-dos(6109)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0207" seq="2001-0207">
<status>Entry</status>
<desc>Buffer overflow in bing allows remote attackers to execute arbitrary commands via a long hostname, which is copied to a small buffer after a reverse DNS lookup using the gethostbyaddr function.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0330.html">20010119 Buffer overflow in bing</ref>
<ref source="XF" url="http://xforce.iss.net/static/6036.php">linux-bing-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2279">2279</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0215" seq="2001-0215">
<status>Entry</status>
<desc>ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0213.html">20010212 ROADS search system &quot;show files&quot; Vulnerability with &quot;null bite&quot; bug</ref>
<ref source="CONFIRM" url="http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html">http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html</ref>
<ref source="XF" url="http://xforce.iss.net/static/6097.php">roads-search-view-files(6097)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2371">2371</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0218" seq="2001-0218">
<status>Entry</status>
<desc>Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0456.html">20010126 format string vulnerability in mars_nwe 0.99pl19</ref>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0081.html">FreeBSD-SA-01:20</ref>
<ref source="XF" url="http://xforce.iss.net/static/6019.php">mars-nwe-format-string(6019)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0219" seq="2001-0219">
<status>Entry</status>
<desc>Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial of service.</desc>
<refs>
<ref source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0016.html">HPSBUX0101-137</ref>
<ref source="XF" url="http://xforce.iss.net/static/5957.php">hp-stm-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2239">2239</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6991">6991</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7029">7029</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7030">7030</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0221" seq="2001-0221">
<status>Entry</status>
<desc>Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.</desc>
<refs>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0079.html">FreeBSD-SA-01:19</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6073">ja-xklock-bo(6073)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0222" seq="2001-0222">
<status>Entry</status>
<desc>webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack.</desc>
<refs>
<ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-016.php3">MDKSA-2001-016</ref>
<ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-004.0.txt">CSSA-2001-004.0</ref>
<ref source="XF" url="http://xforce.iss.net/static/6011.php">linux-webmin-tmpfiles</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0230" seq="2001-0230">
<status>Entry</status>
<desc>Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.</desc>
<refs>
<ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0083.html">FreeBSD-SA-01:22</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6077">dc20ctrl-port-bo(6077)</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6081">6081</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0233" seq="2001-0233">
<status>Entry</status>
<desc>Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0395.html">20010124 patch Re: [PkC] Advisory #003: micq-0.4.6 remote buffer overflow</ref>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0307.html">20010118 [PkC] Advisory #003: micq-0.4.6 remote buffer overflow</ref>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-012">DSA-012</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:14.micq.asc">FreeBSD-SA-01:14</ref>
<ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-005.html">RHSA-2001:005</ref>
<ref source="XF" url="http://xforce.iss.net/static/5962.php">micq-sprintf-remote-bo(5962)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0234" seq="2001-0234">
<status>Entry</status>
<desc>NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0460.html">20010126 NewsDaemon remote administrator access</ref>
<ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=60570">http://sourceforge.net/forum/forum.php?forum_id=60570</ref>
<ref source="XF" url="http://xforce.iss.net/static/6010.php">newsdaemon-gain-admin-access</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0235" seq="2001-0235">
<status>Entry</status>
<desc>Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running.</desc>
<refs>
<ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-024">DSA-024</ref>
<ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:09.crontab.v1.1.asc">FreeBSD-SA-01:09</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2332">2332</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6225">crontab-read-files(6225)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0236" seq="2001-0236">
<status>Entry</status>
<desc>Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long &quot;indication&quot; event.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98462536724454&amp;w=2">20010314 Solaris /usr/lib/dmi/snmpXdmid vulnerability</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2001-05.html">CA-2001-05</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-065.shtml">L-065</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/207">00207</ref>
<ref source="XF" url="http://xforce.iss.net/static/6245.php">solaris-snmpxdmid-bo(6245)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2417">2417</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0237" seq="2001-0237">
<status>Entry</status>
<desc>Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98942093221908&amp;w=2">20010509 def-2001-24: Windows 2000 Kerberos DoS</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms01-024.asp">MS01-024</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-079.shtml">L-079</ref>
<ref source="XF" url="http://xforce.iss.net/static/6506.php">win2k-kerberos-dos(6506)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2707">2707</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0238" seq="2001-0238">
<status>Entry</status>
<desc>Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-022.asp">MS01-022</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-074.shtml">L-074</ref>
<ref source="XF" url="http://xforce.iss.net/static/6405.php">ms-dacipp-webdav-access(6405)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0239" seq="2001-0239">
<status>Entry</status>
<desc>Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176912">20010416 [SX-20010320-2] - Microsoft ISA Server Denial of Service</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/179986">20010427 Microsoft ISA Server Vulnerability</ref>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/177160">20010417 [SX-20010320-2b] - Followup re. Microsoft ISA Server Denial of Service</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-021.asp">MS01-021</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-073.shtml">L-073</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2600">2600</ref>
<ref source="XF" url="http://xforce.iss.net/static/6383.php">isa-web-proxy-dos(6383)</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0240" seq="2001-0240">
<status>Entry</status>
<desc>Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms01-028.asp">MS01-028</ref>
<ref source="XF" url="http://xforce.iss.net/static/6571.php">word-rtf-macro-execution(6571)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2753">2753</ref>
</refs>
</item>

<item type="CVE" name="CVE-2001-0241" seq="2001-0241">
<status>Entry</status>
<desc>Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98874912915948&amp;w=2">20010501 Windows 2000 IIS 5.0 Remote buffer overflow vulnerability (Remote SYSTEM Level Access)</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms01-023.asp">MS01-023</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-2001-10.html">CA-2001-10</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2674">2674</ref>