Monthly Archive: March 2000

CVE-2000-0089

The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration...

CVE-2000-0041

Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack. Date published : 2000-03-22 http://www.securityfocus.com/bid/890

CVE-2000-0040

glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command. Date published : 2000-03-22

CVE-2000-0031

The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack. Date published : 2000-03-22

CVE-2000-0026

Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string. Date published : 2000-03-22 http://www.securityfocus.com/bid/876

CVE-2000-0025

IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi,...