Monthly Archive: September 1999

CVE-1999-0392

Buffer overflow in Thomas Boutell’s cgic library version up to 1.05. Date published : 1999-09-29

CVE-1999-0391

The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. Date published : 1999-09-29

CVE-1999-0388

DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root. Date published : 1999-09-29 http://www.osvdb.org/3186

CVE-1999-0384

The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user’s clipboard when the user accesses documents with ActiveX content. Date published : 1999-09-29...

CVE-1999-0379

Microsoft Taskpads allows remote web sites to execute commands on the visiting user’s machine via certain methods that are marked as Safe for Scripting. Date published : 1999-09-29 http://www.securityfocus.com/bid/498

CVE-1999-0377

Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine’s process tables through multiple connections to network services. Date published : 1999-09-29 http://www.securitytracker.com/id/1033881

CVE-1999-0376

Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. Date published : 1999-09-29

CVE-1999-0375

Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands. Date published : 1999-09-29

CVE-1999-0374

Debian GNU/Linux cfengine package is susceptible to a symlink attack. Date published : 1999-09-29

CVE-1999-0373

Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root. Date published : 1999-09-29