CVE No. |
Description |
SARA Test |
| CVE-1999-0002 |
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems. |
rpc(mountd) check |
| CVE-1999-0003 |
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd) |
rpc(tooltalk) check |
| CVE-1999-0005 |
Arbitrary command execution via IMAP buffer overflow in authenticate command. |
imap version check |
| CVE-1999-0006 |
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command. |
pop version check |
| CVE-1999-0008 |
Buffer overflow in NIS+, in Sun's rpc.nisd program |
rpc(nisd) check |
| CVE-1999-0009 |
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. |
dns version check |
| CVE-1999-0010 |
Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. |
dns version check |
| CVE-1999-0011 |
Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer. |
dns version check |
| CVE-1999-0013 |
Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user. |
ssh version check |
| CVE-1999-0017 |
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce. |
ftp bounce test |
| CVE-1999-0018 |
Buffer overflow in statd allows root privileges. |
rpc(statd) check |
| CVE-1999-0019 |
Delete or create a file via rpc.statd, due to invalid information. |
rpc(statd) check |
| CVE-1999-0021 |
Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program. |
cgi(Count.cgi) check |
| CVE-1999-0024 |
DNS cache poisoning via BIND, by predictable query IDs. |
dns version check |
| CVE-1999-0039 |
Arbitrary command execution using webdist CGI program in IRIX. |
cgi(webdist) test |
| CVE-1999-0042 |
Buffer overflow in University of Washington's implementation of IMAP and POP servers. |
imap and pop3 version check |
| CVE-1999-0043 |
Command execution via shell metachars in INN daemon (innd) 1.5 using newgroup and rmgroup control messages, and others. |
inn version check |
| CVE-1999-0045 |
List of arbitrary files on Web host via nph-test-cgi script |
cgi(nph-test-cgi) check |
| CVE-1999-0046 |
Buffer overflow of rlogin program using TERM environmental variable. |
rlogin check |
| CVE-1999-0047 |
MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4. |
sendmail check |
| CVE-1999-0058 |
Buffer overflow in PHP cgi program, php.cgi allows shell access. |
cgi(php.cgi) test |
| CVE-1999-0059 |
IRIX fam service allows an attacker to obtain a list of all files on the server. |
rpc(sgi_fam) check |
| CVE-1999-0067 |
CGI phf program allows remote command execution through shell metacharacters. |
cgi(phf) test |
| CVE-1999-0068 |
CGI PHP mylog script allows an attacker to read any file on the target server. |
cgi(php) test |
| CVE-1999-0070 |
test-cgi program allows an attacker to list files on the server |
cgi(test-cgi) check |
| CVE-1999-0071 |
Apache httpd cookie buffer overflow for versions 1.1.1 and earlier. |
Apache version check |
| CVE-1999-0080 |
wu-ftp FTP server allows root access via site exec command. |
wu-ftp version check |
| CVE-1999-0081 |
wu-ftp allows files to be overwritten via the rnfr command. |
wu-ftp version check |
| CVE-1999-0082 |
CWD ~root command in ftpd allows root access. |
ftp version check |
| CVE-1999-0083 |
getcwd() file descriptor leak in FTP |
ftp version check |
| CVE-1999-0095 |
The debug command in Sendmail is enabled, allowing attackers to execute commands as root. |
sendmail check |
| CVE-1999-0096 |
Sendmail decode alias can be used to overwrite sensitive files |
sendmail check |
| CVE-1999-0100 |
Remote access in AIX innd 1.5.1, using control messages. |
inn version check |
| CVE-1999-0103 |
Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm. |
chargen check |
| CVE-1999-0129 |
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file. |
sendmail check |
| CVE-1999-0130 |
Local users can start Sendmail in daemon mode and gain root privileges. |
sendmail check |
| CVE-1999-0131 |
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users. |
sendmail check |
| CVE-1999-0146 |
The campas CGI program provided with some NCSA web servers allows an attacker to read arbitrary files. |
cgi(campas) check |
| CVE-1999-0147 |
The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands |
cgi(aglimpse) check |
| CVE-1999-0148 |
The handler CGI program in IRIX allows arbitrary command execution. |
cgi(handler) test |
| CVE-1999-0149 |
The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack. |
cgi(wrap) test |
| CVE-1999-0150 |
The Perl fingerd program allows arbitrary command execution from remote users. |
finger check |
| CVE-1999-0152 |
The DG/UX finger daemon allows remote command execution through shell metacharacters. |
finger check |
| CVE-1999-0161 |
In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering. |
tacacs check |
| CVE-1999-0166 |
NFS allows users to use a cd .. command to access other directories besides the exported file system. |
Service check |
| CVE-1999-0168 |
The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions. |
portmapper test |
| CVE-1999-0170 |
Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list. |
portmapper test |
| CVE-1999-0174 |
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
cgi(view-source) test |
| CVE-1999-0176 |
The Webgais program allows a remote user to execute arbitrary commands. |
cgi(webgais) check |
| CVE-1999-0177 |
The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs. |
cgi(uploader) check |
| CVE-1999-0178 |
The win-c-sample program in the WebSite web server has a buffer overflow that allows remote execution of commands. |
cgi(win-c) check |
| CVE-1999-0180 |
in.rshd allows users to login with a NULL username and execute commands. |
rsh check |
| CVE-1999-0183 |
Linux implementations of TFTP would allow access to files outside the restricted directory. |
tftp check |
| CVE-1999-0185 |
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution. |
ftp bounce test |
| CVE-1999-0191 |
IIS newdsn.exe CGI script allows remote users to overwrite files. |
newdsn.exe check |
| CVE-1999-0196 |
The websendmail program in the Webgais program allows a remote user to access arbitrary files. |
cgi(websendmail) check |
| CVE-1999-0203 |
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper mail from address and an invalid rcpt to address that would cause the mail to bounce to a program. |
sendmail version check |
| CVE-1999-0204 |
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. |
sendmail version check |
| CVE-1999-0206 |
MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access. |
sendmail version check |
| CVE-1999-0211 |
Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone. |
nfs check |
| CVE-1999-0219 |
Buffer overflow in Serv-U FTP server when user performs a cwd to a directory with a long name. |
dtspcd check |
| CVE-1999-0233 |
IIS allows users to execute arbitrary commands using .bat or .cmd files. |
cgi(args) check |
| CVE-1999-0236 |
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. |
cgi(ScriptAlias) test |
| CVE-1999-0237 |
Remote execution of arbitrary commands through Guestbook CGI program. |
Guestbook test |
| CVE-1999-0239 |
Netscape FastTrack Web server lists files when a lowercase get command is used instead of an uppercase GET. |
FastTrack server test |
| CVE-1999-0247 |
Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands. |
inn version check |
| CVE-1999-0248 |
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials. |
ssh version check |
| CVE-1999-0260 |
The jj CGI program allows command execution via shell metacharacters. |
cgi(jj) check |
| CVE-1999-0262 |
faxsurvey CGI script on Linux allows remote command execution via shell metacharacters. |
cgi(faxsurvey) test |
| CVE-1999-0264 |
htmlscript CGI program allows remote read access to files. |
cgi(htmlscript) test |
| CVE-1999-0266 |
The info2www CGI script allows remote file access or remote command execution. |
cgi(info2www) check |
| CVE-1999-0270 |
pfdispaly CGI program for SGI's Performer API Search Tool allows read access to files. |
cgi(pfdispaly) test |
| CVE-1999-0289 |
The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL. |
Apache version test |
| CVE-1999-0294 |
All records in a WINS database can be deleted through SNMP for a denial of service. |
SNMP Check |
| CVE-1999-0310 |
SSH 1.2.25 on HP-UX allows access to new user accounts. |
ssh version check |
| CVE-1999-0320 |
SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files. |
rpc(cmsd) check |
| CVE-1999-0365 |
The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry. |
sendmail version check |
| CVE-1999-0366 |
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. |
open SMB shares |
| CVE-1999-0368 |
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. |
wu-ftp version check |
| CVE-1999-0439 |
Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file. |
sendmail version check |
| CVE-1999-0472 |
The SNMP default community name public is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it. |
snmp test |
| CVE-1999-0493 |
rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd. |
rpc(statd) check |
| CVE-1999-0514 |
UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target. |
chargen check |
| CVE-1999-0526 |
An X server's access control is disabled (e.g. through an xhost + command) and allows anyone to connect to the server. |
X-server test |
| CVE-1999-0566 |
An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities. |
syslog check |
| CVE-1999-0612 |
A version of finger is running that exposes valid user information to any entity on the network. |
finger test |
| CVE-1999-0626 |
A version of rusers is running that exposes valid user information to any entity on the network. |
rusers check |
| CVE-1999-0627 |
The rexd service is running, which uses weak authentication that can allow an attacker to execute commands. |
rex check |
| CVE-1999-0685 |
Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option. |
Netscape version check |
| CVE-1999-0695 |
The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack. |
dot..dot server attack |
| CVE-1999-0696 |
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd) |
rpc(cmsd) test |
| CVE-1999-0704 |
Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others. |
amd check |
| CVE-1999-0705 |
Buffer overflow in INN inews program. |
inn version check |
| CVE-1999-0722 |
The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages. |
Cobalt server test |
| CVE-1999-0744 |
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request. |
Netscape version check |
| CVE-1999-0751 |
Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch. |
Netscape version check |
| CVE-1999-0752 |
Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake. |
Netscape version check |
| CVE-1999-0771 |
The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack. |
CIM version check |
| CVE-1999-0772 |
Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301. |
CIM version check |
| CVE-1999-0815 |
Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries. |
snmpd test |
| CVE-1999-0819 |
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it. |
sendmail check |
| CVE-1999-0833 |
Buffer overflow in BIND 8.2 via NXT records. |
dns version check |
| CVE-1999-0834 |
Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library. |
ssh version check |
| CVE-1999-0835 |
Denial of service in BIND named via malformed SIG records. |
dns version check |
| CVE-1999-0837 |
Denial of service in BIND by improperly closing TCP sessions via so_linger. |
dns version check |
| CVE-1999-0842 |
Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-1999-0848 |
Denial of service in BIND named via consuming more than fdmax file descriptors. |
dns version check |
| CVE-1999-0849 |
Denial of service in BIND named via maxdname. |
dns version check |
| CVE-1999-0853 |
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure. |
Netscape version check |
| CVE-1999-0868 |
ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN. |
inn version check |
| CVE-1999-0878 |
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR. |
wu-ftp version check |
| CVE-1999-0879 |
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file. |
wu-ftp version check |
| CVE-1999-0880 |
Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly. |
wu-ftp version check |
| CVE-1999-0881 |
Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-1999-0887 |
FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-1999-0897 |
iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-1999-0915 |
URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-1999-0922 |
An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file. |
ColdFusion test |
| CVE-1999-0927 |
NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-1999-0933 |
TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-1999-0950 |
Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. |
wu-ftp version check |
| CVE-1999-0955 |
Race condition in wu-ftpd and BSDI ftpd allows remote attackers gain root access via the SITE EXEC command. |
wu-ftp version check |
| CVE-1999-0967 |
Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol. |
Registry Check |
| CVE-1999-0977 |
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request. |
rpc(sadmind) checks |
| CVE-1999-0978 |
htdig allows remote attackers to execute commands via filenames with shell metacharacters. |
cgi(htdig) test |
| CVE-1999-1005 |
Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter. |
dot..dot server attack |
| CVE-1999-1010 |
An SSH 1.2.27 server allows a client to use the none cipher, even if it is not allowed by the server policy. |
ssh version check |
| CVE-1999-1011 |
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands. |
IIS RDS Check |
| CVE-1999-1085 |
SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the SSH insertion attack. |
ssh version check |
| CVE-2000-0012 |
Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands. |
Nimda worm check |
| CVE-2000-0036 |
Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the HTML Mail Attachment vulnerability. |
Registry Check |
| CVE-2000-0039 |
AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program. |
dot..dot server attack |
| CVE-2000-0045 |
MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege. |
Null session test |
| CVE-2000-0144 |
Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0148 |
MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string. |
Multiple mysql vulnerabilities |
| CVE-2000-0159 |
HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges. |
password check |
| CVE-2000-0189 |
ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files. |
cgi(coldfusion) check |
| CVE-2000-0191 |
Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0202 |
Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query. |
MSSQL overflow test |
| CVE-2000-0207 |
SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters. |
cgi(infosrch) check |
| CVE-2000-0208 |
The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch. |
cgi(htsearch) check |
| CVE-2000-0222 |
The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs. |
Account with no password |
| CVE-2000-0233 |
SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges. |
IMAP version check |
| CVE-2000-0245 |
Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts. |
Objectserver check |
| CVE-2000-0260 |
Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the Link View Server-Side Component vulnerability. |
cgi(interdev) test |
| CVE-2000-0261 |
The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0267 |
Cisco Catalyst 5.4.x allows a user to gain access to the enable mode without a password. |
Cisco_catalyst_check |
| CVE-2000-0282 |
TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program. |
webplus dot..dot server attack |
| CVE-2000-0303 |
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack. |
dot..dot server attack |
| CVE-2000-0377 |
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the Remote Registry Access Authentication vulnerability. |
Resgistry Access |
| CVE-2000-0389 |
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges. |
kerberos check |
| CVE-2000-0390 |
Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges. |
kerberos check |
| CVE-2000-0431 |
Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files. |
Cobalt server test |
| CVE-2000-0436 |
MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0443 |
The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0472 |
Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID. |
inn version check |
| CVE-2000-0505 |
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters. |
Apache version check |
| CVE-2000-0567 |
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the Malformed E-mail Header vulnerability. |
Registry Check |
| CVE-2000-0573 |
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command. |
wu-ftp version check |
| CVE-2000-0638 |
Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0660 |
The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0662 |
Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED). |
Registry Check |
| CVE-2000-0666 |
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges. |
rpc(statd) check |
| CVE-2000-0682 |
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet. |
BEA Webserver check |
| CVE-2000-0683 |
BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet. |
BEA Webserver check |
| CVE-2000-0684 |
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file. |
BEA Webserver check |
| CVE-2000-0685 |
BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file. |
BEA Webserver check |
| CVE-2000-0705 |
ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0733 |
Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request. |
IRIX telnetd version |
| CVE-2000-0753 |
The Microsoft Outlook mail client identifies the physical path of the sender's machine within a winmail.dat attachment to Rich Text Format (RTF) files. |
Registry Check |
| CVE-2000-0782 |
netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
netauth directory traversal |
| CVE-2000-0788 |
The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands. |
Registry Check |
| CVE-2000-0810 |
Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0811 |
Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields. |
dot..dot server attack |
| CVE-2000-0818 |
The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands. |
vulnerability test |
| CVE-2000-0860 |
The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables. |
PHP check |
| CVE-2000-0868 |
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/. |
Apache check |
| CVE-2000-0869 |
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method. |
Apache check |
| CVE-2000-0883 |
The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory. |
Apache check |
| CVE-2000-0884 |
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the Web Server Folder Traversal vulnerability. |
IIS check |
| CVE-2000-0886 |
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the Web Server File Request Parsing vulnerability. |
executable file parsing check |
| CVE-2000-0900 |
Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a %2e%2e string, a variation of the .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0913 |
mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression. |
Apache check |
| CVE-2000-0917 |
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. |
LPGng check |
| CVE-2000-0919 |
Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0920 |
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a %2E instead of a . |
dot..dot server attack |
| CVE-2000-0921 |
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. |
dot..dot server attack |
| CVE-2000-0922 |
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter. |
dot..dot server attack |
| CVE-2000-0924 |
Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catigory parameter. |
dot..dot server attack |
| CVE-2000-0967 |
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs. |
PHP check |
| CVE-2000-0975 |
Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack. |
dot..dot server attack |
| CVE-2000-0979 |
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the Share Level Password vulnerability. |
Open share test |
| CVE-2000-1005 |
Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. |
dot..dot server attack |
| CVE-2000-1036 |
Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter. |
dot..dot server attack |
| CVE-2000-1051 |
Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet. |
dot..dot server attack |
| CVE-2000-1068 |
pollit.cgi in Poll It 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the poll_options parameter. |
pollit.cgi check |
| CVE-2000-1069 |
pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters. |
pollit.cgi check |
| CVE-2000-1070 |
pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information. |
pollit.cgi check |
| CVE-2000-1077 |
Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension. |
iPlanet check |
| CVE-2000-1200 |
Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users. |
Null session test |
| CVE-2001-0008 |
Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures. |
Possbile Interbase backdoor |
| CVE-2001-0010 |
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges. |
Buffer overflow in DNS |
| CVE-2001-0011 |
Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. |
Buffer overflow in DNS |
| CVE-2001-0012 |
BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables. |
Buffer overflow in DNS |
| CVE-2001-0013 |
Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges. |
Buffer overflow in DNS |
| CVE-2001-0021 |
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template paramater. |
Web Mailman test |
| CVE-2001-0144 |
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow. |
Version check |
| CVE-2001-0149 |
Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object. |
Registry Check |
| CVE-2001-0236 |
Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long indication event. |
Service check |
| CVE-2001-0333 |
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and \ characters twice. |
IIS traversal check |
| CVE-2001-0340 |
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically. |
Registry Check |
| CVE-2001-0341 |
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll. |
overflow test |
| CVE-2001-0368 |
Directory traversal vulnerability in BearShare 2.2.2 and earlier allows a remote attacker to read certain files via a URL containing a series of . characters, a variation of the .. (dot dot) attack. |
Port check |
| CVE-2001-0500 |
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red. |
IIS overflow test |
| CVE-2001-0538 |
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page. |
Registry Check |
| CVE-2001-0660 |
Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL). |
Registry Check |
| CVE-2001-0666 |
Outlook Web Access (OWA) in Microsoft Exchange 2000 allows an authenticated user to cause a denial of service (CPU consumption) via a malformed OWA request for a deeply nested folder within the user's mailbox. |
Registry Check |
| CVE-2001-0717 |
Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function. |
tooltalk check |
| CVE-2001-0726 |
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message. |
Registry Check |
| CVE-2001-0779 |
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username. |
Service check |
| CVE-2001-0803 |
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands |
dtspcd check |
| CVE-2001-0816 |
OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands. |
ssh version check |
| CVE-2001-1088 |
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the Automatically put people I reply to in my address book option enabled, do not notify the user when the Reply-To address is different than the From address, which could allow an untrusted remote attacker to spoof legitimate addresses and intercept email from the client that is intended for another user. |
Registry Check |
| CVE-2001-1380 |
OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the from option associated with a key, which could allow remote attackers to login from unauthorized IP addresses. |
Version check |
| CVE-2002-0003 |
Buffer overflow in the preprocessor in groff 1.16 and earlier allows remote attackers to gain privileges via lpd in the LPRng printing system. |
service check |
| CVE-2002-0027 |
Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the Frame Domain Verification vulnerability described in MS:MS01-058/CAN-2001-0874. |
Registry test |
| CVE-2002-0033 |
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name. |
service check |
| CVE-2002-0071 |
Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names. |
URL test |
| CVE-2002-0075 |
Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (302 Object Moved) message. |
URL test |
| CVE-2002-0079 |
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code. |
URL test |
| CVE-2002-0081 |
Buffer overflows in (1) php_mime_split in PHP 4.1.0, 4.1.1, and 4.0.6 and earlier, and (2) php3_mime_split in PHP 3.0.x allows remote attackers to execute arbitrary code via a multipart/form-data HTTP POST request when file_uploads is enabled. |
URL test |
| CVE-2002-0082 |
The dbm and shm session cache code in mod_ssl before 2.8.7-1.3.23, and Apache-SSL before 1.3.22+1.46, does not properly initialize memory using the i2d_SSL_SESSION function, which allows remote attackers to use a buffer overflow to execute arbitrary code via a large client certificate that is signed by a trusted Certificate Authority (CA), which produces a large serialized session. |
version check |
| CVE-2002-0139 |
Pi-Soft SpoonFTP 1.1 and earlier allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command. |
ftp bounce test |
| CVE-2002-0148 |
Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page. |
URL Check |
| CVE-2002-0152 |
Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh. |
Registry Check |
| CVE-2002-0364 |
Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise. |
URL Check |
| CVE-2002-0392 |
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. |
Web Server Version Check |
| CVE-2002-0394 |
Red-M 1050 (Bluetooth Access Point) uses case insensitive passwords, which makes it easier for attackers to conduct a brute force guessing attack due to the smaller space of possible passwords. |
Web Server Version Check |
| CVE-2002-0538 |
FTP proxy in Symantec Raptor Firewall 6.5.3 and Enterprise 7.0 rewrites an FTP server's FTP PORT responses in a way that allows remote attackers to redirect FTP data connections to arbitrary ports, a variant of the FTP bounce vulnerability. |
ftp bounce test |
| CVE-2002-0573 |
Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed. |
walld check |
| CVE-2002-0575 |
Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows remote and local authenticated users to gain privileges. |
ssh version check |
| CVE-2002-0639 |
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication. |
ssh version check |
| CVE-2002-0679 |
Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure. |
tooltalk check |
| CVE-2002-0685 |
Heap-based buffer overflow in the message decoding functionality for PGP Outlook Encryption Plug-In, as used in NAI PGP Desktop Security 7.0.4, Personal Security 7.0.3, and Freeware 7.0.3, allows remote attackers to modify the heap and gain privileges via a large, malformed mail message. |
Registry Check |
| CVE-2002-0845 |
Buffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked transfer encoding. |
version test |
| CVE-2002-1056 |
Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to. |
Registry Check |
CVE No. |
References |
| CVE-1999-0002 | SGI:19981006-01-I CERT:CA-98.12.mountd CIAC:J-006 BID:121 XF:linux-mountd-bo |
| CVE-1999-0003 | NAI:NAI-29 CERT:CA-98.11.tooltalk SGI:19981101-01-A SGI:19981101-01-PX XF:aix-ttdbserver XF:tooltalk BID:122 |
| CVE-1999-0005 | CERT:CA-98.09.imapd SUN:00177 BID:130 XF:imap-authenticate-bo |
| CVE-1999-0006 | CERT:CA-98.08.qpopper_vul SGI:19980801-01-I AUSCERT:AA-98.01 XF:qpopper-pass-overflow BID:133 |
| CVE-1999-0008 | CERT:CA-98.06.nisd SUN:00170 ISS:June10 1998 XF:nisd-bo-check |
| CVE-1999-0009 | SGI:19980603-01-PX HP:HPSBUX9808-083 SUN:00180 CERT:CA-98.05.bind_problems XF:bind-bo BID:134 |
| CVE-1999-0010 | CERT:CA-98.05.bind_problems SGI:19980603-01-PX HP:HPSBUX9808-083 XF:bind-dos |
| CVE-1999-0011 | CERT:CA-98.05.bind_problems SGI:19980603-01-PX HP:HPSBUX9808-083 SUN:00180 XF:bind-axfr-dos |
| CVE-1999-0013 | CERT:CA-98.03.ssh-agent NAI:NAI-24 XF:ssh-agent |
| CVE-1999-0017 | CERT:CA-97.27.FTP_bounce XF:ftp-bounce XF:ftp-privileged-port |
| CVE-1999-0018 | CERT:CA-97.26.statd AUSCERT:AA-97.29 XF:statd BID:127 |
| CVE-1999-0019 | CERT:CA-96.09.rpc.statd XF:rpc-stat SUN:00135 |
| CVE-1999-0021 | BUGTRAQ:19971010 Security flaw in Count.cgi (wwwcount) CERT:CA-97.24.Count_cgi XF:http-cgi-count BID:128 |
| CVE-1999-0024 | CERT:CA-97.22.bind XF:bind NAI:NAI-11 |
| CVE-1999-0039 | CERT:CA-97.12.webdist AUSCERT:AA-97.14 SGI:19970501-02-PX BID:374 XF:http-sgi-webdist |
| CVE-1999-0042 | NAI:NAI-21 CERT:CA-97.09.imap_pop XF:popimap-bo |
| CVE-1999-0043 | CERT:CA-97.08.innd XF:inn-controlmsg |
| CVE-1999-0045 | CERT:CA-97.07.nph-test-cgi_script XF:http-cgi-nph |
| CVE-1999-0046 | CERT:CA-97.06.rlogin-term XF:rlogin-termbo |
| CVE-1999-0047 | CERT:CA-97.05.sendmail BID:685 XF:sendmail-mime-bo2 |
| CVE-1999-0058 | NAI:NAI-12 BID:712 XF:http-cgi-phpbo |
| CVE-1999-0059 | NAI:NAI-16 XF:irix-fam |
| CVE-1999-0067 | CERT:CA-96.06.cgi_example_code XF:http-cgi-phf BID:629 |
| CVE-1999-0068 | BUGTRAQ:19971019 Vulnerability in PHP Example Logging Scripts XF:http-cgi-php-mylog BID:713 |
| CVE-1999-0070 | XF:http-cgi-test |
| CVE-1999-0071 | XF:http-apache-cookie NAI:NAI-2 |
| CVE-1999-0080 | CERT:CA-95:16.wu-ftpd.vul XF:ftp-execdotdot |
| CVE-1999-0081 | XF:ftp-rnfr |
| CVE-1999-0082 | XF:ftp-cwd FarmerVenema:Improving the Security of Your Site by Breaking Into it |
| CVE-1999-0083 | XF:cwdleak |
| CVE-1999-0095 | CERT:CA-88.01 CERT:CA-93.14 XF:smtp-debug |
| CVE-1999-0096 | CERT:CA-93.16 CERT:CA-95.05 CIAC:A-13 CIAC:A-14 SUN:00122 XF:smtp-dcod |
| CVE-1999-0100 | ERS:ERS-SVA-E01-1997:002.1 XF:inn-controlmsg |
| CVE-1999-0103 | CERT:CA-96.01.UDP_service_denial XF:echo XF:chargen XF:chargen-patch |
| CVE-1999-0129 | CERT:CA-96.25.sendmail_groups |
| CVE-1999-0130 | CERT:CA-96.24.sendmail.daemon.mode BID:716 XF:sendmail-daemon-mode |
| CVE-1999-0131 | CERT:CA-96.20.sendmail_vul XF:smtp-875bo BID:717 |
| CVE-1999-0146 | BUGTRAQ:Jul15 1997 XF:http-cgi-campas |
| CVE-1999-0147 | XF:http-cgi-glimpse AUSCERT:AA-97.28 |
| CVE-1999-0148 | SGI:19970501-02-PX BID:380 XF:http-sgi-handler |
| CVE-1999-0149 | BUGTRAQ:19970420 IRIX 6.x /cgi-bin/wrap bug SGI:19970501-02-PX XF:http-sgi-wrap BID:373 |
| CVE-1999-0150 | XF:perl-fingerd |
| CVE-1999-0152 | BUGTRAQ:19970811 dgux in.fingerd vulnerability XF:dgux-fingerd |
| CVE-1999-0161 | CISCO:http://www.cisco.com/warp/public/707/1.html XF:cisco-acl-tacacs |
| CVE-1999-0166 | XF:nfs-cd |
| CVE-1999-0168 | XF:nfs-portmap |
| CVE-1999-0170 | XF:nfs-ultrix |
| CVE-1999-0174 | BUGTRAQ:19970208 view-source XF:http-cgi-viewsrc |
| CVE-1999-0176 | BUGTRAQ:Jul10 1997 XF:http-webgais-query |
| CVE-1999-0177 | XF:http-website-uploader |
| CVE-1999-0178 | XF:http-website-winsample |
| CVE-1999-0180 | XF:rsh-null |
| CVE-1999-0183 | XF:linux-tftp |
| CVE-1999-0185 | SUN:00156 XF:sun-ftpd/logind |
| CVE-1999-0191 | XF:http-cgi-newdsn |
| CVE-1999-0196 | XF:http-webgais-smail BUGTRAQ:Jul08 1997 |
| CVE-1999-0203 | CERT:CA-95.08 CIAC:E-03 XF:smtp-sendmail-version5 |
| CVE-1999-0204 | XF:ident-bo CIAC:F-13 |
| CVE-1999-0206 | XF:sendmail-mime-bo AUSCERT:AA-96.06a |
| CVE-1999-0211 | CERT:CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability |
| CVE-1999-0219 | XF:ftp-servu |
| CVE-1999-0233 | MSKB:Q148188 MSKB:Q155056 XF:http-iis-cmd |
| CVE-1999-0236 | XF:http-scriptalias |
| CVE-1999-0237 | XF:http-cgi-guestbook CERT:VB-97.02 |
| CVE-1999-0239 | XF:fastrack-get-directory-list |
| CVE-1999-0247 | NAI:19970721 INN news server vulnerabilities BID:1443 XF:inn-bo |
| CVE-1999-0260 | BUGTRAQ:19961224 jj cgi XF:http-cgi-jj |
| CVE-1999-0262 | XF:http-cgi-faxsurvey BUGTRAQ:Aug04 1998 |
| CVE-1999-0264 | XF:http-htmlscript-file-access BUGTRAQ:Jan27 1998 |
| CVE-1999-0266 | XF:http-cgi-info2www |
| CVE-1999-0270 | SGI:19980401-01-P CIAC:I-041 XF:sgi-pfdispaly |
| CVE-1999-0289 | |
| CVE-1999-0294 | XF:nt-wins-snmp2 |
| CVE-1999-0310 | XF:ssh-1225 |
| CVE-1999-0320 | SUN:00166 XF:sun-rpc.cmsd |
| CVE-1999-0365 | BUGTRAQ:Feb04 1999 XF:metamail-header-commands |
| CVE-1999-0366 | MS:MS99-004 MSKB:Q214840 XF:nt-sp4-auth-error |
| CVE-1999-0368 | NETECT:palmetto.ftpd CERT:CA-99.03 XF:palmetto-ftpd-bo |
| CVE-1999-0439 | BUGTRAQ:19990405 Re: [SECURITY] new version of procmail with security fixes DEBIAN:19990422 CALDERA:CSSA-1999:007 XF:procmail-overflow |
| CVE-1999-0472 | XF:netcache-snmp BUGTRAQ:Apr7 1999 |
| CVE-1999-0493 | CERT:CA-99-05 SUN:00186 CIAC:J-045 BUGTRAQ:19990103 SUN almost has a clue! (automountd) BID:450 |
| CVE-1999-0514 | XF:fraggle |
| CVE-1999-0526 | XF:xcheck-keystroke |
| CVE-1999-0566 | XF:ibm-syslogd XF:syslog-flood |
| CVE-1999-0612 | XF:finger-out XF:finger-running |
| CVE-1999-0626 | XF:rusersd XF:ruser |
| CVE-1999-0627 | XF:rexd |
| CVE-1999-0685 | BUGTRAQ:19991209 Netscape communicator 4.06J 4.5J-4.6J 4.61e Buffer Overflow BID:618 |
| CVE-1999-0695 | BUGTRAQ:19990904 [Sybase] software vendors do not think about old bugs XF:http-powerdynamo-dotdotslash BID:620 |
| CVE-1999-0696 | BUGTRAQ:19990709 Exploit of rpc.cmsd SCO:SB-99.12 SUN:00188 SUNBUG:4230754 HP:HPSBUX9908-102 COMPAQ:SSRT0614U_RPC_CMSD CERT:CA-99-08 CIAC:J-051 XF:sun-cmsd-bo |
| CVE-1999-0704 | REDHAT:RHSA-1999:032-01 CALDERA:CSSA-1999:024.0 FREEBSD:SA-99:06 DEBIAN:19991018 BID:614 CERT:CA-99-12 XF:amd-bo |
| CVE-1999-0705 | XF:inn-inews-bo REDHAT:RHSA1999033_01 CALDERA:CSSA-1999-026 SUSE:19990831 Security hole in INN DEBIAN:19990907 BID:616 |
| CVE-1999-0722 | XF:cobalt-raq2-default-config CERT:CA-99-10 |
| CVE-1999-0744 | ISS:Buffer Overflow in Netscape Enterprise and FastTrack Web Servers BID:603 |
| CVE-1999-0751 | BUGTRAQ:19990913 Accept overflow on Netscape Enterprise Server 3.6 SP2 BID:631 |
| CVE-1999-0752 | BUGTRAQ:19990706 Netscape Enterprise Server SSL Handshake Bug |
| CVE-1999-0771 | BUGTRAQ:19990526 Infosec.19990526.compaq-im.a COMPAQ:SSRT0612U XF:management-agent-file-read |
| CVE-1999-0772 | BUGTRAQ:19990527 Re: Infosec.19990526.compaq-im.a (New DoS and correction to my previous post) COMPAQ:SSRT0612U XF:management-agent-dos |
| CVE-1999-0815 | MSKB:Q196270 XF:nt-snmpagent-leak(1974) |
| CVE-1999-0819 | NTBUGTRAQ:19991130 NTmail and VRFY BUGTRAQ:19991130 NTmail and VRFY XF:nt-mail-vrfy |
| CVE-1999-0833 | SUSE:19991111 Security hole in bind8 < 8.2.2p2 and bind4 < 4.9.7-REL DEBIAN:19991116 Denial of service vulnerabilities in bind CALDERA:CSSA-1999-034.1 REDHAT:RHSA-1999:054-01 CERT:CA-99-14 BID:788 XF:bind-nxt-bo |
| CVE-1999-0834 | BUGTRAQ:19991201 Security Advisory: Buffer overflow in RSAREF2 BUGTRAQ:19991202 OpenBSD sslUSA26 advisory (Re: CORE-SDI: Buffer overflow in RSAREF2) CERT:CA-99-15 BID:843 XF:rsaref-bo |
| CVE-1999-0835 | SUSE:19991111 Security hole in bind8 < 8.2.2p2 and bind4 < 4.9.7-REL DEBIAN:19991116 Denial of service vulnerabilities in bind CALDERA:CSSA-1999-034.1 REDHAT:RHSA-1999:054-01 CERT:CA-99-14 XF:bind-sigrecord-dos BID:788 |
| CVE-1999-0837 | SUSE:19991111 Security hole in bind8 < 8.2.2p2 and bind4 < 4.9.7-REL DEBIAN:19991116 Denial of service vulnerabilities in bind CALDERA:CSSA-1999-034.1 REDHAT:RHSA-1999:054-01 SUN:00194 CERT:CA-99-14 XF:bind-solinger-dos BID:788 |
| CVE-1999-0842 | NTBUGTRAQ:19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability BUGTRAQ:19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability BID:827 XF:symantec-mail-dir-traversal |
| CVE-1999-0848 | SUSE:19991111 Security hole in bind8 < 8.2.2p2 and bind4 < 4.9.7-REL DEBIAN:19991116 Denial of service vulnerabilities in bind CALDERA:CSSA-1999-034.1 REDHAT:RHSA-1999:054-01 SUN:00194 CERT:CA-99-14 BID:788 XF:bind-fdmax-dos |
| CVE-1999-0849 | SUSE:19991111 Security hole in bind8 < 8.2.2p2 and bind4 < 4.9.7-REL DEBIAN:19991116 Denial of service vulnerabilities in bind CALDERA:CSSA-1999-034.1 REDHAT:RHSA-1999:054-01 SUN:00194 CERT:CA-99-14 BID:788 XF:bind-maxdname-bo |
| CVE-1999-0853 | BID:847 ISS:19991201 Buffer Overflow in Netscape Enterprise and FastTrack Authentication Procedure XF:netscape-fasttrack-auth-bo |
| CVE-1999-0868 | CERT:CA-97.08 XF:inn-ucbmail-shell-meta |
| CVE-1999-0878 | AUSCERT:AA-1999.01 CERT:CA-99-13 REDHAT:RHSA1999031_01 XF:wu-ftpd-dir-name BID:599 |
| CVE-1999-0879 | CERT:CA-99-13 XF:wuftp-message-file-root |
| CVE-1999-0880 | CERT:CA-99-13 XF:wuftp-site-newer-dos |
| CVE-1999-0881 | BUGTRAQ:19991025 Falcon Web Server BINDVIEW:Falcon Web Server BID:743 XF:falcon-path-parsing |
| CVE-1999-0887 | BUGTRAQ:19991104 FTGate Version 2.1 Web interface Server Directory Traversal Vulnerability EEYE:AD05261999 |
| CVE-1999-0897 | BUGTRAQ:19980908 bug in iChat 3.0 (maybe others) XF:ichat-file-read-vuln |
| CVE-1999-0915 | BUGTRAQ:19991028 URL Live! 1.0 WebServer BID:746 |
| CVE-1999-0922 | ALLAIRE:ASB99-02 XF:coldfusion-sourcewindow |
| CVE-1999-0927 | EEYE:AD05261999 BID:279 XF:ntmail-fileread |
| CVE-1999-0933 | BUGTRAQ:19991001 RFP9904: TeamTrack webserver vulnerability BID:689 |
| CVE-1999-0950 | BUGTRAQ:19991027 WFTPD v2.40 FTPServer remotely exploitable buffer overflow vulnerability BID:747 XF:wftpd-mkd-bo |
| CVE-1999-0955 | CERT:CA-94.08 CIAC:E-17 XF:ftp-exec |
| CVE-1999-0967 | L0PHT:19971101 Microsoft Internet Explorer 4.0 Suite |
| CVE-1999-0977 | SF-INCIDENTS:19991209 sadmind BUGTRAQ:19991210 Solaris sadmind Buffer Overflow Vulnerability CERT:CA-99-16 SUN:00191 BID:866 XF:sol-sadmind-amslverify-bo |
| CVE-1999-0978 | DEBIAN:19991209 BID:867 |
| CVE-1999-1005 | BUGTRAQ:19991219 Groupewise Web Interface XF:groupwise-web-read-files BID:879 |
| CVE-1999-1010 | BUGTRAQ:19991214 sshd1 allows unencrypted sessions regardless of server policy XF:ssh-policy-bypass |
| CVE-1999-1011 | MS:MS98-004 MS:MS99-025 CIAC:J-054 ISS:19990809 Vulnerabilities in Microsoft Remote Data Service BID:529 XF:nt-iis-rds |
| CVE-1999-1085 | BUGTRAQ:19980612 CORE-SDI-04: SSH insertion attack BUGTRAQ:19980703 UPDATE: SSH insertion attack CISCO:20010627 Multiple SSH Vulnerabilities CERT-VN:VU#13877 XF:ssh-insert(1126) |
| CVE-2000-0012 | BUGTRAQ:19991227 remote buffer overflow in miniSQL BID:898 XF:w3-msql-scanf-bo |
| CVE-2000-0036 | MS:MS99-060 MSKB:Q249082 |
| CVE-2000-0039 | BUGTRAQ:19991229 AltaVista BUGTRAQ:19991230 Follow UP AltaVista BUGTRAQ:19991229 AltaVista followup and monitor script BUGTRAQ:20000103 FW: Patch issued for AltaVista Search Engine Directory TraversalVulnerability BUGTRAQ:20000109 Altavista followup BID:896 |
| CVE-2000-0045 | BUGTRAQ:20000111 Serious bug in MySQL password handling. BUGTRAQ:20000113 New MySQL Available XF:mysql-pwd-grant BID:926 |
| CVE-2000-0144 | BUGTRAQ:20000207 Infosec.20000207.axis700.a BID:971 |
| CVE-2000-0148 | BUGTRAQ:20000208 Remote access vulnerability in all MySQL server versions BUGTRAQ:20000214 MySQL 3.22.32 released BID:975 |
| CVE-2000-0159 | HP:HPSBUX0002-111 |
| CVE-2000-0189 | NTBUGTRAQ:20000301 ColdFusions application.cfm shows full path BUGTRAQ:20000305 ColdFusion Bug: Application.cfm shows full path BID:1021 |
| CVE-2000-0191 | BUGTRAQ:20000229 Infosec.20000229.axisstorpointcd.a XF:axis-storpoint-auth BID:1025 |
| CVE-2000-0202 | MS:MS00-014 BID:1041 |
| CVE-2000-0207 | BUGTRAQ:20000301 infosrch.cgi vulnerability (IRIX 6.5) SGI:20000501-01-P XF:irix-infosrch-fname BID:1031 |
| CVE-2000-0208 | BUGTRAQ:20000228 ht://Dig remote information exposure FREEBSD:FreeBSD-SA-00:06 DEBIAN:20000226 remote users can read files with webserver uid TURBO:TLSA200005-1 BID:1026 |
| CVE-2000-0222 | BUGTRAQ:20000215 Windows 2000 installation process weakness BID:990 |
| CVE-2000-0233 | SUSE:20000327 Security hole in SuSE Linux IMAP Server XF:linux-imap-remote-unauthorized-access |
| CVE-2000-0245 | BUGTRAQ:20000328 Objectserver vulnerability SGI:20000303-01-PX XF:irix-objectserver-create-accounts BID:1079 |
| CVE-2000-0260 | MS:MS00-025 BID:1109 |
| CVE-2000-0261 | BUGTRAQ:20000415 (no subject) BUGTRAQ:20000418 AVM's Statement XF:ken-download-files BID:1103 |
| CVE-2000-0267 | CISCO:20000419 Cisco Catalyst Enable Password Bypass Vulnerability XF:cisco-catalyst-password-bypass BID:1122 |
| CVE-2000-0377 | MS:MS00-040 MSKB:Q264684 XF:nt-registry-request-dos BID:1331 |
| CVE-2000-0389 | BUGTRAQ:20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS CERT:CA-2000-06 FREEBSD:FreeBSD-SA-00:20 REDHAT:RHSA-2000-025 XF:kerberos-krb-rd-req-bo BID:1220 |
| CVE-2000-0390 | BUGTRAQ:20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS CERT:CA-2000-06 FREEBSD:FreeBSD-SA-00:20 REDHAT:RHSA-2000-025 BID:1220 XF:kerberos-krb425-conv-principal-bo |
| CVE-2000-0443 | BUGTRAQ:20000524 HP Web JetAdmin Version 5.6 Web interface Server Directory Traversal Vulnerability XF:hp-jetadmin-directory-traversal BID:1243 |
| CVE-2000-0472 | BUGTRAQ:20000106 innd 2.2.2 remote buffer overflow CALDERA:CSSA-2000-016.0 BUGTRAQ:20000707 inn update BUGTRAQ:20000721 [ANNOUNCE] INN 2.2.3 available BUGTRAQ:20000722 MDKSA-2000:023 inn update BID:1316 XF:innd-cancel-overflow |
| CVE-2000-0505 | BUGTRAQ:20000603 Re: IBM HTTP SERVER / APACHE BID:1284 XF:ibm-http-file-retrieve |
| CVE-2000-0567 | MS:MS00-043 BUGTRAQ:20000719 Buffer Overflow in MS Outlook Email Clients BUGTRAQ:20000719 Aaron Drew - Security Advisory: Buffer Overflow in MS Outlook & Outlook Express Email Clients BID:1481 XF:outlook-date-overflow |
| CVE-2000-0573 | BUGTRAQ:20000622 WuFTPD: Providing *remote* root since at least1994 BUGTRAQ:20000623 WUFTPD 2.6.0 remote root exploit BUGTRAQ:20000707 New Released Version of the WuFTPD Sploit BUGTRAQ:20000623 ftpd: the advisory version AUSCERT:AA-2000.02 CERT:CA-2000-13 DEBIAN:20000622 wu-ftp: remote root exploit in wu-ftp CALDERA:CSSA-2000-020.0 REDHAT:RHSA-2000:039-02 BUGTRAQ:20000723 CONECTIVA LINUX SECURITY ANNOUNCEMENT - WU-FTPD (re-release) BUGTRAQ:20000702 [Security Announce] wu-ftpd update BUGTRAQ:20000929 [slackware-security] wuftpd vulnerability - Slackware 4.0 7.0 7.1 -current FREEBSD:FreeBSD-SA-00:29 NETBSD:NetBSD-SA2000-009 XF:wuftp-format-string-stack-overwrite BID:1387 XF:wuftp-format-string-stack-overwrite(4773) |
| CVE-2000-0662 | BUGTRAQ:20000714 IE 5.5 and 5.01 vulnerability - reading at least local and from any host text and parsed html files BID:1474 XF:ie-dhtmled-file-read(5107) |
| CVE-2000-0666 | BUGTRAQ:20000716 Lots and lots of fun with rpc.statd DEBIAN:20000715 rpc.statd: remote root exploit REDHAT:RHSA-2000:043-03 BUGTRAQ:20000717 CONECTIVA LINUX SECURITY ANNOUNCEMENT - nfs-utils BUGTRAQ:20000718 Trustix Security Advisory - nfs-utils BUGTRAQ:20000718 [Security Announce] MDKSA-2000:021 nfs-utils update CALDERA:CSSA-2000-025.0 CERT:CA-2000-17 BID:1480 XF:linux-rpcstatd-format-overwrite |
| CVE-2000-0705 | BUGTRAQ:20000802 [ Hackerslab bug_paper ] ntop web mode vulnerabliity REDHAT:RHSA-2000:049-02 BID:1550 XF:ntop-remote-file-access |
| CVE-2000-0733 | BUGTRAQ:20000814 [LSD] IRIX telnetd remote vulnerability SGI:20000801-02-P BID:1572 |
| CVE-2000-0753 | BUGTRAQ:20000824 Outlook winmail.dat BUGTRAQ:20010802 Outlook 2000 Rich Text information disclosure BID:1631 XF:outlook-reveal-path(5508) |
| CVE-2000-0788 | BUGTRAQ:20000807 MS Word and MS Access vulnerability - executing arbitrary programs may be exploited by IE/Outlook MS:MS00-071 BID:1566 XF:word-mail-merge(5322) |
| CVE-2000-0810 | BUGTRAQ:20001016 File deletion and other bugs in Auction Weaver LITE 1.0 - 1.04 BID:1782 XF:auction-weaver-delete-files |
| CVE-2000-0811 | BUGTRAQ:20001016 File deletion and other bugs in Auction Weaver LITE 1.0 - 1.04 BID:1783 XF:auction-weaver-username-bidfile |
| CVE-2000-0868 | ATSTAKE:A090700-2 SUSE:20000907 BID:1658 XF:suse-apache-cgi-source-code |
| CVE-2000-0869 | ATSTAKE:A090700-3 SUSE:20000907 BID:1656 XF:apache-webdav-directory-listings |
| CVE-2000-0883 | MANDRAKE:MDKSA-2000:046 BID:1678 XF:linux-mod-perl |
| CVE-2000-0884 | BUGTRAQ:20001017 IIS %c1%1c remote command execution MS:MS00-078 BID:1806 XF:iis-unicode-translation |
| CVE-2000-0886 | BUGTRAQ:20001107 NSFOCUS SA2000-07 : Microsoft IIS 4.0/5.0 CGI File Name Inspection Vulnerability MS:MS00-086 BID:1912 XF:iis-invalid-filename-passing(5470) |
| CVE-2000-0900 | BUGTRAQ:20001002 thttpd ssi: retrieval of arbitrary world-readable files FREEBSD:FreeBSD-SA-00:73 XF:acme-thttpd-ssi BID:1737 |
| CVE-2000-0913 | BUGTRAQ:20000929 Security vulnerability in Apache mod_rewrite MANDRAKE:MDKSA-2000:060 REDHAT:RHSA-2000:088-04 CALDERA:CSSA-2000-035.0 HP:HPSBUX0010-126 BUGTRAQ:20001011 Conectiva Linux Security Announcement - apache BID:1728 XF:apache-rewrite-view-files |
| CVE-2000-0917 | BUGTRAQ:20000925 Format strings: bug #2: LPRng CERT:CA-2000-22 CALDERA:CSSA-2000-033.0 REDHAT:RHSA-2000:065-06 FREEBSD:FreeBSD-SA-00:56 XF:lprng-format-string BID:1712 |
| CVE-2000-0919 | BUGTRAQ:20001007 PHPix advisory BID:1773 XF:phpix-dir-traversal |
| CVE-2000-0920 | BUGTRAQ:20001006 Vulnerability in BOA web server v0.94.8.2 FREEBSD:FreeBSD-SA-00:60 DEBIAN:20001009 boa: exposes contents of local files BID:1770 XF:boa-webserver-get-dir-traversal |
| CVE-2000-0921 | BUGTRAQ:20001007 Security Advisory: Hassan Consulting's shop.cgi Directory Traversal Vulnerability. BID:1777 XF:hassan-shopping-cart-dir-traversal |
| CVE-2000-0922 | BUGTRAQ:20001008 Security Advisory: Bytes Interactive's Web Shopper (shopper.cgi) Directory Traversal Vulnerability BID:1776 XF:web-shopper-directory-traversal |
| CVE-2000-0924 | BUGTRAQ:20001009 Master Index traverse advisory BID:1772 XF:master-index-directory-traversal |
| CVE-2000-0967 | ATSTAKE:A101200-1 MANDRAKE:MDKSA-2000:062 DEBIAN:20001014 php3: possible remote exploit DEBIAN:20001014 php4: possible remote exploit CALDERA:CSSA-2000-037.0 FREEBSD:FreeBSD-SA-00:75 BUGTRAQ:20001012 Conectiva Linux Security Announcement - mod_php3 BID:1786 XF:php-logging-format-string |
| CVE-2000-0975 | BUGTRAQ:20001012 Anaconda Advisory XF:anaconda-apexec-directory-traversal |
| CVE-2000-0979 | BUGTRAQ:20001012 NSFOCUS SA2000-05: Microsoft Windows 9x NETBIOS password MS:MS00-072 BID:1780 XF:win9x-share-level-password |
| CVE-2000-1005 | BUGTRAQ:20001009 Security Advisory : eXtropia WebStore (web_store.cgi) Directory Traversal Vulnerability BID:1774 XF:extropia-webstore-fileread |
| CVE-2000-1036 | BUGTRAQ:20000920 Extent RBS directory Transversal. BID:1704 XF:rbs-isp-directory-traversal |
| CVE-2000-1051 | BUGTRAQ:20001023 Allaire JRUN 2.3 Arbitrary File Retrieval ALLAIRE:ASB00-028 XF:allaire-jrun-ssifilter-url |
| CVE-2000-1069 | BUGTRAQ:20001023 Re: Poll It v2.0 cgi (again) XF:pollit-admin-password-var |
| CVE-2000-1070 | BUGTRAQ:20001023 Re: Poll It v2.0 cgi (again) XF:pollit-webroot-gain-access |
| CVE-2000-1077 | BUGTRAQ:20001026 Buffer overflow in iPlanet Web Server 4 server side SHTML parsing module XF:iplanet-web-server-shtml-bo |
| CVE-2000-1200 | BUGTRAQ:20000201 Windows NT and account list leak ! A new SID usage XF:nt-lsa-domain-sid(4015) BID:959 |
| CVE-2001-0008 | CERT:CA-2001-01 BID:2192 XF:interbase-backdoor-account(5911) |
| CVE-2001-0010 | NAI:20010129 Vulnerabilities in BIND 4 and 8 CERT:CA-2001-02 IBM:ERS-SVA-E01-2001:002.1 MANDRAKE:MDKSA-2001-017 REDHAT:RHSA-2001-007 CONECTIVA:000377 FREEBSD:FreeBSD-SA-01:18 XF:bind-tsig-bo BID:2302 |
| CVE-2001-0011 | NAI:20010129 Vulnerabilities in BIND 4 and 8 CERT:CA-2001-02 IBM:ERS-SVA-E01-2001:002.1 MANDRAKE:MDKSA-2001-017 REDHAT:RHSA-2001-007 CONECTIVA:000377 FREEBSD:FreeBSD-SA-01:18 XF:bind-complain-bo BID:2307 |
| CVE-2001-0012 | NAI:20010129 Vulnerabilities in BIND 4 and 8 CERT:CA-2001-02 IBM:ERS-SVA-E01-2001:002.1 MANDRAKE:MDKSA-2001-017 REDHAT:RHSA-2001-007 CONECTIVA:000377 FREEBSD:FreeBSD-SA-01:18 XF:bind-inverse-query-disclosure BID:2321 |
| CVE-2001-0013 | NAI:20010129 Vulnerabilities in BIND 4 and 8 CERT:CA-2001-02 IBM:ERS-SVA-E01-2001:002.1 MANDRAKE:MDKSA-2001-017 REDHAT:RHSA-2001-007 CONECTIVA:000377 FREEBSD:FreeBSD-SA-01:18 XF:bind-complain-format-string BID:2309 |
| CVE-2001-0144 | BINDVIEW:20010208 Remote vulnerability in SSH daemon crc32 compensation attack detector BUGTRAQ:20010208 [CORE SDI ADVISORY] SSH1 CRC-32 compensation attack detector XF:ssh-deattack-overwrite-memory(6083) BID:2347 |
| CVE-2001-0149 | BUGTRAQ:20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files NTBUGTRAQ:20000926 IE 5.5/Outlook Express security vulnerability - GetObject() expose user's files MS:MS01-015 XF:ie-getobject-expose-files(5293) |
| CVE-2001-0236 | BUGTRAQ:20010314 Solaris /usr/lib/dmi/snmpXdmid vulnerability CERT:CA-2001-05 CIAC:L-065 SUN:00207 XF:solaris-snmpxdmid-bo(6245) BID:2417 |
| CVE-2001-0333 | BUGTRAQ:20010515 NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability MS:MS01-026 CERT:CA-2001-12 XF:iis-url-decoding(6534) BID:2708 |
| CVE-2001-0340 | MS:MS01-030 CIAC:L-091 XF:exchange-owa-script-execution(6652) |
| CVE-2001-0341 | BUGTRAQ:20010625 NSFOCUS SA2001-03 : Microsoft FrontPage 2000 Server Extensions Buffer Overflow Vulnerability MS:MS01-035 BID:2906 XF:frontpage-ext-rad-bo(6730) |
| CVE-2001-0368 | BUGTRAQ:20010430 A Serious Security Vulnerability Found in BearShare (Directory Traversal) BID:2672 XF:bearshare-dot-download-files(6481) |
| CVE-2001-0500 | BUGTRAQ:20010618 All versions of Microsoft Internet Information Services Remote buffer overflow (SYSTEM Level Access) MS:MS01-033 CERT:CA-2001-13 BID:2880 XF:iis-isapi-idq-bo(6705) CIAC:L-098 |
| CVE-2001-0538 | BUGTRAQ:20010712 MS Office XP - the more money I give to Microsoft the more vulnerable my Windows computers are NTBUGTRAQ:20010712 Vulnerability in IE/Outlook ActiveX control MS:MS01-038 CIAC:L-113 CERT-VN:VU#131569 XF:outlook-activex-view-control(6831) BID:3025 |
| CVE-2001-0660 | MS:MS01-047 MSKB:Q307195 XF:exchange-owa-obtain-addresses(7089) BID:3301 |
| CVE-2001-0666 | MS:MS01-049 XF:exchange-owa-folder-request-dos(7168) BID:3368 |
| CVE-2001-0717 | ISS:20011002 Multi-Vendor Format String Vulnerability in ToolTalk Service CERT:CA-2001-27 CIAC:M-002 HP:HPSBUX0110-168 SUN:00212 COMPAQ:SSRT0767U HP:HPSBUX0110-168 CALDERA:CSSA-2001-SCO.28 BID:3382 XF:tooltalk-ttdbserverd-format-string(7069) |
| CVE-2001-0726 | MS:MS01-057 XF:exchange-owa-embedded-script-execution(7663) BID:3650 |
| CVE-2001-0779 | BUGTRAQ:20010528 solaris 2.6 7 yppasswd vulnerability BUGTRAQ:20011004 Patches for Solaris rpc.yppasswdd available SUNBUG:4456994 CERT-VN:VU#327281 SUN:00209 CIAC:M-008 XF:solaris-yppasswd-bo(6629) BID:2763 |
| CVE-2001-0803 | ISS:20011112 Multi-Vendor Buffer Overflow Vulnerability in CDE Subprocess Control Service CERT:CA-2001-31 CERT:CA-2002-01 CERT-VN:VU#172583 SUN:00214 HP:HPSBUX0111-175 CALDERA:CSSA-2001-SCO.30 SGI:20011107-01-P BID:3517 XF:cde-dtspcd-bo(7396) |
| CVE-2001-0816 | BUGTRAQ:20010918 OpenSSH: sftp & bypassing keypair auth restrictions CONECTIVA:CLSA-2001:431 IMMUNIX:IMNX-2001-70-034-01 REDHAT:RHSA-2001:154 XF:openssh-sftp-bypass-restrictions(7634) |
| CVE-2001-1380 | BUGTRAQ:20011018 Immunix OS update for OpenSSH BUGTRAQ:20011017 TSLSA-2001-0023 - OpenSSH BUGTRAQ:20010926 OpenSSH Security Advisory (adv.option) BUGTRAQ:20011019 TSLSA-2001-0026 - OpenSSH REDHAT:RHSA-2001:114 MANDRAKE:MDKSA-2001:081 |
| CVE-2002-0003 | REDHAT:RHSA-2002:004 MANDRAKE:MDKSA-2002:012 HP:HPSBTL0201-014 XF:linux-groff-preprocessor-bo(7881) BID:3869 |
| CVE-2002-0027 | BUGTRAQ:20011219 Internet Explorer Document.Open() Without Close() Cookie Stealing File Reading Site Spoofing Bug MS:MS02-005 BID:3721 |
| CVE-2002-0071 | ATSTAKE:A041002-1 BUGTRAQ:20020411 KPMG-2002010: Microsoft IIS .htr ISAPI buffer overrun VULNWATCH:20020411 [VulnWatch] KPMG-2002010: Microsoft IIS .htr ISAPI buffer overrun MS:MS02-018 CERT:CA-2002-09 CISCO:20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 CERT-VN:VU#363715 XF:iis-htr-isapi-bo(8799) BID:4474 |
| CVE-2002-0075 | BUGTRAQ:20020411 [SNS Advisory No.49] A Possibility of Internet Information Server/Services Cross Site Scripting MS:MS02-018 CERT:CA-2002-09 CISCO:20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 CERT-VN:VU#520707 XF:iis-redirected-url-error-css(8804) BID:4487 |
| CVE-2002-0079 | BUGTRAQ:20020410 Windows 2000 and NT4 IIS .ASP Remote Buffer Overflow MS:MS02-018 CERT:CA-2002-09 CISCO:20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 CERT-VN:VU#610291 XF:iis-asp-chunked-encoding-bo(8795) BID:4485 |
| CVE-2002-0148 | BUGTRAQ:20020410 IIS allows universal CrossSiteScripting MS:MS02-018 CERT:CA-2002-09 CISCO:20020415 Microsoft IIS Vulnerabilities in Cisco Products - MS02-018 XF:iis-http-error-page-css(8803) CERT-VN:VU#886699 BID:4486 |
| CVE-2002-0152 | BUGTRAQ:20020416 w00w00 on Microsoft IE/Office for Mac OS MS:MS02-019 XF:ms-mac-html-file-bo(8850) BID:4517 |
| CVE-2002-0364 | BUGTRAQ:20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612] NTBUGTRAQ:20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow VULNWATCH:20020612 ADVISORY: Windows 2000 and NT4 IIS .HTR Remote Buffer Overflow [AD20020612] BUGTRAQ:20020613 VNA - .HTR HEAP OVERFLOW CERT-VN:VU#313819 MS:MS02-028 BID:4855 XF:iis-htr-chunked-encoding-bo(9327) |
| CVE-2002-0394 | ATSTAKE:A060502-1 XF:redm-1050ap-insecure-passwords(9263) |
| CVE-2002-0573 | BUGTRAQ:20020430 Adivosry + Exploit for Remote Root Hole in Default Installation of Popular Commercial Operating System VULNWATCH:20020430 [VulnWatch] Adivosry + Exploit for Remote Root Hole in Default Installation of Popular Commercial Operating System CERT:CA-2002-10 CERT-VN:VU#638099 XF:solaris-rwall-format-string(8971) BID:4639 |
| CVE-2002-0575 | BUGTRAQ:20020426 Revised OpenSSH Security Advisory (adv.token) BUGTRAQ:20020419 OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable buffer overflow VULN-DEV:20020419 OpenSSH 2.2.0 - 3.1.0 server contains a locally exploitable buffer overflow BUGTRAQ:20020517 OpenSSH 3.2.2 released (fwd) BUGTRAQ:20020429 TSLSA-2002-0047 - openssh BUGTRAQ:20020420 OpenSSH Security Advisory (adv.token) CALDERA:CSSA-2002-022.2 BID:4560 XF:openssh-sshd-kerberos-bo(8896) |
| CVE-2002-0639 | ISS:20020626 OpenSSH Remote Challenge Vulnerability BUGTRAQ:20020626 OpenSSH Security Advisory (adv.iss) BUGTRAQ:20020626 Revised OpenSSH Security Advisory (adv.iss) BUGTRAQ:20020627 How to reproduce OpenSSH Overflow. NETBSD:2002-005 CERT-VN:VU#369347 CERT:CA-2002-18 HP:HPSBUX0206-195 CALDERA:CSSA-2002-030.0 BUGTRAQ:20020626 [OpenPKG-SA-2002.005] OpenPKG Security Advisory (openssh) CONECTIVA:CLA-2002:502 ENGARDE:ESA-20020702-016 MANDRAKE:MDKSA-2002:040 BID:5093 XF:openssh-challenge-response-bo(9169) |
| CVE-2002-1056 | BUGTRAQ:20020331 More Office XP Problems BUGTRAQ:20020403 More Office XP problems (Version 2.0) MS:MS02-021 BID:4397 XF:outlook-object-execute-script(8708) |