Monthly Archive: February 2000
04/02/2000
by
Fred
· Published 04/02/2000
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack. Date published : 2000-02-04 http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp
04/02/2000
by
Fred
· Published 04/02/2000
Vulnerability in the Wguest CGI program. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
The Java Web Server would allow remote users to obtain the source code for CGI programs. Date published : 2000-02-04 http://marc.info/?l=bugtraq&m=88256790401004&w=2
04/02/2000
by
Fred
· Published 04/02/2000
Progressive Networks Real Video server (pnserver) can be crashed remotely. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
Netmanager Chameleon SMTPd has several buffer overflows that cause a crash. Date published : 2000-02-04 http://www.insecure.org/sploits/netmanage.chameleon.overflows.html
04/02/2000
by
Fred
· Published 04/02/2000
Bonk variation of teardrop IP fragmentation denial of service. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
Nestea variation of teardrop IP fragmentation denial of service. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
Buffer overflow in ircd allows arbitrary command execution. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. Date published : 2000-02-04
04/02/2000
by
Fred
· Published 04/02/2000
Denial of service in Qmail through long SMTP commands. Date published : 2000-02-04 http://marc.info/?l=bugtraq&m=87602558319024&w=2 http://cr.yp.to/qmail/venema.html