<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-06-20" name="CVE-1999-0001" published="1999-12-30" seq="1999-0001" severity="Medium" type="CVE"><desc><descript source="cve">ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1998-13.html">CA-1998-13</ref><ref source="" url="http://www.openbsd.org/errata23.html#tcpfix"></ref><ref source="OSVDB" url="http://www.osvdb.org/5707">5707</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="1.0"/><vers num="1.1"/><vers num="1.1.5.1"/><vers num="1.2"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.5"/><vers num="2.1.5"/><vers num="2.1.6"/><vers num="2.1.6.1"/><vers num="2.1.7"/><vers num="2.1.7.1"/><vers num="2.2"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.8"/><vers num="3.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/><vers num="2.3"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0002" published="1998-10-12" seq="1999-0002" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.12.mountd.html">CA-98.12</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/121">BID 121</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1411.php">linux-mountd-bo(1411)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I">19981006-01-I</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-006.shtml">J-006</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/><vers num="3.0.3"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="1.1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0003" published="1998-04-01" seq="1999-0003" severity="High" type="CVE"><desc><descript source="cve">Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.11.tooltalk.html">CA-98.11</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/122">BID 122</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/813.php">aix-ttdbserver(813)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1408.php">tooltalk(1408)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A">19981101-01-A</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX">19981101-01-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/122">122</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod><prod name="TED CDE" vendor="TriTreal"><vers num="4.3"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers num="1.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.3"/><vers num="10.2"/><vers num="10.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0004" published="1997-12-16" seq="1999-0004" severity="Medium" type="CVE"><desc><descript source="cve">MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-98.10.mime_buffer_overflows.html">CERT:CA-98.10.mime_buffer_overflows</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1217.php">outlook-long-name</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-008.asp">MS98-008</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.0"/></prod><prod name="dtmail" vendor="HP"><vers num=""/></prod><prod name="Pine" vendor="University of Washington"><vers num="4.02"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-1999-0005" published="1998-07-20" seq="1999-0005" severity="High" type="CVE"><desc><descript source="cve">Arbitrary command execution via IMAP buffer overflow in authenticate command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.09.imapd.html">CA-98.09.imapd</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/130">BID 130</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177">00177</ref><ref source="BID" url="http://www.securityfocus.com/bid/130">130</ref></refs><vuln_soft><prod name="Netscape Messaging Server" vendor="Netscape"><vers num="3.55"/></prod><prod name="IMAP" vendor="University of Washington"><vers num="10.234"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0006" published="1998-07-14" seq="1999-0006" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in POP servers based on BSD/Qualcomm&apos;s qpopper allows remote attackers to gain root access using a long PASS command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1890.php">qpopper-pass-overflow(1890)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.08.qpopper_vul.html">CA-98.08.qpopper_vul</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/133">BID 133</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I">19980801-01-I</ref><ref source="BID" url="http://www.securityfocus.com/bid/133">133</ref></refs><vuln_soft><prod name="qpopper" vendor="Qualcomm"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0007" published="1998-06-26" seq="1999-0007" severity="Medium" type="CVE"><desc><descript source="cve">Information from SSL-encrypted sessions via PKCS #1.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.07.PKCS.html">CA-98.07.PKCS</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/676">BID 676</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx">MS98-002</ref></refs><vuln_soft><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/></prod><prod name="SSLeay" vendor="SSLeay"><vers num="0.9"/><vers num="0.8.1"/><vers num="0.6.6"/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/></prod><prod name="Collabra Server" vendor="Netscape"><vers num="3.5.2"/></prod><prod name="exchange srv" vendor="Microsoft"><vers num="5.5"/></prod><prod name="Netscape Messaging Server" vendor="Netscape"><vers num="3.54"/></prod><prod name="Netscape Directory Server" vendor="Netscape"><vers num="3.12"/><vers num="3.1P1"/><vers num="1.3P5"/></prod><prod name="Certificate Server" vendor="Netscape"><vers num="1.0P1"/></prod><prod name="FastTrack" vendor="Netscape"><vers num="3.0.1B"/></prod><prod name="Netscape Proxy Server" vendor="Netscape"><vers num="3.5.1"/></prod><prod name="Secure WebServer" vendor="Open Market"><vers num="2.1"/></prod><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.51"/><vers num="3.0.1b"/><vers num="2.0"/></prod><prod name="StongHold Web Server" vendor="C2Net"><vers num="2.3"/><vers num="2.2"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0008" published="1998-06-08" seq="1999-0008" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NIS+, in Sun&apos;s rpc.nisd program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.06.nisd.html">CA-98.06.nisd</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/962.php">nisd-bo-check(962)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/104">bugtraq id 104</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170">00170</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.34"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0009" published="1998-04-08" seq="1999-0009" severity="High" type="CVE"><desc><descript source="cve">Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.05.bind_problems.html">CA-98.05.bind_problems</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/895.php">bind-bo(895)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/134">BID 134</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref><ref source="BID" url="http://www.securityfocus.com/bid/134">134</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/><vers num="4.0.5 IPR"/><vers num="4.0.5H"/><vers num="4.0.5G"/><vers num="4.0.5F"/><vers num="4.0.5E"/><vers num="4.0.5D"/><vers num="4.0.5A"/><vers num="4.0.5 IOP"/><vers num="4.0.5"/><vers num="4.0.4T"/><vers num="4.0.4B"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1T"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.3.3"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="DG_UX" vendor="Data General"><vers num="5.4_4.11"/><vers num="5.4_4.1"/><vers num="5.4_3.1"/><vers num="5.4_3.0"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/><vers num="5.0"/></prod><prod name="UnixWare" vendor="SCO"><vers num="7.0"/><vers num="2.1"/></prod><prod name="BIND" vendor="ISC"><vers num="8.1.1"/><vers num="8.1"/><vers num="4.9.6"/></prod><prod name="UX_4800" vendor="NEC"><vers num="64"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0010" published="1998-04-08" seq="1999-0010" severity="Medium" type="CVE"><desc><descript source="cve">Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.05.bind_problems.html">CA-98.05.bind_problems</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/896.php">bind-dos(896)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref></refs><vuln_soft><prod name="Unix" vendor="SCO"><vers num="3.2v4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="DG_UX" vendor="Data General"><vers num="Y2K patchR4.20MU03"/><vers num="Y2K patchR4.20MU02"/><vers num="Y2K patchR4.20MU01"/><vers num="Y2K patchR4.11MU05"/><vers num="Y2K patchR4.12MU03"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/><vers num="7.0"/></prod><prod name="BIND" vendor="ISC"><vers num="8"/><vers num="4.9"/></prod><prod name="UX_4800" vendor="NEC"><vers num="11"/><vers num="13"/></prod><prod name="Solaris" vendor="Sun"><vers num="5.3"/><vers num="5.4"/><vers num="5.5"/><vers num="5.5.1"/><vers num="5.6"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1.x"/><vers num="4.2.x"/><vers num="4.3.x"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.2"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-27" name="CVE-1999-0011" published="1998-04-08" seq="1999-0011" severity="High" type="CVE"><desc><descript source="cve">Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.05.bind_problems.html">CA-98.05.bind_problems</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2346.php">bind-axfr-dos (2346)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref></refs><vuln_soft><prod name="Unix" vendor="SCO"><vers num="3.2v4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="DG_UX" vendor="Data General"><vers num="Y2K patchR4.20MU03"/><vers num="Y2K patchR4.20MU02"/><vers num="Y2K patchR4.20MU01"/><vers num="Y2K patchR4.11MU05"/><vers num="Y2K patchR4.12MU03"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/><vers num="7.0"/></prod><prod name="BIND" vendor="ISC"><vers num="8"/><vers num="4.9"/></prod><prod name="UX_4800" vendor="NEC"><vers num="11"/><vers num="13"/></prod><prod name="Solaris" vendor="Sun"><vers num="5.3"/><vers num="5.4"/><vers num="5.5"/><vers num="5.5.1"/><vers num="5.6"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1.x"/><vers num="4.2.x"/><vers num="4.3.x"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.2"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0012" published="1998-02-06" seq="1999-0012" severity="Medium" type="CVE"><desc><descript source="cve">Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.04.Win32.WebServers.html">CA-98.04.Win32.WebServers</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/709.php">nt-web8.3(709)</ref></refs><vuln_soft><prod name="Personal Web Server" vendor="Microsoft"><vers num="4.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.0"/></prod><prod name="Frontpage" vendor="Microsoft"><vers num=""/></prod><prod name="FastTrack" vendor="Netscape"><vers num="2.01"/><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0013" published="1998-01-22" seq="1999-0013" severity="High" type="CVE"><desc><descript source="cve">Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.03.ssh-agent.html">CA-98.03.ssh-agent</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/700.php">ssh-agent(700)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/138">bugtraq id 138</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.14"/><vers num="1.2.13"/><vers num="1.2.12"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0014" published="1998-01-21" seq="1999-0014" severity="High" type="CVE"><desc><descript source="cve">Unauthorized privileged access or denial of service via dtappgather program in CDE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.02.CDE.html">CA-98.02.CDE</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075">HPSBUX9801-075</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185">00185</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.10"/><vers num="10.20"/><vers edition="VVOS" num="10.24"/><vers num="11.0"/></prod><prod name="CDE" vendor="CDE"><vers num="1.2"/><vers num="1.2_x86"/><vers num="1.02"/><vers num="1.02_x86"/><vers num="1.01"/><vers num="1.01_x86"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0015" published="1997-12-16" seq="1999-0015" severity="Medium" type="CVE"><desc><descript source="cve">Teardrop IP denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-97.28.Teardrop_Land.html">CERT:CA-97.28 Denial of Service Attack</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.3u1"/><vers num="4.1.4"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="3.5"/><vers num="3.5.1"/><vers num="4.0"/><vers num="3.5.1 SP1"/><vers num="3.5.1 SP2"/><vers num="4.0 SP1"/><vers num="4.0 SP2"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="0.0a"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.2.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="9.0"/><vers num="9.1"/><vers num="9.3"/><vers num="9.4"/><vers num="9.5"/><vers num="9.7"/><vers num="10"/><vers num="10.1"/><vers num="10.16"/><vers num="10.20"/><vers num="10.24"/><vers num="10.30"/><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0016" published="1997-12-01" seq="1999-0016" severity="Medium" type="CVE"><desc><descript source="cve">Land IP denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1" buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.28.Teardrop_Land.html">CA-97.28.Teardrop_Land</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-98:01.land.asc">FreeBSD-SA-98:01</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1246.php">cisco-land(1246)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/288.php">land(288)</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/770/land-pub.shtml">http://www.cisco.com/warp/public/770/land-pub.shtml</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076">HPSBUX9801-076</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="7000"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.0"/><vers num="1.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.30"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/><vers num="9.4"/><vers num="9.3"/><vers num="9.5"/><vers num="9.7"/><vers num="9.1"/><vers num="9.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3u1"/><vers num="4.1.4"/></prod><prod name="WinSock" vendor="Microsoft"><vers num="2.0"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="inet" vendor="GNU"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0017" published="1997-12-10" seq="1999-0017" severity="High" type="CVE"><desc><descript source="cve">FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.27.FTP_bounce.html">CA-97.27.FTP_bounce</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/199.php">ftp-bounce(199)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/892.php">ftp-privileged-port(892)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.2.1"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.5.1"/><vers edition="x86" num="5.5.1"/><vers num="5.5"/><vers edition="x86" num="5.5"/><vers num="5.4"/><vers edition="x86" num="5.4"/><vers num="5.3"/><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/></prod><prod name="Wu-ftpd" vendor="Washington University"><vers num="2.4"/></prod><prod name="inet" vendor="GNU"><vers num="5.01"/><vers num="6.01"/><vers num="6.02"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.7"/><vers num="2.1.0"/><vers num="2.0"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="Reliant UNIX" vendor="Siemens"><vers num=""/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.4"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-16" name="CVE-1999-0018" published="1997-12-05" seq="1999-0018" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in statd allows root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.26.statd.html">CA-97.26</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/696.php">statd(696)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/127">127</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="3.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod><prod name="IRIX" vendor="SGI"><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0019" published="1996-04-24" seq="1999-0019" severity="Medium" type="CVE"><desc><descript source="cve">Delete or create a file via rpc.statd, due to invalid information.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.09.rpc.statd.html">CA-96.09.rpc.statd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/109.php">rps-stat(109)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.1"/></prod><prod name="CX_UX" vendor="NightHawk"><vers num=""/></prod><prod name="DG_UX" vendor="Data General"><vers num="4.11"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="2"/><vers num="3"/></prod><prod name="Unixware" vendor="SCO"><vers num="2"/></prod><prod name="MP-RAS" vendor="NCR"><vers num="2.03"/><vers num="3.0"/></prod><prod name="PowerUX" vendor="NightHawk"><vers num=""/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.4"/><vers num="5.3"/><vers num="5.4"/><vers edition="x86" num="5.4"/><vers num="5.5"/><vers edition="x86" num="5.5"/></prod><prod name="OpenServer" vendor="SCO"><vers num="3.0"/><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-1999-0020" published="1999-01-01" reject="1" seq="1999-0020" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0032.  Reason: This candidate is a duplicate of CVE-1999-0032.  Notes: All CVE users should reference CVE-1999-0032 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0021" published="1997-11-05" seq="1999-0021" severity="High" type="CVE"><desc><descript source="cve">Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.24.Count_cgi.html">CA-97.24.Count_cgi</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/586.php">http-cgi-count(586)</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/128">bugtraq id 128</ref><ref source="BID" url="http://www.securityfocus.com/bid/128">128</ref></refs><vuln_soft><prod name="wwwcount" vendor="Muhammad A. Muquit"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0022" published="1996-07-03" seq="1999-0022" severity="High" type="CVE"><desc><descript source="cve">Local user gains root privileges via buffer overflow in rdist, via expstr() function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.23.rdist.html">CA-97.23.rdist</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/129">BID 129</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/559.php">rdist-bo3(559)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/540.php">rdist-sept97(540)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/><vers num="3.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers edition="U1" num="4.1.3"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="1.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.0"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0023" published="1996-07-24" seq="1999-0023" severity="High" type="CVE"><desc><descript source="cve">Local user gains root privileges via buffer overflow in rdist, via lookup() function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.14.rdist_vul.html">CA-96.14.rdist_vul</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/421.php">rdist-bo(421)</ref></refs><vuln_soft><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.2"/><vers num="5.0"/><vers num="2.0"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.0"/><vers num="2.0.5"/><vers num="2.1.0"/><vers num="2.2"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="2.0"/><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.0"/><vers num="2.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="1.1"/><vers num="1.1.1a"/><vers num="1.1.2"/><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.3u1"/><vers num="4.1.4"/><vers num="5.3"/><vers num="5.4"/><vers num="5.5"/><vers num="5.5.1"/></prod><prod name="TCP/IP" vendor="SCO"><vers num="1.2.0"/><vers num="1.2.1"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod><prod name="inet" vendor="inet"><vers num="5.01"/><vers num="6.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-05-19" name="CVE-1999-0024" published="1997-08-13" seq="1999-0024" severity="Medium" type="CVE"><desc><descript source="cve">DNS cache poisoning via BIND, by predictable query IDs.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.22.bind.html">CA-97.22.bind</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/485.php">bind(485)</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/678">BID 678</ref></refs><vuln_soft><prod name="Unix" vendor="SCO"><vers num="3.2v4"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/></prod><prod name="BIND" vendor="ISC"><vers num="8.1"/><vers num="4.9.5"/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num="4.2MP"/><vers num="4.2"/></prod><prod name="UX_4800" vendor="NEC"><vers num="64"/></prod><prod name="UP-UX_V" vendor="NEC"><vers num="4.2MP"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0025" published="1997-07-16" seq="1999-0025" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in df command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/440.php">AUSCERT:AA-97.19.IRIX.df.buffer.overflow.vul,XF:df-bo</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CA-1997-21</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/20851">VU#20851</ref><ref source="BID" url="http://www.securityfocus.com/bid/346">346</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/440">df-bo(440)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0026" published="1997-07-16" seq="1999-0026" severity="Medium" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in pset command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/442.php">pset-bo(442)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0027" published="1997-07-16" seq="1999-0027" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in eject command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CERT:CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/441.php">AUSCERT:AA-97.21.IRIX.eject.buffer.overflow.vul,XF:eject-bo</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0028" published="1997-07-16" seq="1999-0028" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/443.php">sgi-schemebo(443)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0029" published="1997-07-16" seq="1999-0029" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in ordist command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/444.php">ordist-bo(444)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0030" published="1997-07-16" seq="1999-0030" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in xlock command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CERT:CA-97.21.sgi_buffer_overflow</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0031" published="1997-07-08" seq="1999-0031" severity="Low" type="CVE"><desc><descript source="cve">JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user&apos;s web activities, aka the Bell Labs vulnerability.</descript></desc><loss_types><conf/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.20.javascript.html">CA-97.20 JavaScript Vulnerability</ref><ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html">HPSBUX9707-065</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="2.0"/><vers num="3.0"/><vers num="4.0"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0.0"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0032" published="1996-10-25" seq="1999-0032" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.19.bsdlp.html">CA-97.19.bsdlp</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/707">BID 707</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/843.php">lpr-bo(843)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/409.php">bsd-lprbo(409)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/446.php">bsd-lprbo2(446)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/707">707</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="NeXTstep" vendor="NeXT"><vers num="4.1"/><vers num="4.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0033" published="1997-06-12" seq="1999-0033" severity="High" type="CVE"><desc><descript source="cve">Command execution in Sun systems via buffer overflow in the at program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-97.18.at.html">Vulnerability in the At(1) program</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/705.php">sun-atbo(705)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num=""/></prod><prod name="MP-RAS" vendor="NCR"><vers num="3.0"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="OpenServer" vendor="SCO"><vers num="3.0"/><vers num="5.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.3"/><vers edition="x86" num="5.4"/><vers num="5.4"/><vers edition="x86" num="5.5"/><vers num="5.5"/><vers edition="x86" num="5.5.1"/><vers num="5.5.1"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/><vers num="3.2v4"/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0034" published="1997-05-29" seq="1999-0034" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.17.sperl.html">CA-97.17.sperl</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/448.php">perl-suid(448)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/708">bugtraq id 708</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="Perl" vendor="Larry Wall"><vers num="5.3"/></prod><prod name="Freeware" vendor="SGI"><vers num="2.0"/><vers num="1.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-07" name="CVE-1999-0035" published="1997-05-29" seq="1999-0035" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.16.ftpd.html">CA-97.16.ftpd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/449.php">ftp-ftpd(449)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod><prod name="inet" vendor="GNU"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0036" published="1997-05-26" seq="1999-0036" severity="High" type="CVE"><desc><descript source="cve">IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.15.sgi_login.html">CA-97.15.sgi_login</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/392">bugtraq id 392</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/557.php">sgi-lockout(557)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-106.shtml">H-106</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX">19970508-02-PX</ref><ref source="OSVDB" url="http://www.osvdb.org/990">990</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/557">sgi-lockout(557)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0037" published="1997-05-21" seq="1999-0037" severity="High" type="CVE"><desc><descript source="cve">Arbitrary command execution via metamail package using message headers, when user processes attacker&apos;s message using metamail.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.14.metamail.html">CA-97.14.metamail</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1676.php">metamail-header-commands(1676)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Linux" vendor="Red Hat"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0038" published="1997-04-26" seq="1999-0038" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in xlock program allows local users to execute commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.13.xlock.html">CA-97.13.xlock</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/224">BID 224</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/483.php">xlock-bo(483)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="DG_UX" vendor="Data General"><vers num="7.0"/><vers num="6.0"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.8"/><vers num="10.34"/><vers num="10.30"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="0.93"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0039" published="1997-05-06" seq="1999-0039" severity="High" type="CVE"><desc><descript source="cve">webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.12.webdist.html">CA-97.12.webdist</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/374">BID 374</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/333.php">http-sgi-webdist(333)</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1997-12.html">CA-1997-12</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/374">374</ref><ref source="OSVDB" url="http://www.osvdb.org/235">235</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/333">http-sgi-webdist(333)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0040" published="1997-05-01" seq="1999-0040" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.11.libXt.html">CA-97.11.libXt</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/237">BID 237</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/489.php">libXt-bo(489)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.0"/><vers num="4.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/><vers num="4.1.3"/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num="4.2MP"/><vers num="4.2"/></prod><prod name="UX_4800" vendor="NEC"><vers num="64"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="HP-UX" vendor="HP"><vers num="9.10"/><vers num="9.1"/><vers num="9.0"/><vers num="10.9"/><vers num="10.8"/><vers num="10.34"/><vers num="10.30"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.0"/><vers num="1.1.5.1"/></prod><prod name="UP-UX_V" vendor="NEC"><vers num="4.2MP"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0041" published="1997-02-13" seq="1999-0041" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NLS (Natural Language Service).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.10.nls.html">CA-97.10.nls</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/711">BID 711</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/450.php">nls-bo(450)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2.5"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.0"/></prod><prod name="libc" vendor="Linux"><vers num="5.3.12"/><vers num="5.2.18"/><vers num="5.0.9"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="3.1"/></prod><prod name="UNICOS_mk" vendor="Cray"><vers num="1.5"/></prod><prod name="UNICOS" vendor="Cray"><vers num="9.2"/><vers num="9.0"/><vers num="1.3 MAX"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0042" published="1997-04-07" seq="1999-0042" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in University of Washington&apos;s implementation of IMAP and POP servers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.09.imap_pop.html">CA-97.09.imap_pop</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/96.php">popimap-bo(96)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.0"/><vers num="2.0"/></prod><prod name="IMAP" vendor="University of Washington"><vers num="4"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="3.0"/></prod><prod name="POP" vendor="University of Washington"><vers num="3"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-1999-0043" published="1996-12-04" seq="1999-0043" severity="High" type="CVE"><desc><descript source="cve">Command execution via shell metachars in INN daemon (innd) 1.5 using &quot;newgroup&quot; and &quot;rmgroup&quot; control messages, and others.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.08.innd.html">CA-97.08.innd</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=580o28$9jp@senator-bedfellow.MIT.EDU"></ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/687">BID 687</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/184.php">inn-controlmsg(184)</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="1.5"/><vers num="1.4unoff4"/><vers num="1.4unoff3"/><vers num="1.4sec2"/><vers num="1.4sec"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.1"/><vers num="4.0"/></prod><prod name="Goah_NetworkSV" vendor="NEC"><vers num="3.1"/><vers num="2.2"/><vers num="1.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod><prod name="News Server" vendor="Netscape"><vers num="1.1"/></prod><prod name="Goah_IntraSV" vendor="NEC"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0044" published="1996-12-03" seq="1999-0044" severity="High" type="CVE"><desc><descript source="cve">fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/355">BID 355</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2106.php">sgi-fsdump(2106)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0045" published="1996-12-10" seq="1999-0045" severity="High" type="CVE"><desc><descript source="cve">List of arbitrary files on Web host via nph-test-cgi script.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.07.nph-test-cgi_script.html">CA-97.07.nph-test-cgi_script</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/686">BID 686</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/289.php">http-cgi-nph(289)</ref></refs><vuln_soft><prod name="Netscape Commerce Server" vendor="Netscape"><vers num="1.12"/></prod><prod name="Netscape Communications Server" vendor="Netscape"><vers num="1.12"/><vers num="1.1"/></prod><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="2.0a"/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.1"/><vers num="1.0.5"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0"/><vers num="0.8.14"/><vers num="0.8.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0046" published="1997-02-06" seq="1999-0046" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow of rlogin program using TERM environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.06.rlogin-term.html">CA-97.06.rlogin-term</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/242">BID 242</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/423.php">rlogin-termbo(423)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.1"/><vers num="1.0"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0B"/><vers num="4.0A"/><vers num="4.0"/><vers num="3.2G"/></prod><prod name="Ultrix" vendor="Digital"><vers num="4.5"/><vers num="4.4"/><vers num="4.3a"/><vers num="4.3"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/><vers num="2.2"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="NeXTstep" vendor="NeXT"><vers num="4.0"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.1"/><vers num="2.0"/><vers num="1.0a"/><vers num="1.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="0.93"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.9"/><vers num="10.8"/><vers num="10.34"/><vers num="10.30"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/></prod><prod name="DG_UX" vendor="Data General"><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0047" published="1997-01-28" seq="1999-0047" severity="High" type="CVE"><desc><descript source="cve">MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.05.sendmail.html">CA-97.05.sendmail</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/685">bugtraq id 685</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1835.php">sendmail-mime-bo2(1835)</ref><ref source="BID" url="http://www.securityfocus.com/bid/685">685</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.8.4"/><vers num="8.8.3"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-07" name="CVE-1999-0048" published="1997-01-27" seq="1999-0048" severity="High" type="CVE"><desc><descript source="cve">Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.04.talkd.html">CA-97.04.talkd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/453.php">talkd-bo(453)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/413.php">netkit-talkd(413)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147">00147</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.1"/><vers num="4.1"/><vers num="4.2"/></prod><prod name="NetKit" vendor="Debian"><vers num="0.07"/></prod><prod name="UP-UX_V" vendor="NEC"><vers num=""/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num=""/></prod><prod name="UX_4800" vendor="NEC"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0049" published="1997-01-08" seq="1999-0049" severity="High" type="CVE"><desc><descript source="cve">Csetup under IRIX allows arbitrary file creation or overwriting.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.03.csetup.html">CA_97.04.csetup</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/452.php">sgi-csetup(452)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0050" published="1996-12-01" seq="1999-0050" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HP-UX newgrp program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.02.hp_newgrp.html">CA-97.02.hp_newgrp</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/683">BID 683</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/451.php">hp-newgrpbo(451)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.9"/><vers num="9.8"/><vers num="9.7"/><vers num="9.6"/><vers num="9.5"/><vers num="9.4"/><vers num="9.3"/><vers num="9.10"/><vers num="9.1"/><vers num="9.0"/><vers num="10.20"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0051" published="1997-01-06" seq="1999-0051" severity="High" type="CVE"><desc><descript source="cve">Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.01.flex_lm.html">CA-97.01.flex_lm</ref><ref source="Security Focus" url="http://securityfocus.com/vdb/cve.html?cve=CVE-1999-0051"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/893.php">sgi-licensemanager(893)</ref></refs><vuln_soft><prod name="license_oeo" vendor="SGI"><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4JL"/><vers num="4.1.4"/><vers num="4.1.3u1"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/><vers num="4.0.5 IPR"/><vers num="4.0.5H"/><vers num="4.0.5G"/><vers num="4.0.5F"/><vers num="4.0.5E"/><vers num="4.0.5D"/><vers num="4.0.5A"/><vers num="4.0.5 IOP"/><vers num="4.0.5"/><vers num="4.0.4T"/><vers num="4.0.4B"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1T"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.3.3"/><vers num="3.3.2"/></prod><prod name="FLEXlm" vendor="GLOBEtrotter"><vers num="5.0"/><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0052" published="1998-11-04" seq="1999-0052" severity="Medium" type="CVE"><desc><descript source="cve">IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/120">BID 120</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1389.php">freebsd-ip-frag-dos(1389)</ref><ref source="OSVDB" url="http://www.osvdb.org/908">908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1389">freebsd-ip-frag-dos(1389)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2.8"/><vers num="2.2.2"/><vers num="2.1.7.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0053" published="1998-10-13" seq="1999-0053" severity="Medium" type="CVE"><desc><descript source="cve">TCP RST denial of service in FreeBSD.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/6094">6094</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0054" published="1998-06-10" seq="1999-0054" severity="Medium" type="CVE"><desc><descript source="cve">Sun&apos;s ftpd daemon can be subjected to a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/709">BID 709</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1127.php">sun-ftpd(1127)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171">00171</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0055" published="1998-05-14" seq="1999-0055" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Sun libnsl allow root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/148">BID 148</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1204.php">sun-libnsl(1024)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172">00172</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only">IX80543</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0056" published="1998-09-09" seq="1999-0056" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Sun&apos;s ping program can give root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1365.php">sun-ping(1365)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174">00174</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/></prod><prod name="SunOS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-07" name="CVE-1999-0057" published="1998-11-16" seq="1999-0057" severity="High" type="CVE"><desc><descript source="cve">Vacation program allows command execution by remote users through a sendmail command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/569.php">vacation(569)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087">HPSBUX9811-087</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Vacation" vendor="Eric Allman"><vers num=""/></prod><prod name="VVOS" vendor="HP"><vers num=""/></prod><prod name="Solaris" vendor="Sun"><vers num=""/></prod><prod name="SunOS" vendor="Sun"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num="10.24"/><vers num="10.0"/><vers num="10.9"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0058" published="1997-04-17" seq="1999-0058" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in PHP cgi program, php.cgi allows shell access.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/712">bugtraq id 712</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/293.php">http-cgi-phpbo(293)</ref><ref source="BID" url="http://www.securityfocus.com/bid/712">712</ref></refs><vuln_soft><prod name="PHP_FI" vendor="PHP"><vers num="2.0b10"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0059" published="1997-07-14" seq="1999-0059" severity="High" type="CVE"><desc><descript source="cve">IRIX fam service allows an attacker to obtain a list of all files on the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/353">bugtraq id 353</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/325.php">irix-fam(325)</ref><ref source="BID" url="http://www.securityfocus.com/bid/353">353</ref><ref source="OSVDB" url="http://www.osvdb.org/164">164</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/325">irix-fam(325)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0060" published="1998-03-16" seq="1999-0060" severity="Medium" type="CVE"><desc><descript source="cve">Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/714">BID 714</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/889.php">ascend-config-kill(889)</ref><ref source="ASCEND" url="http://www.ascend.com/2695.html">http://www.ascend.com/2695.html</ref></refs><vuln_soft><prod name="Ascend TNT Router" vendor="Lucent"><vers num="2.0"/><vers num="1.0"/></prod><prod name="Ascend Pipeline Router" vendor="Lucent"><vers num="6.0"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="Ascend MAX Router" vendor="Lucent"><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0061" published="1997-10-02" seq="1999-0061" severity="Medium" type="CVE"><desc><descript source="cve">File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/568.php">bsd-lpd(568)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.1"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0062" published="1998-08-03" seq="1999-0062" severity="High" type="CVE"><desc><descript source="cve">The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1220.php">openbsd-chpass(1220)</ref><ref source="OSVDB" url="http://www.osvdb.org/7559">7559</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0063" published="1999-01-11" seq="1999-0063" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/iossyslog-pub.shtml"></ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/675">BID 675</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1558.php">cisco-syslog-crash(1558)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0.2XD"/><vers num="12.0.2XC"/><vers num="12.0.1XE"/><vers num="12.0.1XB"/><vers num="12.0.1XA3"/><vers num="12.0.1W"/><vers num="12.0T"/><vers num="12.0S"/><vers num="12.0DB"/><vers num="12.0"/><vers num="11.3DB"/><vers num="11.3AA"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0064" published="1997-05-26" seq="1999-0064" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX lquerylv program gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/451">BID 451</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/386.php">lquerylv-bo(386)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0065" published="1998-08-31" seq="1999-0065" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/175">BID 175</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1367.php">hp-dtmail(1367)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181">00181</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0066" published="1995-07-31" seq="1999-0066" severity="High" type="CVE"><desc><descript source="cve">AnyForm CGI remote execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/719">BID 719</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/301.php">http-cgi-anyform(301)</ref><ref source="BID" url="http://www.securityfocus.com/bid/719">719</ref></refs><vuln_soft><prod name="AnyForm" vendor="John S. Roberts"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0067" published="1996-03-20" seq="1999-0067" severity="High" type="CVE"><desc><descript source="cve">phf CGI program allows remote command execution through shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/629">bugtraq id 629</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-96.06.cgi_example_code.html">CA-96.06.cgi_example_code</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/148.php">http-cgi-phf(148)</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</ref><ref source="BID" url="http://www.securityfocus.com/bid/629">629</ref><ref source="OSVDB" url="http://www.osvdb.org/136">136</ref></refs><vuln_soft><prod name="NCSA httpd" vendor="NCSA"><vers edition="export" num="1.5a"/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0068" published="1997-10-19" seq="1999-0068" severity="High" type="CVE"><desc><descript source="cve">CGI PHP mylog script allows an attacker to read any file on the target server.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/713">bugtraq id 713</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1468.php">http-cgi-php-mylog(1468)</ref><ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref><ref source="OSVDB" url="http://www.osvdb.org/3396">3396</ref></refs><vuln_soft><prod name="PHP_FI" vendor="PHP"><vers num="2.0b10"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0069" published="1998-04-29" seq="1999-0069" severity="High" type="CVE"><desc><descript source="cve">Solaris ufsrestore buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/966.php">sun-ufsrestore(966)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169">00169</ref><ref source="OSVDB" url="http://www.osvdb.org/8158">8158</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5"/><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0070" published="1996-04-01" seq="1999-0070" severity="Medium" type="CVE"><desc><descript source="cve">test-cgi program allows an attacker to list files on the server.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/149.php">http-cgi-test(149)</ref></refs><vuln_soft><prod name="NCSA Web Server" vendor="NCSA"><vers num=""/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0071" published="1997-09-01" seq="1999-0071" severity="High" type="CVE"><desc><descript source="cve">Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/331.php">http-apache-cookie</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0072" published="1997-10-22" seq="1999-0072" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX xdat gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/449">bugtraq id 449</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/585.php">ibm-xdat(585)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0073" published="1995-10-13" seq="1999-0073" severity="High" type="CVE"><desc><descript source="cve">Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.14.Telnetd_Environment_Vulnerability.html">CA-95.14.Telnetd_Environment_Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/459">BID 459</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/67.php">linkerbug(67)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0"/><vers num="3.2G"/></prod><prod name="OSF_1" vendor="Digital"><vers num="3.2"/><vers num="3.0"/><vers num="2.0"/><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0074" published="1997-07-01" seq="1999-0074" severity="Medium" type="CVE"><desc><descript source="cve">Listening TCP ports are sequentially allocated, allowing spoofing attacks.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/209.php">seqport(209)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0075" published="1996-10-16" seq="1999-0075" severity="Medium" type="CVE"><desc><descript source="cve">PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/200.php">ftp-pasvcore(200)</ref><ref source="OSVDB" url="http://www.osvdb.org/5742">5742</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0076" published="1997-07-01" seq="1999-0076" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in wu-ftp from PASV command causes a core dump.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/201.php">ftp-args(201)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0077" published="1995-01-01" seq="1999-0077" severity="Medium" type="CVE"><desc><descript source="cve">Predictable TCP sequence numbers allow spoofing.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/vdb/cve.html?cve=CVE-1999-0077"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/139.php">tcp-seq-predict(139)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0078" published="1996-04-18" seq="1999-0078" severity="Low" type="CVE"><desc><descript source="cve">pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-96.08.pcnfsd.html">Vulnerabilities in PCNFSD</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.3"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1"/></prod><prod name="NeXTstep" vendor="NeXT"><vers num=""/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers num="2.5"/></prod><prod name="MP-RAS" vendor="NCR"><vers num="2.03"/><vers num="3.0"/><vers num="3.01"/></prod><prod name="UP-UX_V" vendor="NEC"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0079" published="1997-09-12" seq="1999-0079" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/271">bugtraq id 271</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/563.php">ftp-pasv-dos(563)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/202.php">ftp-pasvdos(202)</ref></refs><vuln_soft><prod name="BisonWare FTP Server" vendor="BisonWare"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0080" published="1995-11-30" seq="1999-0080" severity="High" type="CVE"><desc><descript source="cve">Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the &quot;site exec&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.16.wu-ftpd.vul.html">CA-95.16.wu-ftpd.vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/618.php">ftp-execdotdot(618)</ref></refs><vuln_soft><prod name="Wu-ftpd" vendor="Washington University"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0081" published="1997-01-11" seq="1999-0081" severity="Medium" type="CVE"><desc><descript source="cve">wu-ftp allows files to be overwritten via the rnfr command.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/324.php">ftp-rnfr(324)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0082" published="1988-11-11" seq="1999-0082" severity="High" type="CVE"><desc><descript source="cve">CWD ~root command in ftpd allows root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/54.php">ftp-cwd(54)</ref><ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref></refs><vuln_soft><prod name="FTP" vendor="FTP"><vers num=""/></prod><prod name="ftpcd" vendor="ftpcd"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0083" published="1997-06-11" seq="1999-0083" severity="Medium" type="CVE"><desc><descript source="cve">getcwd() file descriptor leak in FTP.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/335.php">cwdleak(335)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0084" published="1990-05-01" seq="1999-0084" severity="High" type="CVE"><desc><descript source="cve">Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/78">nfs-mknod(78)</ref></refs><vuln_soft><prod name="NFS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0085" published="1996-08-21" seq="1999-0085" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/118.php">rwhod-vuln(118)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/119">rwhod(119)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/118">rwhod-vuln(118)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0086" published="1998-01-08" seq="1999-0086" severity="Medium" type="CVE"><desc><descript source="cve">AIX routed allows remote users to modify sensitive files.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-2_num-1.php">IBM-routed</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.x"/><vers num="4.1.x"/><vers num="4.2.x"/><vers num="4.3.x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0087" published="1998-02-01" seq="1999-0087" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/706.php">ibm-telnetdos(706)</ref><ref source="OSVDB" url="http://www.osvdb.org/7992">7992</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0088" published="1998-10-26" seq="1999-0088" severity="High" type="CVE"><desc><descript source="cve">IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0089" published="1997-10-28" seq="1999-0089" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX libDtSvc library can allow local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs/><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0090" published="1997-10-01" seq="1999-0090" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX rcp command allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/400">BID 400</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2296.php">ibm-rcp(2296)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0091" published="1997-10-28" seq="1999-0091" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX writesrv command allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/399">BID 399</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2295.php">ibm-writesrv(2295)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0092" published="1997-10-29" seq="1999-0092" severity="High" type="CVE"><desc><descript source="cve">Various vulnerabilities in the AIX portmir command allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-1_num-6.phpportmir">IBM-portmir</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0093" published="1997-10-29" seq="1999-0093" severity="High" type="CVE"><desc><descript source="cve">AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/377">BID 377</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/604.php">ibm-nslookup(604)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0094" published="1997-10-29" seq="1999-0094" severity="Medium" type="CVE"><desc><descript source="cve">AIX piodmgrsu command allows local users to gain additional group privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/386">BID 386</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/593.php">ibm-piodmgrsu(593)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0095" published="1988-10-01" seq="1999-0095" severity="High" type="CVE"><desc><descript source="cve">The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-88.01.ftpd.hole.html">CA-88.01</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-93.14.Internet.Security.Scanner.html">CA-93.14</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1">BID 1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1">1</ref><ref source="OSVDB" url="http://www.osvdb.org/195">195</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="5.58"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0096" published="1996-12-10" seq="1999-0096" severity="Medium" type="CVE"><desc><descript source="cve">Sendmail decode alias can be used to overwrite sensitive files.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.25.sendmail_groups.html">CA-96.25.sendmail_groups</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/126.php">smtp-dcod(126)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.5"/><vers num="2.1.6"/><vers num="2.1.6.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/><vers num="5.0.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0097" published="1997-10-29" seq="1999-0097" severity="High" type="CVE"><desc><descript source="cve">The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/396">BID 396</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/605.php">ibm-ftp(605)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3c"/><vers num="4.1.3u1"/></prod><prod name="HP-UX" vendor="HP"><vers num="9.9"/><vers num="9.8"/><vers num="9.7"/><vers num="9.6"/><vers num="9.5"/><vers num="9.4"/><vers num="9.3"/><vers num="9.10"/><vers num="9.1"/><vers num="9.0"/><vers num="11.0"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0098" published="1998-04-01" seq="1999-0098" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/886.php">smtp-helo-bo(886)</ref></refs><vuln_soft><prod name="Slmail" vendor="Slmail"><vers num="2.6"/></prod><prod name="AppleShare IP" vendor="Apple"><vers num=""/></prod><prod name="Mercury Mail Server" vendor="Mercury"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0099" published="1995-10-19" seq="1999-0099" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.13.syslog.vul.html">CA-95.13</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/129.php">smtp-syslog(129)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="3.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.0"/><vers num="2.0.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers edition="x86" num="2.4"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.3u1"/><vers num="4.1.4"/></prod><prod name="SPP-UX" vendor="Convex"><vers num="3"/></prod><prod name="ConvexOS" vendor="Convex"><vers num="10.1"/><vers num="10.2"/><vers num="11.0"/><vers num="11.1"/></prod><prod name="UNICOS" vendor="Cray"><vers num="8.0"/><vers num="8.3"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0100" published="1997-01-01" seq="1999-0100" severity="High" type="CVE"><desc><descript source="cve">Remote access in AIX innd 1.5.1, using control messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/184.php">inn-controlmsg(184)</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0101" published="1996-12-10" seq="1999-0101" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX and Solaris &quot;gethostbyname&quot; library call allows root access through corrupt DNS host names.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">IBM AIX(r) Security Vulnerabilities (gethostbyname,lquerypv)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1751.php">ghbn-bo(1751)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0102" published="1998-07-09" seq="1999-0102" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/153">bugtraq id 153</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1595.php">slmail-fromheader-overflow(1595)</ref></refs><vuln_soft><prod name="SLMail" vendor="Seattle Lab Software"><vers num="3.0.2421"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0103" published="1996-02-08" seq="1999-0103" severity="Medium" type="CVE"><desc><descript source="cve">Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.01.UDP_service_denial.html">CA-96.01.UDP_service_denial</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0104" published="1997-12-16" seq="1999-0104" severity="Medium" type="CVE"><desc><descript source="cve">A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-97.28.Teardrop_Land.html">IP Denial of Service</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/343.php">teardrop-mod</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="4.0 SP1"/><vers num="4.0 SP2"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="0a"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="2.0"/></prod><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0105" published="1997-03-01" seq="1999-0105" severity="Low" type="CVE"><desc><descript source="cve">finger allows recursive searches by using a long string of @ symbols.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/47.php">fingerbomb</ref></refs></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0106" published="1997-03-01" seq="1999-0106" severity="Low" type="CVE"><desc><descript source="cve">Finger redirection allows finger bombs.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/47.php">fingerbomb</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0107" published="1997-12-30" seq="1999-0107" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-1_num-10.phplist">apache-dos</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="0.8.11"/><vers num="0.8.14"/><vers num="1.0"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.5"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0108" published="1998-05-01" seq="1999-0108" severity="High" type="CVE"><desc><descript source="cve">The printers program in IRIX has a buffer overflow that gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/808.php">printers-bo(808)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0109" published="1997-02-10" seq="1999-0109" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ffbconfig in Solaris 2.5.1.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/202">BID 202</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/874.php">ffbconfig-bo(874)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140">00140</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-1999-0110" published="1999-01-01" reject="1" seq="1999-0110" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0315.  Reason: This candidate&apos;s original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315.  Notes: All CVE users should reference CVE-1999-0315 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0111" published="1997-07-01" seq="1999-0111" severity="Medium" type="CVE"><desc><descript source="cve">RIP v1 is susceptible to spoofing.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/703.php">ibm-routed(703)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0112" published="1997-05-01" seq="1999-0112" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX dtterm program for the CDE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/878.php">dtterm-bo(878)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/878">dtterm-bo(878)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.2"/></prod><prod name="CDE" vendor="CDE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0113" published="1994-05-23" seq="1999-0113" severity="High" type="CVE"><desc><descript source="cve">Some implementations of rlogin allow root access if given a -froot parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.09.bin.login.vulnerability.html">CA-94.09.bin.login.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/104.php">rlogin-froot(104)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/458">BID 458</ref><ref source="BID" url="http://www.securityfocus.com/bid/458">458</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0114" published="1998-01-01" seq="1999-0114" severity="Medium" type="CVE"><desc><descript source="cve">Local users can execute commands as other users, and read other users&apos; files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/711.php">elm-filter2(711)</ref></refs><vuln_soft><prod name="ELM" vendor="Elm Development Group"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-21" name="CVE-1999-0115" published="1997-09-01" seq="1999-0115" severity="High" type="CVE"><desc><descript source="cve">AIX bugfiler program allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/500.php">ibm-bugfiler(500)</ref><ref adv="1" source="CA" url="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=13">AIX bugfiler file creation vulnerability</ref><ref source="insecure" url="http://www.insecure.org/sploits/aix.bugfiler.html">AIX bugfiler</ref><ref source="BID" url="http://www.securityfocus.com/bid/1800">1800</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.1"/><vers num="3.2"/><vers num="3.2.4"/><vers num="3.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0116" published="1996-09-19" seq="1999-0116" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.21.tcp_syn_flooding.html">CA-96.21.tcp_syn.flooding</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2.5"/></prod><prod name="SNG" vendor="IBM"><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0117" published="1992-03-31" seq="1999-0117" severity="High" type="CVE"><desc><descript source="cve">AIX passwd allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-92.07.AIX.passwd.vulnerability.html">CA-92.07.AIX.passwd.vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/555.php">ibm-passwd(555)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0118" published="1998-11-01" seq="1999-0118" severity="High" type="CVE"><desc><descript source="cve">AIX infod allows local users to gain root access through an X display.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1407.php">aix-infod(1407)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91158980826979&amp;w=2">19981119 RSI.0011.11-09-98.AIX.INFOD</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0119" published="1999-01-19" seq="1999-0119" severity="High" type="CVE"><desc><descript source="cve">Windows NT 4.0 beta allows users to read and delete shares.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0120" published="1994-03-21" seq="1999-0120" severity="High" type="CVE"><desc><descript source="cve">Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.06.utmp.vulnerability.html">CA-94.06.umtp.vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/506.php">utmp-write(506)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="1.1.1a"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0121" published="1999-01-21" seq="1999-0121" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in dtaction command gives root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0122" published="1997-07-21" seq="1999-0122" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX lchangelv gives root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/389">bugtraq id 389</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/845.php">lchangelv-bo(845)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0123" published="1995-12-01" seq="1999-0123" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Linux mailx command allows local users to read user files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs/><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0124" published="1993-08-09" seq="1999-0124" severity="High" type="CVE"><desc><descript source="cve">Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/544.php">gopher-vuln(544)</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-93.11.UMN.UNIX.gopher.vulnerability.html">CA-93.11.UMN.UNIX.gopher.vulnerability</ref></refs><vuln_soft><prod name="gopherd" vendor="University of Minnesota"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0125" published="1998-01-25" seq="1999-0125" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in SGI IRIX mailx program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/393">BID 393</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1371.php">sgi-mailx-bo(1371)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX">19980605-01-PX</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers edition="HW3" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="5.3"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0126" published="1998-05-03" seq="1999-0126" severity="High" type="CVE"><desc><descript source="cve">SGI IRIX buffer overflow in xterm and Xaw allows root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vul_notes/VN-98.01.XFree86.html">VN-98.01.XFree86</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/963.php">xfree86-xterm-xaw(963)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2096.php">xfree86-xaw(2096)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-010.shtml">J-010</ref></refs><vuln_soft><prod name="XFree86" vendor="XFree86 Project"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0127" published="1996-12-19" seq="1999-0127" severity="High" type="CVE"><desc><descript source="cve">swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://www.cert.org/advisories/CA-96.27.hp_sw_install.html">Vulnerability in HP Software Installation Programs</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0128" published="1996-12-18" seq="1999-0128" severity="Medium" type="CVE"><desc><descript source="cve">Oversized ICMP ping packets can result in a denial of service, aka Ping o&apos; Death.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.26.ping.html">CA-96.26.ping</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/95.php">ping-death(95)</ref></refs><vuln_soft><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/><vers num="1.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/><vers num="5.0.2"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.5.1"/><vers edition="x86" num="5.5.1"/><vers num="5.5"/><vers edition="x86" num="5.5"/><vers num="5.4"/><vers edition="x86" num="5.4"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="OSF_1" vendor="Digital"><vers num="1.3.3"/></prod><prod name="SNG" vendor="IBM"><vers num="2.2"/><vers num="2.1"/><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num="1.3"/><vers num="2.0"/></prod><prod name="TCP/IP" vendor="SCO"><vers num="1.2.1"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0129" published="1996-12-03" seq="1999-0129" severity="Medium" type="CVE"><desc><descript source="cve">Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.25.sendmail_groups.html">CA-96.25.sendmail_groups</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/715">BID 715</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="1.1"/><vers num="1.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="Sendmail" vendor="Eric Allman"><vers num="8.8.3"/><vers num="8.8.2"/><vers num="8.8.1"/><vers num="8.8"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.6.1"/><vers num="2.1.6"/><vers num="2.1.5"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.2"/><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0130" published="1996-11-16" seq="1999-0130" severity="High" type="CVE"><desc><descript source="cve">Local users can start Sendmail in daemon mode and gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.24.sendmail.daemon.mode.html">CA-96.24.sendmail.daemon.mode</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/716">BID 716</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1837.php">sendmail-daemon-mode(1837)</ref><ref source="BID" url="http://www.securityfocus.com/bid/716">716</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.6"/><vers num="2.1.5"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/></prod><prod name="Network Desktop" vendor="Caldera"><vers num="1.0"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Sendmail" vendor="Eric Allman"><vers num="8.8.2"/><vers num="8.8.1"/><vers num="8.8"/><vers num="8.7"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="10.10"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0131" published="1996-09-11" seq="1999-0131" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.20.sendmail_vul.html">CA-96.20.sendmal_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/428.php">smtp-875bo(428)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/717">BID 717</ref><ref source="BID" url="http://www.securityfocus.com/bid/717">717</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="10.10"/><vers num="10.0.1"/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/></prod><prod name="OSF_1" vendor="Digital"><vers num="1.3.2"/></prod><prod name="Sendmail" vendor="Eric Allman"><vers num="8.7.5"/><vers num="8.7.4"/><vers num="8.7.3"/><vers num="8.7.2"/><vers num="8.7.1"/><vers num="8.6"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.5"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.2"/><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="Linux" vendor="Red Hat"><vers num="3.0.3"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0132" published="1996-08-15" seq="1999-0132" severity="Low" type="CVE"><desc><descript source="cve">Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.19.expreserve.html">CA-96.19.expreserve</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/401.php">expreserve(401)</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</ref><ref source="OSVDB" url="http://www.osvdb.org/11723">11723</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/401">expreserve(401)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/><vers edition="x86" num="2.4"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.3c"/><vers num="4.1.3u1"/></prod><prod name="HP-UX" vendor="HP"><vers num="9"/><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0133" published="1996-08-14" seq="1999-0133" severity="Low" type="CVE"><desc><descript source="cve">fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.18.fm_fls.html">CA-96.18.fm_fls</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/403.php">fmaker-logfile(403)</ref></refs><vuln_soft><prod name="FrameMaker" vendor="Adobe"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0134" published="1996-08-06" seq="1999-0134" severity="High" type="CVE"><desc><descript source="cve">vold in Solaris 2.x allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.17.Solaris_vold_vul.html">CA-96.17.Solaris_vold_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/434.php">sol-voldtmp(434)</ref><ref source="OSVDB" url="http://www.osvdb.org/8159">8159</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="5.5.1"/><vers edition="x86" num="5.5.1"/><vers num="5.5"/><vers edition="x86" num="5.5"/><vers num="5.4"/><vers edition="x86" num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0135" published="1996-07-25" seq="1999-0135" severity="High" type="CVE"><desc><descript source="cve">admintool in Solaris allows a local user to write to arbitrary files and gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.16.Solaris_admintool_vul.html">CA-96.16.Solaris_admintool_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/394.php">sun-admintool(394)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/289">bugtraq id 289</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0136" published="1996-07-31" seq="1999-0136" severity="High" type="CVE"><desc><descript source="cve">Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.15.Solaris_KCMS_vul.html">CA-96.15.Solaris_KCMS_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/482.php">sol-KCMSvuln(482)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5"/><vers num="2.5.1"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.5.1"/><vers edition="x86" num="5.5.1"/><vers num="5.5"/><vers edition="x86" num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0137" published="1996-07-09" seq="1999-0137" severity="High" type="CVE"><desc><descript source="cve">The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.13.dip_vul.html">CA-96.13.dip_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/398.php">linux-dipbo(398)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/86">BID 86</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/881.php">dip-bo(881)</ref></refs><vuln_soft><prod name="dip" vendor="Fred N. van Kempen"><vers num="3.3.7o"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-07" name="CVE-1999-0138" published="1996-06-26" seq="1999-0138" severity="High" type="CVE"><desc><descript source="cve">The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.12.suidperl_vul.html">CA-96.12.suidperl_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/429.php">sperl-suid(429)</ref></refs><vuln_soft><prod name="A_UX" vendor="Apple"><vers num="3.1.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="1.2"/><vers num="2.0"/></prod><prod name="OSF_1" vendor="Digital"><vers num="1.3"/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num="4.2MP"/><vers num="4.2"/></prod><prod name="UX_4800" vendor="NEC"><vers num=""/></prod><prod name="UP-UX_V" vendor="NEC"><vers num="4.2MP"/></prod><prod name="HP-UX" vendor="HP"><vers num="8"/><vers num="9"/><vers num="10"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.0"/><vers num="2.0.5"/><vers num="2.1.0"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0139" published="1998-12-12" seq="1999-0139" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1429.php">sol-mkcookie(1429)</ref><ref source="OSVDB" url="http://www.osvdb.org/8205">8205</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.6"/><vers edition="x86" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0140" published="1999-06-30" seq="1999-0140" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in RAS/PPTP on NT systems.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0141" published="1996-03-29" seq="1999-0141" severity="Low" type="CVE"><desc><descript source="cve">Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/><user_init/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.07.java_bytecode_verifier.html">CA-96.07.java_bytecode_verifier</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/490.php">http-java-applet(490)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</ref></refs><vuln_soft><prod name="Navigator" vendor="Netscape"><vers num="2.02"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0142" published="1996-03-01" seq="1999-0142" severity="High" type="CVE"><desc><descript source="cve">The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer&apos;s Kit 1.0 allows an applet to connect to arbitrary hosts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/492.php">http-java-appletsecmgr(492)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.05.java_applet_security_mgr.html">CA-96.05.java_applet_security_mgr</ref></refs><vuln_soft><prod name="Navigator" vendor="Netscape"><vers num=""/></prod><prod name="Java" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0143" published="1996-02-21" seq="1999-0143" severity="Medium" type="CVE"><desc><descript source="cve">Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.03.kerberos_4_key_server.html">CA-96.03.kerberos_4_key_server</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/64.php">kerberos-bf(64)</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="5.0"/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0"/></prod><prod name="MultiNet" vendor="Process Software"><vers num="3.4"/><vers num="3.5"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0144" published="1997-06-01" seq="1999-0144" severity="Low" type="CVE"><desc><descript source="cve">Denial of service in Qmail by specifying a large number of recipients with the RCPT command.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/208.php">qmail-rcpt</ref><ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref><ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/2237">2237</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319029&amp;w=2">19970612 Re: Denial of service (qmail-smtpd)</ref></refs></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0145" published="1993-09-30" seq="1999-0145" severity="High" type="CVE"><desc><descript source="cve">Sendmail WIZ command enabled, allowing root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-93.14.Internet.Security.Scanner.html">Internet Security Scanner (ISS)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/131.php">smtp-wiz(131)</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</ref><ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</ref><ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0146" published="1997-07-15" seq="1999-0146" severity="High" type="CVE"><desc><descript source="cve">The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/298.php">http-cgi-campas(298)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1975">1975</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/298">http-cgi-campas(298)</ref></refs><vuln_soft><prod name="Servers" vendor="NCSA"><vers num=""/></prod><prod name="Campas" vendor="NCSA"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0147" published="1997-07-01" seq="1999-0147" severity="High" type="CVE"><desc><descript source="cve">The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/297.php">http-cgi-glimpse(297)</ref></refs><vuln_soft><prod name="Glimpse HTTP" vendor="University of Arizona"><vers num="2.0"/></prod><prod name="WebGlimpse" vendor="University of Arizona"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0148" published="1997-09-01" seq="1999-0148" severity="High" type="CVE"><desc><descript source="cve">The handler CGI program in IRIX allows arbitrary command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/380">bugtraq id 380</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/340.php">http-sgi-handler(340)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/380">380</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0149" published="1997-04-19" seq="1999-0149" severity="High" type="CVE"><desc><descript source="cve">The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/373">bugtraq id 373</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/290.php">http-sgi-wrap(290)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/373">373</ref><ref source="OSVDB" url="http://www.osvdb.org/247">247</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/290">http-sgi-wrap(290)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0150" published="1997-07-01" seq="1999-0150" severity="High" type="CVE"><desc><descript source="cve">The Perl fingerd program allows arbitrary command execution from remote users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/625.php">perl-fingerd(625)</ref></refs><vuln_soft><prod name="fingerd" vendor="GNU"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0151" published="1995-04-03" seq="1999-0151" severity="High" type="CVE"><desc><descript source="cve">The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.07a.REVISED.satan.vul.html">CA-95.07a.REVISED.satan.vul</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.06.satan.html">CA-95.06.satan.vul</ref></refs><vuln_soft><prod name="SATAN" vendor="SATAN"><vers num="1.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0152" published="1997-08-11" seq="1999-0152" severity="High" type="CVE"><desc><descript source="cve">The DG/UX finger daemon allows remote command execution through shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/302.php">dgux-fingerd(302)</ref></refs><vuln_soft><prod name="DG_UX" vendor="Data General"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0153" published="1997-07-01" seq="1999-0153" severity="Medium" type="CVE"><desc><descript source="cve">Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/173.php">win-oob(173)</ref><ref source="OSVDB" url="http://www.osvdb.org/1666">1666</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0154" published="1999-12-31" seq="1999-0154" severity="Medium" type="CVE"><desc><descript source="cve">IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/336.php">http-iis-aspdot(336)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0155" published="1995-08-31" seq="1999-0155" severity="High" type="CVE"><desc><descript source="cve">The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/404.php">gscript-dsafer(404)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.10.ghostscript.html">CA-95.10.ghostscript</ref></refs><vuln_soft><prod name="Ghostscript" vendor="Aladdin Enterprises"><vers num="3.22"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0156" published="1997-07-01" seq="1999-0156" severity="Medium" type="CVE"><desc><descript source="cve">wu-ftpd FTP daemon allows any user and password combination.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/204.php">ftp-pwless(204)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0157" published="1998-08-18" seq="1999-0157" severity="Medium" type="CVE"><desc><descript source="cve">Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/nifrag.shtml">Cisco PIX and CBAC Fragmentation Attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/690">BID 690</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1584.php">cisco-fragmented-attacks(1584)</ref><ref source="OSVDB" url="http://www.osvdb.org/1097">1097</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0T"/><vers num="12.0"/><vers num="11.3T"/><vers num="11.2P"/></prod><prod name="PIX Firewall" vendor="Cisco"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0158" published="1998-08-31" seq="1999-0158" severity="Medium" type="CVE"><desc><descript source="cve">Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1583.php">cisco-pix-file-exposure(1583)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/691">BID 691</ref><ref source="OSVDB" url="http://www.osvdb.org/685">685</ref></refs><vuln_soft><prod name="PIX Firewall" vendor="Cisco"><vers num="4.2.1"/><vers num="4.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0159" published="1998-08-12" seq="1999-0159" severity="Medium" type="CVE"><desc><descript source="cve">Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/ioslogin-pub.shtml">Cisco IOS Remote Router Crash</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1238.php">cisco-ios-crash(1238)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/692">BID 692</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="9.1"/><vers num="11.3.1T"/><vers num="11.3.1ED"/><vers num="11.3.1"/><vers num="11.2.9XA"/><vers num="11.2.9P"/><vers num="11.2.8SA3"/><vers num="11.2.10BC"/><vers num="11.2.10"/><vers num="11.1.17CT"/><vers num="11.1.17CC"/><vers num="11.1.16IA"/><vers num="11.1.16AA"/><vers num="11.1.16"/><vers num="11.1.15CA"/><vers num="11.0.20.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0160" published="1997-10-01" seq="1999-0160" severity="High" type="CVE"><desc><descript source="cve">Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/chapvuln-pub.shtml"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/570.php">cisco-CHAP(570)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/693">bugtraq id 693</ref><ref source="OSVDB" url="http://www.osvdb.org/1099">1099</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="9.1"/><vers num="11.2P"/><vers num="11.2"/><vers num="11.1"/><vers num="11.0"/><vers num="10.3"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0161" published="1995-07-31" seq="1999-0161" severity="High" type="CVE"><desc><descript source="cve">In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/1.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1247.php">cisco-acl-tacacs(1247)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/703">bugtraq id 703</ref><ref source="OSVDB" url="http://www.osvdb.org/797">797</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="10.3.4.2"/><vers num="10.3.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0162" published="1998-09-01" seq="1999-0162" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;established&quot; keyword in some Cisco IOS software allowed an attacker to bypass filtering.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/2.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1248.php">cisco-acl-established(1248)</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/315">bugtraq id 315</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="11.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0163" published="1997-01-01" seq="1999-0163" severity="High" type="CVE"><desc><descript source="cve">In older versions of Sendmail, an attacker could use a pipe character to execute root commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/616.php">smtp-pipe</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0164" published="1995-08-29" seq="1999-0164" severity="Medium" type="CVE"><desc><descript source="cve">A race condition in the Solaris ps command allows an attacker to overwrite critical files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.09.Solaris.ps.vul.html">CA-95.09.Solaris.ps.vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/420.php">sol-pstmprace(420)</ref><ref source="OSVDB" url="http://www.osvdb.org/8346">8346</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="5.3"/><vers num="5.4"/><vers edition="x86" num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0165" published="1997-03-01" seq="1999-0165" severity="High" type="CVE"><desc><descript source="cve">NFS cache poisoning.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/73.php">nfs-cache(73)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="3.5"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="1.1"/><vers num="1.1.1a"/><vers num="1.1.2"/><vers num="1.2"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/><vers edition="x86" num="2.4"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod><prod name="NFS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0166" published="1997-01-01" seq="1999-0166" severity="Medium" type="CVE"><desc><descript source="cve">NFS allows users to use a &quot;cd ..&quot; command to access other directories besides the exported file system.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/75.php">nfs-cd(75)</ref></refs><vuln_soft><prod name="NFS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0167" published="1991-12-06" seq="1999-0167" severity="Medium" type="CVE"><desc><descript source="cve">In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-91.21.SunOS.NFS.Jumbo.and.fsirand.html">CA-91.21.SunOS.NFS.Jumbo.and.fsirand</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/77.php">nfs-guess(77)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/32">bugtraq id 32</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0168" published="1992-06-04" seq="1999-0168" severity="High" type="CVE"><desc><descript source="cve">The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/46">bugtraq id 46</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/673.php">decod-portmap-call (673)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/80.php">nfs-portmap (80)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.3c"/><vers num="4.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0169" published="1997-07-01" seq="1999-0169" severity="High" type="CVE"><desc><descript source="cve">NFS allows attackers to read and write any file on the system by specifying a false UID.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/82.php">nfs-uid</ref></refs><vuln_soft><prod name="NFS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0170" published="1997-01-01" seq="1999-0170" severity="High" type="CVE"><desc><descript source="cve">Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/83.php">nfs-ultrix(83)</ref></refs><vuln_soft><prod name="Ultrix" vendor="Digital"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0171" published="1997-01-01" seq="1999-0171" severity="Low" type="CVE"><desc><descript source="cve">Denial of service in syslog by sending it a large number of superfluous messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/136.php">syslog-flood</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0172" published="1995-08-02" seq="1999-0172" severity="High" type="CVE"><desc><descript source="cve">FormMail CGI program allows remote execution of commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/299.php">http-cgi-formmail-exe(299)</ref></refs><vuln_soft><prod name="FormMail" vendor="Matt Wright"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0173" published="1997-01-01" seq="1999-0173" severity="Medium" type="CVE"><desc><descript source="cve">FormMail CGI program can be used by web servers other than the host server that the program resides on.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/300.php">http-cgi-formmail-use(300)</ref></refs><vuln_soft><prod name="FormMail" vendor="Matt Wright"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0174" published="1997-02-01" seq="1999-0174" severity="Medium" type="CVE"><desc><descript source="cve">The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/303">bugtraq id 303</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/291.php">http-cgi-viewsrc(291)</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.6"/><vers num="4.51"/><vers num="4.5"/><vers num="4.0"/><vers num="4.07"/><vers num="4.06"/><vers num="4.05"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0175" published="1996-07-01" seq="1999-0175" severity="Medium" type="CVE"><desc><descript source="cve">The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/339.php">http-nov-convert(339)</ref></refs><vuln_soft><prod name="Novell Web Server" vendor="Novell"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0176" published="1997-07-10" seq="1999-0176" severity="High" type="CVE"><desc><descript source="cve">The Webgais program allows a remote user to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1467.php">http-webgais-query(1467)</ref></refs><vuln_soft><prod name="WebGAIS" vendor="WebGAIS Development Team"><vers num="1.0B2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0177" published="1997-09-01" seq="1999-0177" severity="High" type="CVE"><desc><descript source="cve">The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/294.php">http-website-uploader(294)</ref></refs><vuln_soft><prod name="Website" vendor="OReilly"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0178" published="1997-01-01" seq="1999-0178" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/295.php">http-website-winsample(295)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</ref><ref source="BID" url="http://www.securityfocus.com/bid/2078">2078</ref><ref source="OSVDB" url="http://www.osvdb.org/8">8</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/295">http-website-winsample(295)</ref></refs><vuln_soft><prod name="OReilly Website" vendor="OReilly"><vers num="1.1e"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0179" published="1997-01-01" seq="1999-0179" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT crashes or locks up when a Samba client executes a &quot;cd ..&quot; command on a file share.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/397.php">nt-samba-dotdot(397)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q140818">Q140818</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="3.5"/><vers num="3.5.1"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0180" published="1997-01-01" seq="1999-0180" severity="High" type="CVE"><desc><descript source="cve">in.rshd allows users to login with a NULL username and execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/112.php">rsh-null(112)</ref></refs></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-16" name="CVE-1999-0181" published="1994-01-01" seq="1999-0181" severity="Medium" type="CVE"><desc><descript source="cve">The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/150.php">walld(150)</ref></refs><vuln_soft><prod name="rpc.walld" vendor="rpc.walld"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0182" published="1997-09-30" seq="1999-0182" severity="High" type="CVE"><desc><descript source="cve">Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/337.php">nt-samba-bo(337)</ref><ref adv="1" patch="1" source="CERT" url="ftp://ftp.cert.org/pub/cert_bulletins/VB-97.10.samba">VB-97.10.samba</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-110.shtml">H-110</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="1.9.17 p2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0183" published="1997-09-01" seq="1999-0183" severity="Medium" type="CVE"><desc><descript source="cve">Linux implementations of TFTP would allow access to files outside the restricted directory.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/308.php">linux-tftp(308)</ref></refs><vuln_soft><prod name="TFTP" vendor="TFTP"><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0184" published="1997-07-01" seq="1999-0184" severity="Medium" type="CVE"><desc><descript source="cve">When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/196.php">dns-updates(196)</ref><ref adv="1" source="ISC" url="http://www.isc.org/products/BIND/bind-security-19991108.html">nxt bug</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-14-bind.html">CA-99-14-bind.html</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0185" published="1997-10-01" seq="1999-0185" severity="High" type="CVE"><desc><descript source="cve">In SunOS or Solaris, a remote user could connect from an FTP server&apos;s data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/607.php">sun-ftpd/logind(607)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156">00156</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.4"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0186" published="1998-10-01" seq="1999-0186" severity="High" type="CVE"><desc><descript source="cve">In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1336.php">snmp-backdoor-access</ref><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm"></ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-1999-0187" published="1999-01-01" reject="1" seq="1999-0187" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0022.  Reason: This candidate is a duplicate of CVE-1999-0022.  Notes: All CVE users should reference CVE-1999-0022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0188" published="1998-12-17" seq="1999-0188" severity="High" type="CVE"><desc><descript source="cve">The passwd command in Solaris can be subjected to a denial of service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/174">bugtraq id 174</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1442.php">sun-passwd-dos(1442)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182">00182</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0189" published="1997-06-04" seq="1999-0189" severity="High" type="CVE"><desc><descript source="cve">Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Sun Sunsolve" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142&amp;type=0&amp;nav=sec.sba">#00142</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/330.php">rpc-32771(330)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142">00142</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0190" published="1998-04-08" seq="1999-0190" severity="High" type="CVE"><desc><descript source="cve">Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/67">bugtraq id 67</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/894.php">sun-rpcbind</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167">00167</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0191" published="1997-09-01" seq="1999-0191" severity="Medium" type="CVE"><desc><descript source="cve">IIS newdsn.exe CGI script allows remote users to overwrite files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1530.php">http-cgi-newdsn(1530)</ref><ref source="OSVDB" url="http://www.osvdb.org/275">275</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0192" published="1997-10-18" seq="1999-0192" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/588">BID 588</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/610.php">bsd-tel-tgetent(610)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/><vers edition="i386" num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="4.0"/><vers num="3.9"/><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0193" published="1997-12-01" seq="1999-0193" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/static/614.php">ascend-kill</ref></refs><vuln_soft><prod name="CascadeView_UX" vendor="Ascend"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0194" published="1999-05-01" seq="1999-0194" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in in.comsat allows attackers to generate messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1884.php">comsat(1884)</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0195" published="1997-07-01" seq="1999-0195" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2308.php">pmap-sset(2308)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0196" published="1997-07-08" seq="1999-0196" severity="Medium" type="CVE"><desc><descript source="cve">websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/296.php">http-webgais-smail(296)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2077">2077</ref><ref source="OSVDB" url="http://www.osvdb.org/237">237</ref></refs><vuln_soft><prod name="WebGAIS" vendor="WebGAIS Development Team"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0197" published="1999-01-01" seq="1999-0197" severity="High" type="CVE"><desc><descript source="cve">finger 0@host on some systems may print information on some user accounts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0198" published="1999-01-01" seq="1999-0198" severity="High" type="CVE"><desc><descript source="cve">finger .@host on some systems may print information on some user accounts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0200" published="1999-01-01" seq="1999-0200" severity="High" type="CVE"><desc><descript source="cve">Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0201" published="1997-01-01" seq="1999-0201" severity="Medium" type="CVE"><desc><descript source="cve">A quote cwd command on FTP servers can reveal the full path of the home directory of the &quot;ftp&quot; user.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/203.php">ftp-home(203)</ref></refs><vuln_soft><prod name="FTP" vendor="FTP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0202" published="1997-01-01" seq="1999-0202" severity="High" type="CVE"><desc><descript source="cve">The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/619.php">ftp-exectar(619)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0203" published="1995-08-17" seq="1999-0203" severity="High" type="CVE"><desc><descript source="cve">In Sendmail, attackers can gain root privileges via SMTP by specifying an improper &quot;mail from&quot; address and an invalid &quot;rcpt to&quot; address that would cause the mail to bounce to a program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.08.sendmail.v.5.vulnerability.html">CA-95.08.sendmail.v.5.vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/518.php">smtp-sendmail-version5(518)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.6.10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0204" published="1997-01-01" seq="1999-0204" severity="High" type="CVE"><desc><descript source="cve">Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/627.php">ident-bo(627)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0205" published="1999-01-01" seq="1999-0205" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Sendmail 8.6.11 and 8.6.12.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/SM%208.6.12">19990708 SM 8.6.12</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.6.12"/><vers num="8.6.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0206" published="1996-10-01" seq="1999-0206" severity="High" type="CVE"><desc><descript source="cve">MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1836.php">sendmail-mime-bo(1836)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.8"/><vers num="8.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0207" published="1994-06-09" seq="1999-0207" severity="High" type="CVE"><desc><descript source="cve">Remote attacker can execute commands through Majordomo using the Reply-To field and a &quot;lists&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.11.majordomo.vulnerabilities.html">CERT:CA-94.11.majordomo.vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/510.php">majordomo-exe(510)</ref></refs><vuln_soft><prod name="Majordomo" vendor="Great Circle Associates"><vers num="1.90"/><vers num="1.91"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-16" name="CVE-1999-0208" published="1995-12-12" seq="1999-0208" severity="High" type="CVE"><desc><descript source="cve">rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.17.rpc.ypupdated.vul.html">CA-95.17.rpc.ypupodated.vul</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/110.php">rpc-update(110)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="3.2"/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num=""/></prod><prod name="UP-UX_V" vendor="NEC"><vers num=""/></prod><prod name="IRIX" vendor="SGI"><vers num="3"/><vers num="4"/><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/></prod><prod name="UX_4800" vendor="NEC"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0209" published="1990-08-14" seq="1999-0209" severity="Medium" type="CVE"><desc><descript source="cve">The SunView (SunTools) selection_svc facility allows remote users to read files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-90.05.sunselection.vulnerability.html">CA-90.05.sunselection.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/122.php">selsvc(122)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/8">bugtraq id 8</ref><ref source="BID" url="http://www.securityfocus.com/bid/8">8</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0210" published="1997-11-26" seq="1999-0210" severity="High" type="CVE"><desc><descript source="cve">Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/235">bugtraq id 235</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05-statd-automountd</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88053459921223&amp;w=2">19971126 Solaris 2.5.1 automountd exploit (fwd)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104">HPSBUX9910-104</ref><ref source="BID" url="http://www.securityfocus.com/bid/235">235</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0211" published="1994-02-14" seq="1999-0211" severity="Medium" type="CVE"><desc><descript source="cve">Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability.html">CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/24">24</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.3c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0212" published="1998-04-29" seq="1999-0212" severity="High" type="CVE"><desc><descript source="cve">Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Sun Sunsolve" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/168&amp;type=0&amp;nav=sec.sba">#00168</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/967.php">sun-mountd(967)</ref><ref patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-048.shtml">I-048</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod><prod name="SunOS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0213" published="1998-07-15" seq="1999-0213" severity="High" type="CVE"><desc><descript source="cve">libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-2_num-8.phpSun-libnsl">sun-libnsl</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0214" published="1992-07-21" seq="1999-0214" severity="High" type="CVE"><desc><descript source="cve">Denial of service by sending forged ICMP unreachable packets.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/50">bugtraq id 50</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1883.php">icmp-unreachable(1883)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0215" published="1998-10-26" seq="1999-0215" severity="Medium" type="CVE"><desc><descript source="cve">Routed allows attackers to append data to files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/320.php">ripapp(320)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX">19981004-01-PX</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-012.shtml">J-012</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="3"/><vers num="4"/><vers num="5"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0216" published="1997-11-01" seq="1999-0216" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service of inetd on Linux through SYN and RST packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2013.php">linux-inutid-dos</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-2_num-4.phpHP-inetd">hp-inetd</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num="10"/></prod><prod name="inet" vendor="GNU"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0217" published="1997-01-01" seq="1999-0217" severity="Medium" type="CVE"><desc><descript source="cve">Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/143.php">udp-bomb(143)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.0.3"/><vers num="4.0.3c"/><vers num="4.1"/><vers num="4.1PSR_A"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.3a1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0218" published="1995-10-01" seq="1999-0218" severity="Medium" type="CVE"><desc><descript source="cve">Livingston portmaster machines could be rebooted via a series of commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1885.php">portmaster-reboot(1885)</ref></refs><vuln_soft><prod name="Portmaster" vendor="Livingston Portmaster"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0219" published="1997-07-01" seq="1999-0219" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/269">bugtraq id 269</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/205.php">ftp-servu</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2">19990503 Buffer overflows in FTP Serv-U 2.5</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref><ref source="BID" url="http://www.securityfocus.com/bid/269">269</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/205">ftp-servu(205)</ref></refs><vuln_soft><prod name="Serv-U" vendor="Cat Soft"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0220" published="1999-01-01" seq="1999-0220" severity="High" type="CVE"><desc><descript source="cve">Attackers can do a denial of service of IRC by crashing the server.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0221" published="1999-03-01" seq="1999-0221" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service of Ascend routers through port 150 (remote administration).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1881.php">ascend-150-kill(1881)</ref></refs><vuln_soft><prod name="Ascend Routers" vendor="Lucent"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0222" published="1999-03-01" seq="1999-0222" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1886.php">cisco-web-crash</ref></refs><vuln_soft><prod name="Cisco router" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0223" published="1999-03-01" seq="1999-0223" severity="Low" type="CVE"><desc><descript source="cve">Solaris syslogd crashes when receiving a message from a host that doesn&apos;t have an inverse DNS entry.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1887.php">sol-syslogd-crash(1887)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/bid/Syslogd%20and%20Solaris%202.4">Syslogd and Solaris 2.4</ref><ref source="" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches"></ref><ref source="BID" url="http://www.securityfocus.com/bid/1878">1878</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0224" published="1999-07-23" seq="1999-0224" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Windows NT messenger service through a long username.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/465">bugtraq id 465</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0225" published="1998-02-14" seq="1999-0225" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/342.php">nt-logondos(342)</ref><ref adv="1" patch="1" source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp"></ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=180963">Q180963</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0226" published="1999-01-01" seq="1999-0226" severity="High" type="CVE"><desc><descript source="cve">Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0227" published="1997-06-01" seq="1999-0227" severity="Medium" type="CVE"><desc><descript source="cve">Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1892.php">nt-lsass-crash(1892)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154087">Q154087</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0228" published="1997-02-07" seq="1999-0228" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/688">bugtraq id 688</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/17.php">nt-rpc-ver(17)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q162567">Q162567</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0229" published="1999-05-12" seq="1999-0229" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Windows NT IIS server using ..\..</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-10.php">http-alibaba-dotdot</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0230" published="1997-12-15" seq="1999-0230" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Cisco 7xx routers through the telnet service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/pwbuf-pub.shtml">7xx Router Password Buffer Overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/704">bugtraq id 704</ref><ref source="OSVDB" url="http://www.osvdb.org/1102">1102</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0231" published="1999-01-01" seq="1999-0231" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="SLMail" vendor="Seattle Lab Software"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0232" published="1995-02-01" seq="1999-0232" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/517.php">http-ncsa-longurl</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0233" published="1996-02-25" seq="1999-0233" severity="High" type="CVE"><desc><descript source="cve">IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/63.php">http-iis-cmd(63)</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q148/1/88.asp"></ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q148188">Q148188</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q155056">Q155056</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0234" published="1996-10-08" seq="1999-0234" severity="Medium" type="CVE"><desc><descript source="cve">Bash treats any character with a value of 255 as a command separator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.22.bash_vuls.html">CA-96.22.bash_vuls</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="4.2"/></prod><prod name="Linux" vendor="Red Hat"><vers num="3.0.3"/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod><prod name="Linux" vendor="Yggdrasil"><vers num=""/></prod><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0235" published="1995-02-17" seq="1999-0235" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1995-04.html">CERT:CA-95:04</ref></refs><vuln_soft><prod name="NCSA Web Server" vendor="NCSA"><vers num="1.3"/><vers num="1.4"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0236" published="1997-01-01" seq="1999-0236" severity="High" type="CVE"><desc><descript source="cve">ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/332.php">http-scriptalias(332)</ref></refs><vuln_soft><prod name="Servers" vendor="NCSA"><vers num=""/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0237" published="1997-09-01" seq="1999-0237" severity="High" type="CVE"><desc><descript source="cve">Remote execution of arbitrary commands through Guestbook CGI program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/321.php">http-cgi-guestbook(321)</ref><ref adv="1" patch="1" source="CERT" url="ftp://info.cert.org/pub/cert_bulletins/VB-97.02.sol_guestbook">VB-97.02.sol_questday</ref></refs><vuln_soft><prod name="CGI Guestbook" vendor="Webcom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0238" published="1997-08-01" seq="1999-0238" severity="High" type="CVE"><desc><descript source="cve">php.cgi allows attackers to read any file on the system.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/292.php">http-cgi-phpfileread</ref></refs><vuln_soft><prod name="PHP_FI" vendor="PHP"><vers num="1.0"/><vers num="2.0"/><vers num="2.0b10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0239" published="1998-01-01" seq="1999-0239" severity="Medium" type="CVE"><desc><descript source="cve">Netscape FastTrack Web server lists files when a lowercase &quot;get&quot; command is used instead of an uppercase GET.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/481">bugtraq id 481</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1731.php">fastrack-get-directory-list(1731)</ref><ref source="OSVDB" url="http://www.osvdb.org/122">122</ref></refs><vuln_soft><prod name="FastTrack" vendor="Netscape"><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0240" published="1999-01-01" seq="1999-0240" severity="High" type="CVE"><desc><descript source="cve">Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0241" published="1995-11-01" seq="1999-0241" severity="High" type="CVE"><desc><descript source="cve">Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/334.php">http-xguess-cookie</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1429.php">sol-mkcookie(1429)</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num=""/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.6"/><vers edition="x86" num="7.0"/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0242" published="1995-03-01" seq="1999-0242" severity="High" type="CVE"><desc><descript source="cve">Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/418.php">linux-pop3d</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0243" published="1999-01-01" seq="1999-0243" severity="High" type="CVE"><desc><descript source="cve">Linux cfingerd could be exploited to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0244" published="1997-12-01" seq="1999-0244" severity="High" type="CVE"><desc><descript source="cve">Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1891.php">radius-accounting-overflow(1891)</ref></refs><vuln_soft><prod name="RADIUS" vendor="Livingston"><vers num="1.x"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0245" published="1995-09-07" seq="1999-0245" severity="Medium" type="CVE"><desc><descript source="cve">Some configurations of NIS+ in Linux allowed attackers to log in as the user &quot;+&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/307.php">linux-plus(307)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0246" published="1996-10-01" seq="1999-0246" severity="High" type="CVE"><desc><descript source="cve">HP Remote Watch allows a remote user to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://xforce.iss.net/static/620.php">hp-remote</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0247" published="1997-07-21" seq="1999-0247" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1443">1443</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/623.php">inn-bo</ref><ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp">19970721 INN news server vulnerabilities</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="1.4"/><vers num="1.4sec"/><vers num="1.4sec2"/><vers num="1.4unoff3"/><vers num="1.4unoff4"/><vers num="1.5"/><vers num="1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0248" published="1999-01-01" seq="1999-0248" severity="High" type="CVE"><desc><descript source="cve">A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user&apos;s credentials.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html">http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html</ref><ref source="CONFIRM" url="http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1">http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.27"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0249" published="1997-01-01" seq="1999-0249" severity="High" type="CVE"><desc><descript source="cve">Windows NT RSHSVC program allows remote users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/114.php">rsh-svc</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0250" published="1997-07-01" seq="1999-0250" severity="High" type="CVE"><desc><descript source="cve">Denial of service in Qmail through long SMTP commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/207.php">qmail-leng</ref><ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref><ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref></refs><vuln_soft><prod name="Qmail" vendor="Dan Bernstein"><vers num="1.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0251" published="1997-01-01" seq="1999-0251" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in talk program allows remote attackers to disrupt a user&apos;s display.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/615.php">talkd-flash(615)</ref></refs><vuln_soft><prod name="talkd" vendor="talkd"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0252" published="1997-01-01" seq="1999-0252" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in listserv allows arbitrary command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/617.php">smtp-listserv(617)</ref></refs><vuln_soft><prod name="Listserv" vendor="L-Soft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0253" published="1997-01-01" seq="1999-0253" severity="High" type="CVE"><desc><descript source="cve">IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/621.php">http-iis-2e</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0254" published="1998-11-02" seq="1999-0254" severity="High" type="CVE"><desc><descript source="cve">A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-2.phpHPOV-hidden-SNMP-comm">hpov-hidden-snmp-comm</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0255" published="1999-01-01" seq="1999-0255" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ircd allows arbitrary command execution.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0256" published="1998-02-01" seq="1999-0256" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in War FTP allows remote execution of commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/345.php">war-ftpd(345)</ref><ref source="OSVDB" url="http://www.osvdb.org/875">875</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod><prod name="WarFTPd" vendor="Jgaa"><vers num="1.66" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0257" published="1998-04-01" seq="1999-0257" severity="Medium" type="CVE"><desc><descript source="cve">Nestea variation of teardrop IP fragmentation denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/897.php">nestea-linux-dos(897)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0258" published="1998-02-13" seq="1999-0258" severity="Medium" type="CVE"><desc><descript source="cve">Bonk variation of teardrop IP fragmentation denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/343.php">teardrop-mod</ref><ref adv="1" source="CERT" url="ftp://ftp.cert.org/pub/cert_summaries/CS-98.02">Denial of Service attack (broad)</ref><ref adv="1" source="CERT" url="ftp://ftp.cert.org/pub/cert_summaries/CS-98.01">Denial of Service Attacks (Broad)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0259" published="1997-05-23" seq="1999-0259" severity="Medium" type="CVE"><desc><descript source="cve">cfingerd lists all users on a system via search.**@target.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1811.php">cfinger-user-enumeration(1811)</ref><ref adv="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9705D&amp;L=bugtraq&amp;P=R1300"></ref></refs><vuln_soft><prod name="cfingerd" vendor="Infodrom"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0260" published="1996-12-24" seq="1999-0260" severity="High" type="CVE"><desc><descript source="cve">The jj CGI program allows command execution via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1808.php">http-cgi-jj(1808)</ref></refs><vuln_soft><prod name="jj" vendor="Renaud Deraison"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0261" published="1999-03-01" seq="1999-0261" severity="Medium" type="CVE"><desc><descript source="cve">Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1987.php">chameleon-smtp-dos(1987)</ref><ref source="MISC" url="http://www.insecure.org/sploits/netmanage.chameleon.overflows.html">http://www.insecure.org/sploits/netmanage.chameleon.overflows.html</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0262" published="1998-08-04" seq="1999-0262" severity="High" type="CVE"><desc><descript source="cve">Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1532.php">http-cgi-faxsurvey(1532)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2056">2056</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1532">http-cgi-faxsurvey(1532)</ref></refs><vuln_soft><prod name="faxsurvey" vendor="Renaud Deraison"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0263" published="1998-07-16" seq="1999-0263" severity="Medium" type="CVE"><desc><descript source="cve">Solaris SUNWadmap can be exploited to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/430">bugtraq id 430</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1200.php">sun-sunwadmap(1200)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/173">00173</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86HW5" num="2.6"/><vers edition="x86HW3" num="2.6"/><vers edition="HW5" num="2.6"/><vers edition="HW3" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-1999-0264" published="1998-01-27" seq="1999-0264" severity="Medium" type="CVE"><desc><descript source="cve">htmlscript CGI program allows remote read access to files.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1466.php">http-htmlscript-file-access(1466)</ref></refs><vuln_soft><prod name="htmlscript" vendor="Miva"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0265" published="1997-01-01" seq="1999-0265" severity="Medium" type="CVE"><desc><descript source="cve">ICMP redirect messages may crash or lock up a host.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/285.php">icmp-redirect(285)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154174">Q154174</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="3.12"/></prod><prod name="OS-9" vendor="Microware"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0266" published="1998-03-01" seq="1999-0266" severity="High" type="CVE"><desc><descript source="cve">The info2www CGI script allows remote file access or remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1732.php">http-cgi-info2www(1732)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1995">1995</ref></refs><vuln_soft><prod name="info2www" vendor="Roar Smith"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-1999-0267" published="1997-09-23" seq="1999-0267" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.04.NCSA.http.daemon.for.unix.vulnerability.html">CA-95.04.NCSA.http.daemon.for.unix.vulnerability</ref></refs><vuln_soft><prod name="NCSA httpd" vendor="NCSA"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0268" published="1999-01-01" seq="1999-0268" severity="High" type="CVE"><desc><descript source="cve">MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/Security%20vulnerabilities%20in%20MetaInfo%20products">Security vulnerabilities in Metalinfo products</ref><ref source="OSVDB" url="http://www.osvdb.org/110">110</ref><ref source="OSVDB" url="http://www.osvdb.org/3969">3969</ref></refs><vuln_soft><prod name="MetaWeb" vendor="Metainfo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0269" published="1998-08-01" seq="1999-0269" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Enterprise servers may list files through the PageServices query.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1810.php">netscape-server-pageservices(1810)</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0270" published="1998-04-03" seq="1999-0270" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as &quot;pfdisplay&quot;) for SGI&apos;s Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-041.shtml">Performer API Search Tool 2.2 pfdispaly.cgi Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/810.php">sgi-pfdispaly(810)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-03-15&amp;msg=199803162306.AAA25015@gtc1.cps.unizar.es"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P">19980401-01-P</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-041.shtml">I-041</ref><ref source="BID" url="http://www.securityfocus.com/bid/64">64</ref><ref source="OSVDB" url="http://www.osvdb.org/134">134</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/810">sgi-pfdispaly(810)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0271" published="1998-01-15" seq="1999-0271" severity="Medium" type="CVE"><desc><descript source="cve">Progressive Networks Real Video server (pnserver) can be crashed remotely.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-1999-0272" published="1997-10-01" seq="1999-0272" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Slmail v2.5 through the POP3 port.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/221">BID 221</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1662.php">slmail-username-bo(1662)</ref></refs><vuln_soft><prod name="Slmail" vendor="Slmail"><vers num="3.0.2421"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0273" published="1998-01-01" seq="1999-0273" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service through Solaris 2.5.1 telnet by sending ^D characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1464.php">sun-telnet-kill(1464)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0274" published="1997-01-01" seq="1999-0274" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn&apos;t made.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3106.php">nt-dns-dos(3106)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0275" published="1997-06-10" seq="1999-0275" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/186.php">nt-dnscrash(186)</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q142/0/47.asp"></ref><ref adv="1" source="Insecure.org" url="http://www.insecure.org/sploits/NT.DNS.character_flood.html"></ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0276" published="1999-01-01" seq="1999-0276" severity="High" type="CVE"><desc><descript source="cve">mSQL v2.0.1 and below allows remote execution through a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2143.php">msql-debug-bo(2143)</ref></refs><vuln_soft><prod name="mSQL" vendor="Hughes"><vers num="2.0.1"/><vers num="2.0."/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0277" published="1996-10-28" seq="1999-0277" severity="High" type="CVE"><desc><descript source="cve">The WorkMan program can be used to overwrite any file to get root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.23.workman_vul.html">CA-96.23.workman_vul</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/435.php">workman(435)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0278" published="1998-06-01" seq="1999-0278" severity="Medium" type="CVE"><desc><descript source="cve">In IIS, remote attackers can obtain source code for ASP files by appending &quot;::$DATA&quot; to the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/149">BID 149</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1125.php">iis-asp-data-check(1135)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-003.mspx">MS98-003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:913">oval:org.mitre.oval:def:913</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0279" published="1998-01-01" seq="1999-0279" severity="High" type="CVE"><desc><descript source="cve">Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1418.php">excite-cgi-search-vuln(1418)</ref><ref adv="1" patch="1" source="CERT" url="ftp://ftp.cert.org/pub/cert_bulletins/VB-98.01.excite">VB-98.01.excite-cgi-search-vuln</ref></refs><vuln_soft><prod name="EWS" vendor="Excite"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0280" published="1997-04-01" seq="1999-0280" severity="High" type="CVE"><desc><descript source="cve">Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/463.php">http-ie-lnkurl(463)</ref><ref patch="1" source="Microsoft" url="http://www.microsoft.com/windows/ie/security/download.asp"></ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0"/><vers num="3.0.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0281" published="1997-06-01" seq="1999-0281" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in IIS using long URLs.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/531.php">http-iis-longurl(531)</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q143/4/84.asp"></ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry modified="2005-10-31" name="CVE-1999-0282" published="1997-09-23" reject="1" seq="1999-0282" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1584, CVE-1999-1586.  Reason: This candidate combined references from one issue with the description from another issue.  Notes: Users should consult CVE-1999-1584 and CVE-1999-1586 to obtain the appropriate name.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0283" published="1999-01-01" seq="1999-0283" severity="High" type="CVE"><desc><descript source="cve">The Java Web Server would allow remote users to obtain the source code for CGI programs.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88256790401004&amp;w=2">19970716 Viewable .jhtml source with JavaWebServer</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0284" published="1998-01-01" seq="1999-0284" severity="High" type="CVE"><desc><descript source="cve">Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1834.php">mdaemon-helo-bo</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1813.php">lotus-notes-helo-crash</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/344.php">smtp-exchangedos(344)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="4.0"/><vers num="5.0"/></prod><prod name="Lotus Domino Mail Server" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0285" published="1999-01-01" seq="1999-0285" severity="High" type="CVE"><desc><descript source="cve">Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0286" published="1999-01-01" seq="1999-0286" severity="High" type="CVE"><desc><descript source="cve">In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0287" published="1999-04-09" seq="1999-0287" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in the Wguest CGI program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2072.php">http-cgi-webcom-guestbook(2072)</ref><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9904&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=2194">CGI Webcom guestbook</ref></refs><vuln_soft><prod name="CGI Guestbook" vendor="Webcom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0288" published="1998-08-01" seq="1999-0288" severity="Medium" type="CVE"><desc><descript source="cve">The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/298">BID 298</ref><ref source="" url="http://safenetworks.com/Windows/wins.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1233">nt-winsupd-fix(1233)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0289" published="1999-12-12" seq="1999-0289" severity="Medium" type="CVE"><desc><descript source="cve">The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0290" published="1998-02-21" seq="1999-0290" severity="Medium" type="CVE"><desc><descript source="cve">The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2003.php">wingate-dos(2003)</ref><ref adv="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9802D&amp;L=bugtraq&amp;P=R56"></ref></refs><vuln_soft><prod name="WinGate" vendor="Qbik"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0291" published="1999-02-01" seq="1999-0291" severity="High" type="CVE"><desc><descript source="cve">The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1849.php">wingate-unpassworded(1849)</ref></refs><vuln_soft><prod name="WinGate" vendor="Qbik"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0292" published="1997-04-01" seq="1999-0292" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service through Winpopup using large user names.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/538.php">nt-winpopup(538)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP1"/><vers num="4.0 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0293" published="1998-01-01" seq="1999-0293" severity="High" type="CVE"><desc><descript source="cve">AAA authentication on Cisco systems allows attackers to execute commands without authorization.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/aaapair-pub.shtml">Cisco IOS 11.3(1.2) and 11.3(1.2)T AAA Failure</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1245.php">cisco-ios-aaa-auth(1245)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0294" published="1997-10-01" seq="1999-0294" severity="Medium" type="CVE"><desc><descript source="cve">All records in a WINS database can be deleted through SNMP for a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/982.php">nt-wins-snmp2(982)</ref></refs><vuln_soft><prod name="WINS" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0295" published="1997-10-01" seq="1999-0295" severity="High" type="CVE"><desc><descript source="cve">Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/241">bugtraq id 241</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/608.php">sun-sysdef(608)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157">00157</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0296" published="1998-02-01" seq="1999-0296" severity="High" type="CVE"><desc><descript source="cve">Solaris volrmmount program allows attackers to read any file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/708.php">sun-volrmmount(708)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/162">00162</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers edition="x86" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-1999-0297" published="1996-12-12" seq="1999-0297" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3124.php">vixie-cron(3124)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0"/></prod><prod name="Linux" vendor="Red Hat"><vers num=""/></prod><prod name="Vixie Cron" vendor="Paul Vixie"><vers num="3.0"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0298" published="1997-02-05" seq="1999-0298" severity="High" type="CVE"><desc><descript source="cve">ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1441">BID 1441</ref><ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp">19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.4"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0299" published="1997-03-05" seq="1999-0299" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FreeBSD lpd through long DNS hostnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/6093">6093</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0300" published="1997-10-01" seq="1999-0300" severity="High" type="CVE"><desc><descript source="cve">nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/239">BID 239</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/606.php">sun-niscache(606)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155">00155</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0301" published="1997-08-01" seq="1999-0301" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SunOS/Solaris ps command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/220">BID 220</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/484.php">sun-ps2bo(484)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149">00149</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0302" published="1998-09-01" seq="1999-0302" severity="High" type="CVE"><desc><descript source="cve">SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1370.php">sun-ftp-server(1370)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/176">00176</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0303" published="1998-05-21" seq="1999-0303" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1395.php">bnu-uucpd-bo(1395)</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.1"/><vers num="2.2"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers edition="x86" num="2.5"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers edition="JL" num="1.1.4"/><vers num="1.1.4"/><vers edition="U1" num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1a"/><vers num="1.1"/><vers edition="x86" num="Any"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.4"/></prod><prod name="OSF_1" vendor="Digital"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0304" published="1998-02-01" seq="1999-0304" severity="High" type="CVE"><desc><descript source="cve">mmap function in BSD allows local attackers in the kmem group to modify memory through devices.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/735.php">bsd-mmap(735)</ref><ref adv="1" source="FreeBSD AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/ESB/ESB-98.087"></ref><ref adv="1" source="Insecure.org" url="http://www.insecure.org/sploits/bsd.mmap.chardevice.html"></ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0305" published="1998-02-01" seq="1999-0305" severity="Medium" type="CVE"><desc><descript source="cve">The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/736.php">bsd-sourceroute(736)</ref><ref source="" url="http://www.openbsd.org/advisories/sourceroute.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/11502">11502</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/736">bsd-sourceroute(736)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2"/><vers num="2.2.5"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.1"/><vers num="2.2"/><vers num="2.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0306" published="1997-11-04" seq="1999-0306" severity="High" type="CVE"><desc><descript source="cve">buffer overflow in HP xlock program.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-1_num-7.phpHP-xlock">hp-xlock</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-97.13.xlock.html">Vulnerability in xlock</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers edition="VVOS" num="10.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0307" published="2000-12-20" seq="1999-0307" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HP-UX cstm program allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1440.php">hpux-cstm-bo</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.0"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0308" published="1996-10-01" seq="1999-0308" severity="Medium" type="CVE"><desc><descript source="cve">HP-UX gwind program allows users to modify arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1414.php">hpux-gwind-overwrite(1414)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018">HPSBUX9410-018</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="8"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0309" published="1997-02-01" seq="1999-0309" severity="High" type="CVE"><desc><descript source="cve">HP-UX vgdisplay program gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1415.php">hpux-vgdisplay(1415)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056">HPSBUX9702-056</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.24"/><vers num="10.0"/><vers num="10.1"/><vers num="10.10"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0310" published="1998-09-01" seq="1999-0310" severity="High" type="CVE"><desc><descript source="cve">SSH 1.2.25 on HP-UX allows access to new user accounts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1423.php">ssh-1225(1423)</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.25"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0311" published="1996-11-01" seq="1999-0311" severity="High" type="CVE"><desc><descript source="cve">fpkg2swpk in HP-UX allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1437.php">hpux-fpkg2swpk(1437)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042">HPSBUX9612-042</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0312" published="1993-01-13" seq="1999-0312" severity="Medium" type="CVE"><desc><descript source="cve">HP ypbind allows attackers with root privileges to modify NIS data.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-93.01.REVISED.HP.NIS.ypbind.vulnerability.html">CA-93:01.REVISED.HP.NIS.ypbind.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/519.php">nis-ypbind(519)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/52">bugtraq id 52</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0313" published="1998-07-01" seq="1999-0313" severity="High" type="CVE"><desc><descript source="cve">disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/214">bugtraq id 214</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1441.php">sgi-disk-bandwidth(1441)</ref><ref source="" url="http://www.securityfocus.com/bid/213/exploit"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref><ref source="BID" url="http://www.securityfocus.com/bid/214">214</ref><ref source="OSVDB" url="http://www.osvdb.org/936">936</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1441">sgi-disk-bandwidth(1441)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4 S2MP"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0314" published="1998-07-01" seq="1999-0314" severity="High" type="CVE"><desc><descript source="cve">ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1199.php">sgi-ioconfig(1199)</ref><ref source="" url="http://www.securityfocus.com/bid/213/exploit"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref><ref source="BID" url="http://www.securityfocus.com/bid/213">213</ref><ref source="OSVDB" url="http://www.osvdb.org/6788">6788</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1199">sgi-ioconfig(1199)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0315" published="1997-04-01" seq="1999-0315" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris fdformat command gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/875.php">fdformat-bo(875)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138">00138</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.6"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.4"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0316" published="1995-12-01" seq="1999-0316" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux splitvt command gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/430.php">linux-splitvt(430)</ref></refs><vuln_soft><prod name="Splitvt" vendor="Sam Lantinga"><vers num="1.6.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0317" published="1999-11-25" seq="1999-0317" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux su command gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/734.php">su-bo(734)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-10.phpunixware-su-username-bo">unixware-su-username-bo</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0318" published="1997-03-01" seq="1999-0318" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/436.php">xmcd-envbo(436)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4"/></prod><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers num="2.6"/><vers num="7.0"/><vers num="8.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0319" published="1996-10-01" seq="1999-0319" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/437.php">xmcd-tiflestr(437)</ref></refs></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0320" published="1998-03-01" seq="1999-0320" severity="High" type="CVE"><desc><descript source="cve">SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/428">BID 428</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/818.php">sun-rpc.cmsd(818)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0321" published="1998-12-01" seq="1999-0321" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris kcms_configure command allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1473.php">sun-kcms-configure-bo(1473)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0322" published="1997-10-29" seq="1999-0322" severity="Low" type="CVE"><desc><descript source="cve">The open() function in FreeBSD allows local attackers to write to arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/591.php">freebsd-open(591)</ref><ref adv="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-97:05.open.asc">FreeBSD-SA-97:05</ref><ref source="OSVDB" url="http://www.osvdb.org/6092">6092</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0323" published="1998-02-20" seq="1999-0323" severity="High" type="CVE"><desc><descript source="cve">FreeBSD mmap function allows users to modify append-only or immutable files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/735.php">bsd-mmap(735)</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc">1998-003</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0324" published="1996-09-01" seq="1999-0324" severity="High" type="CVE"><desc><descript source="cve">ppl program in HP-UX allows local users to create root files through symlinks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/419.php">hp-ppllog(419)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053">HPSBUX9702-053</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.0"/><vers num="9"/><vers num="10.1"/><vers num="10.10"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0325" published="1995-12-01" seq="1999-0325" severity="High" type="CVE"><desc><descript source="cve">vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/433.php">hp-vhe(433)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013">HPSBUX9406-013</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="8"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0326" published="1997-10-01" seq="1999-0326" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in HP-UX mediainit program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/567.php">hp-mediainit(567)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071">HPSBUX9710-071</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9"/><vers num="10.1"/><vers num="10.10"/><vers num="10.20"/><vers num="10.30"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0327" published="1997-11-01" seq="1999-0327" severity="Low" type="CVE"><desc><descript source="cve">SGI syserr program allows local users to corrupt files.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/85">bugtraq id 85</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/691.php">sgi-syserr</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0328" published="1997-11-01" seq="1999-0328" severity="High" type="CVE"><desc><descript source="cve">SGI permissions program allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/417">BID 417</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/692.php">sgi-permtool(692)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0329" published="1998-06-01" seq="1999-0329" severity="High" type="CVE"><desc><descript source="cve">SGI mediad program allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/394">BID 394</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1122.php">sgi-mediad(1122)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX">19980602-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0330" published="1998-03-01" seq="1999-0330" severity="High" type="CVE"><desc><descript source="cve">Linux bdash game has a buffer overflow that allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/821.php">bdash-bo(821)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0331" published="1998-01-01" seq="1999-0331" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Internet Explorer 4.0(1).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/917.php">iemk-bug(917)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0.02"/><vers num="4.0.0"/><vers num="4.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0332" published="1998-12-01" seq="1999-0332" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NetMeeting allows denial of service and remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/171">BID 171</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1222.php">nt-netmeeting(1222)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q184346">Q184346</ref></refs><vuln_soft><prod name="NetMeeting" vendor="Microsoft"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0333" published="1998-08-01" seq="1999-0333" severity="High" type="CVE"><desc><descript source="cve">HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1396.php">omniback-remote(1396)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0334" published="1993-12-16" seq="1999-0334" severity="High" type="CVE"><desc><descript source="cve">In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-93.19.Solaris.Startup.vulnerability.html">CA-93.19.Solaris.Startup.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/552.php">sol-startup(552)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="x86"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0335" published="1996-08-01" seq="1999-0335" severity="High" type="CVE"><desc><descript source="cve">DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="ftp://info.cert.org/pub/cert_advisories/CA-97.19.bsdlp">CA-97.19.bsdlp</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/409.php">bsd-lprbo(409)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0336" published="1996-11-01" seq="1999-0336" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in mstm in HP-UX allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1439.php">hpux-mstm-bo(1439)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0337" published="1994-06-03" seq="1999-0337" severity="High" type="CVE"><desc><descript source="cve">AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.10.IBM.AIX.bsh.vulnerability.html">CA-94.10.IBM.AIX.bsh.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/509.php">ibm-bsh(509)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/349">bugtraq id 349</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="3.1"/><vers num="2.2.1"/><vers num="1.3"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0338" published="1994-02-24" seq="1999-0338" severity="High" type="CVE"><desc><descript source="cve">AIX Licensed Program Product performance tools allow local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.03.AIX.performance.tools.html">CA-94.03.AIX.performance.tools</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/504.php">ibm-perf-tools(504)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="3.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0339" published="1998-08-01" seq="1999-0339" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/442">bugtraq id 442</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1219.php">sol-sun-libauth(1219)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0340" published="1997-12-01" seq="1999-0340" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux Slackware crond program allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/695.php">linux-crond(695)</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0341" published="1998-01-01" seq="1999-0341" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Linux mail program &quot;deliver&quot; allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/226">bugtraq id 226</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/702.php">linux-deliver(702)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="1.3.1"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0342" published="1998-12-01" seq="1999-0342" severity="Medium" type="CVE"><desc><descript source="cve">Linux PAM modules allow local users to gain root access using temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1474.php">linux-pam-passwd-tmprace(1474)</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/corp/support/errata/rh42-errata-general.htmlpam">pam</ref><ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/rh42-errata-general.html#pam">http://www.redhat.com/corp/support/errata/rh42-errata-general.html#pam</ref></refs><vuln_soft><prod name="pam" vendor="pam"><vers num="0.64" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0343" published="1998-10-02" seq="1999-0343" severity="Medium" type="CVE"><desc><descript source="cve">A malicious Palace server can force a client to execute arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1631.php">palace-malicious-servers-vuln(1631)</ref><ref adv="1" source="Netscape" url="http://www.netspace.org/cgi-bin/wa?A2=ind9810A&amp;L=bugtraq&amp;P=R886"></ref></refs><vuln_soft><prod name="Palace Client" vendor="Palace"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0344" published="1998-08-01" seq="1999-0344" severity="Medium" type="CVE"><desc><descript source="cve">NT users can gain debug-level access on a system process using the Sechole exploit.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1231.php">nt-priv-fix(1231)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-009.mspx">MS98-009</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q190288">Q190288</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="3.5"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0345" published="1997-01-01" seq="1999-0345" severity="Medium" type="CVE"><desc><descript source="cve">Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/95.php">ping-death(95)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.26.ping.html">CA-96.26</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="1.0"/><vers num="1.1"/><vers num="1.1.5.1"/><vers num="1.2"/><vers num="2.0"/><vers num="2.0.5"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5"/></prod><prod name="SunOS" vendor="Sun"><vers num=""/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/><vers num="1.1"/></prod><prod name="SNG" vendor="IBM"><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0346" published="1997-10-16" seq="1999-0346" severity="Medium" type="CVE"><desc><descript source="cve">CGI PHP mlog script allows an attacker to read any file on the target server.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1505.php">http-cgi-php-mlog(1505)</ref><ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref><ref source="OSVDB" url="http://www.osvdb.org/3397">3397</ref></refs><vuln_soft><prod name="PHP_FI" vendor="PHP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-11-02" name="CVE-1999-0347" published="1999-01-26" seq="1999-0347" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a &quot;%01&quot; character in an &quot;about:&quot; Javascript URL, which causes Internet Explorer to use the domain specified after the character.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91745430007021&amp;w=2">19990126 Javascript ecurity bug in Internet Explorer</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91756771207719&amp;w=2">19990126 Javascript ecurity bug in Internet Explorer</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0348" published="1999-01-27" seq="1999-0348" severity="Medium" type="CVE"><desc><descript source="cve">IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/195">bugtraq id 195</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q197003">Q197003</ref><ref source="OSVDB" url="http://www.osvdb.org/930">930</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0349" published="1999-01-27" seq="1999-0349" severity="High" type="CVE"><desc><descript source="cve">A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/192">bugtraq id 192</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1654.php">iis-remote-ftp(1654)</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/IIS Remote FTP Exploit/DoS Attack.html">IIS Remote FTP Exploit/DoS Attack</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx">MS99-003</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q188348">Q188348</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0350" published="1999-02-08" seq="1999-0350" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/538">BID 538</ref><ref adv="1" patch="1" source="CERT" url="http://xforce.iss.net/static/1718.php">clearcase-temp-race(1718)</ref></refs><vuln_soft><prod name="ClearCase" vendor="Rational Software"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0351" published="1999-02-01" seq="1999-0351" severity="Medium" type="CVE"><desc><descript source="cve">FTP PASV &quot;Pizza Thief&quot; denial of service and unauthorized data access.  Attackers can steal data by connecting to a port that was intended for use by a client.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3389">FTP PASV Pizza Thief denial of service</ref><ref source="" url="http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt"></ref></refs><vuln_soft><prod name="FTP PASV" vendor="FTP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0352" published="1999-01-25" seq="1999-0352" severity="High" type="CVE"><desc><descript source="cve">ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1651.php">controlit-passwd-encrypt(1651)</ref></refs></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0353" published="1999-02-10" seq="1999-0353" severity="High" type="CVE"><desc><descript source="cve">rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1699.php">pcnfsd-world-write(1699)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091">HPSBUX9902-091</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-026.shtml">J-026</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.1"/><vers num="10.10"/><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0354" published="1999-11-01" seq="1999-0354" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn&apos;t warn the user that the template contains executable content.  Also applies to Outlook when the client views a malicious email message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3498.php">word97-template-macro(3498)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-002.asp">MS99-002</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/></prod><prod name="Word" vendor="Microsoft"><vers num="97"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0355" published="1999-01-01" seq="1999-0355" severity="Medium" type="CVE"><desc><descript source="cve">Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise18.php"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1653.php">controlit-reboot(1653)</ref></refs><vuln_soft><prod name="ControlIT" vendor="Computer Associates"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0356" published="1999-01-25" seq="1999-0356" severity="High" type="CVE"><desc><descript source="cve">ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-5.phpcontrolit-bookfile-access">controlit-bookfile-access</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0357" published="1999-01-25" seq="1999-0357" severity="Medium" type="CVE"><desc><descript source="cve">Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted &quot;oshare&quot; packets, possibly involving invalid fragmentation offsets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2228.php">win98-oshare-dos(2228)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0358" published="1999-02-01" seq="1999-0358" severity="High" type="CVE"><desc><descript source="cve">Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3137.php">du-inc(3137)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12121">19990125 Digital Unix 4.0 exploitable buffer overflows</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-027.shtml">J-027</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num="4.0"/><vers num="4.0A"/><vers num="4.0B"/><vers num="4.0C"/><vers num="4.0D"/><vers num="4.0e"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0359" published="2001-03-12" seq="1999-0359" severity="High" type="CVE"><desc><descript source="cve">ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26start%3D1999-01-27%26mid%3D12179%26end%3D1999-02-02%26fromthread%3D0%26threads%3D0%26">19990127 UNIX shell modem access vulnerabilities</ref></refs><vuln_soft><prod name="ptylogin" vendor="Marc Schaefer"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0360" published="1999-01-30" seq="1999-0360" severity="High" type="CVE"><desc><descript source="cve">MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="NT Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91763097004101&amp;w=2">IIS/MS Site Server</ref></refs><vuln_soft><prod name="Site Server" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0361" published="1999-01-01" seq="1999-0361" severity="High" type="CVE"><desc><descript source="cve">NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0362" published="1999-02-02" seq="1999-0362" severity="Medium" type="CVE"><desc><descript source="cve">WS_FTP server remote denial of service through cwd command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/217">bugtraq id 217</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1694.php">wsftp-remote-dos(1694)</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02021999.html">AD02021999</ref><ref source="BID" url="http://www.securityfocus.com/bid/217">217</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="1.0.2EVAL"/><vers num="1.0.1EVAL"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0363" published="1999-02-02" seq="1999-0363" severity="High" type="CVE"><desc><descript source="cve">SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1738.php">plp-lpc-bo(1738)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/328">BID 328</ref><ref source="BID" url="http://www.securityfocus.com/bid/328">328</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="5.2"/></prod><prod name="Line Printer Control" vendor="PLP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0364" published="1999-01-01" seq="1999-0364" severity="High" type="CVE"><desc><descript source="cve">Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91816470220259&amp;w=2">19990204 Microsoft Access 97 Stores Database Password as Plaintext</ref></refs><vuln_soft><prod name="Access" vendor="Microsoft"><vers num="97"/></prod><prod name="Total VB SourceBook" vendor="FMS Inc."><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0365" published="1999-02-04" seq="1999-0365" severity="High" type="CVE"><desc><descript source="cve">The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/110">BID 110</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1676.php">metamail-header-commands(1676)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Metainfo"><vers num="2.5"/><vers num="2.0"/></prod><prod name="MetaIP" vendor="Metainfo"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0366" published="1999-02-08" seq="1999-0366" severity="High" type="CVE"><desc><descript source="cve">In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/227">BID 227</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1719.php">nt-sp4-auth-error(1719)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-004.mspx">MS99-004</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q214840">Q214840</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0367" published="1999-02-09" seq="1999-0367" severity="Low" type="CVE"><desc><descript source="cve">NetBSD netstat command allows local users to access kernel memory.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" source="NetBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-002.txt.asc">1999-002</ref><ref source="OSVDB" url="http://www.osvdb.org/7571">7571</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0368" published="1999-02-09" seq="1999-0368" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-03-FTP-Buffer-Overflows.html">CA-99-03-FTP-Buffer-Overflows</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1728.php">palmetto-ftpd-bo(1728)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/113">BID 113</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.2 pre1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="5.1"/><vers num="5.0"/></prod><prod name="wu-ftpd" vendor="Washington University"><vers num="2.4.2 Beta18 VR9"/><vers num="2.4.2 Beta18"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="7.0.1"/><vers num="7.0"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.3"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0369" published="1997-02-01" seq="1999-0369" severity="High" type="CVE"><desc><descript source="cve">The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1729.php">sun-sdtcm-convert-bo(1729)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183">00183</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers edition="JL" num="1.1.4"/><vers num="1.1.4"/><vers edition="U1" num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1a"/><vers num="1.1"/><vers edition="x86" num="Any"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0370" published="1999-02-10" seq="1999-0370" severity="Medium" type="CVE"><desc><descript source="cve">In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-5.phpsun-man">sun-man</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D165">Solaris/SunOS man/catman Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/165">165</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers edition="x86" num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers edition="x86" num="2.5.1"/><vers num="2.6"/><vers edition="x86" num="2.6"/><vers num="7.0"/><vers edition="x86" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-04" name="CVE-1999-0371" published="1999-02-11" seq="1999-0371" severity="Low" type="CVE"><desc><descript source="cve">Lynx allows a local user to overwrite sensitive files through /tmp symlinks.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1665.php">lynx-temp-files-race(1665)</ref></refs><vuln_soft><prod name="Lynx" vendor="University of Kansas"><vers num="2.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0372" published="1999-02-12" seq="1999-0372" severity="Low" type="CVE"><desc><descript source="cve">The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1736.php">nt-backoffice-setup(1736)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-005.asp">MS99-005</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-005.mspx">MS99-005</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q217004">Q217004</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="BackOffice" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0373" published="1999-02-01" seq="1999-0373" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the &quot;Super&quot; utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/341">bugtraq id 341</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1723.php">linux-super-bo(1723)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1832.php">linux-super-logging-bo(1832)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0374" published="1999-02-16" seq="1999-0374" severity="Low" type="CVE"><desc><descript source="cve">Debian GNU/Linux cfengine package is susceptible to a symlink attack.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/314">bugtraq id 314</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1802.php">linux-cfengine-symlinks(1802)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0375" published="1999-02-16" seq="1999-0375" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1775.php">nfr-webd-overflow(1775)</ref></refs><vuln_soft><prod name="Network Flight Recorder" vendor="Network Flight Recorder"><vers num="2.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0376" published="1999-02-20" seq="1999-0376" severity="Medium" type="CVE"><desc><descript source="cve">Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/234">BID 234</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1820.php">nt-knowndlls-list(1820)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-006.asp">MS99-006</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-006.mspx">MS99-006</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-21" name="CVE-1999-0377" published="1999-02-22" seq="1999-0377" severity="Medium" type="CVE"><desc><descript source="cve">Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine&apos;s process tables through multiple connections to network services.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="remote assessment" url="http://remoteassessment.com/?op=varchive&amp;vulnid=5026">unix-process-table-dos</ref><ref source="CA" url="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=1459">Kernel process-table DoS</ref></refs><vuln_soft><prod name="Unix" vendor="Unix"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0378" published="1999-02-22" seq="1999-0378" severity="Medium" type="CVE"><desc><descript source="cve">InterScan VirusWall for Solaris doesn&apos;t scan files for viruses when a single HTTP request includes two GET commands.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3280.php">viruswall-http-request(3280)</ref><ref source="OSVDB" url="http://www.osvdb.org/6167">6167</ref></refs><vuln_soft><prod name="InterScan VirusWall" vendor="Trend Micro"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0379" published="1999-02-22" seq="1999-0379" severity="High" type="CVE"><desc><descript source="cve">Microsoft Taskpads allows remote web sites to execute commands on the visiting user&apos;s machine via certain methods that are marked as Safe for Scripting.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/498">bugtraq id 498</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1821.php">win-resourcekit-taskpads(1821)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-007.asp">MS99-007</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-007.mspx">MS99-007</ref><ref source="BID" url="http://www.securityfocus.com/bid/498">498</ref><ref source="OSVDB" url="http://www.osvdb.org/1019">1019</ref></refs><vuln_soft><prod name="BackOffice Resource Kit" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0380" published="1999-02-25" seq="1999-0380" severity="Medium" type="CVE"><desc><descript source="cve">SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user&apos;s Finger File to point to the target file, then running finger on the user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D497">NT SLMail Remote Administration Service Vulnerability</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91999015212415&amp;w=2">199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91996412724720&amp;w=2">19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92110501504997&amp;w=2">SLmail 3.2 Build 3113 (Web Administration Security Fix)</ref><ref source="BID" url="http://www.securityfocus.com/bid/497">497</ref><ref source="XF" url="http://xforce.iss.net/static/5392.php">slmail-ras-ntfs-bypass(5392)</ref></refs><vuln_soft><prod name="SLMail" vendor="Seattle Lab Software"><vers num="3.0.2421"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0381" published="1999-02-26" seq="1999-0381" severity="High" type="CVE"><desc><descript source="cve">super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1832.php">linux-super-logging-bo(1832 )</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/342">Debian Super Syslog Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.990225011801.12757A-100000@eleet">19990225 SUPER buffer overflow</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0382" published="1999-03-12" seq="1999-0382" severity="High" type="CVE"><desc><descript source="cve">The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/474">BID 474</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1946.php">nt-screen-saver(1946)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-008.asp">MS99-008</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-008.mspx">MS99-008</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/><vers num="3.5.1 SP5"/><vers num="3.5.1 SP4"/><vers num="3.5.1 SP3"/><vers num="3.5.1 SP2"/><vers num="3.5.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0383" published="1999-02-02" seq="1999-0383" severity="High" type="CVE"><desc><descript source="cve">ACC Tigris allows public access without a login.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/183">BID 183</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1571.php">acc-tigris-login(1571)</ref><ref source="BID" url="http://www.securityfocus.com/bid/183">183</ref><ref source="OSVDB" url="http://www.osvdb.org/267">267</ref></refs><vuln_soft><prod name="Tigris" vendor="ACC"><vers num="10.5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0384" published="1999-01-01" seq="1999-0384" severity="Medium" type="CVE"><desc><descript source="cve">The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user&apos;s clipboard when the user accesses documents with ActiveX content.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1659.php">forms-vuln-patch(1659)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-001.asp">MS99-001</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-001.mspx">MS99-001</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Office" vendor="Microsoft"><vers edition="Mac" num="98"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="98"/></prod><prod name="Visual Basic" vendor="Microsoft"><vers num="5.0"/></prod><prod name="Project" vendor="Microsoft"><vers num="98"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-1999-0385" published="1998-12-01" seq="1999-0385" severity="High" type="CVE"><desc><descript source="cve">The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/503">bugtraq id 503</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1969.php">ldap-mds-dos(1969)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-009.asp">MS99-009</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-009.mspx">MS99-009</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0386" published="1999-03-01" seq="1999-0386" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2036.php">pws-file-access(2036)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-010.asp">MS99-010</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-010.mspx">MS99-010</ref><ref source="OSVDB" url="http://www.osvdb.org/111">111</ref></refs><vuln_soft><prod name="Personal Web Server" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Frontpage" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0387" published="1999-11-29" seq="1999-0387" severity="High" type="CVE"><desc><descript source="cve">A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-052.asp">MS99-052</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-052.asp">MS99-052</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3574.php">9x-plaintext-pwd(3574)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/829">Bugtraq id 829</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q168115">Q168115</ref><ref source="BID" url="http://www.securityfocus.com/bid/829">829</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0388" published="1999-01-01" seq="1999-0388" severity="Medium" type="CVE"><desc><descript source="cve">DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/186">bugtraq id 186</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1543.php">datalynx-suguard-relative-paths(1543)</ref><ref source="OSVDB" url="http://www.osvdb.org/3186">3186</ref></refs><vuln_soft><prod name="suGuard" vendor="DataLynx"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0389" published="1999-01-03" seq="1999-0389" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the bootp server in the Debian Linux netstd package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/324">Debian GNU/Linux netstd Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4099.php">debian-netstd-bo(4099)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0390" published="1999-01-04" seq="1999-0390" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Dosemu Slang library in Linux.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-12-29&amp;msg=Pine.LNX.3.96.990104062606.4420B-100000@bufh.bbs.is"></ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/187">Bugtraq id 187</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt">CSSA-1999-006.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/187">187</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0391" published="1999-01-05" seq="1999-0391" severity="High" type="CVE"><desc><descript source="cve">The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/233">BID 233</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="3.5.1 SP5"/><vers num="3.5.1 SP4"/><vers num="3.5.1 SP3"/><vers num="3.5.1 SP2"/><vers num="3.5.1 SP1"/></prod><prod name="Terminal Server" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0392" published="1999-01-10" seq="1999-0392" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Thomas Boutell&apos;s cgic library version up to 1.05.</descript></desc><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1603.php">http-cgic-library-bo(1603)</ref></refs><vuln_soft><prod name="cgic library" vendor="Thomas Boutell"><vers num="1.05" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0393" published="1999-01-01" seq="1999-0393" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3477.php">sendmail-parsing-redirection(3477)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91694391227372&amp;w=2">19990121 Sendmail 8.8.x/8.9.x bugware</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.9.2"/><vers num="8.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0394" published="1999-01-01" seq="1999-0394" severity="High" type="CVE"><desc><descript source="cve">DPEC Online Courseware allows an attacker to change another user&apos;s password without knowing the original password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0395" published="1999-01-01" seq="1999-0395" severity="Medium" type="CVE"><desc><descript source="cve">A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1611.php">backweb-polite-agent-protocol(1611)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise17.php">backweb-polite-agent-protocol</ref></refs><vuln_soft><prod name="BackWeb Polite Agent Protocol" vendor="BackWeb Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0396" published="1999-02-17" seq="1999-0396" severity="Low" type="CVE"><desc><descript source="cve">A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1658.php">netbsd-tcp-race(1658)</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0397" published="1999-01-01" seq="1999-0397" severity="High" type="CVE"><desc><descript source="cve">The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0398" published="1999-01-01" seq="1999-0398" severity="Medium" type="CVE"><desc><descript source="cve">In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3493.php">ssh-exp-account-access(3493)</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.27"/></prod><prod name="SSH2" vendor="SSH Communications Security"><vers num="2.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0399" published="1999-01-01" seq="1999-0399" severity="High" type="CVE"><desc><descript source="cve">The DCC server command in the Mirc 5.5 client doesn&apos;t filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3495.php">mirc-dcc-metachar-filename</ref></refs><vuln_soft><prod name="mIRC" vendor="Khaled Mardam-Bey"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0400" published="1999-01-26" seq="1999-0400" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Linux 2.2.0 running the ldd command on a core file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/344">Linux ldd core Vulnerability</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0401" published="1999-01-01" seq="1999-0401" severity="Low" type="CVE"><desc><descript source="cve">A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3497.php">linux-race-condition-proc(3497)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0402" published="1999-01-02" seq="1999-0402" severity="Medium" type="CVE"><desc><descript source="cve">wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1805.php">wget-permissions(1805)</ref></refs><vuln_soft><prod name="wget" vendor="GNU"><vers num="1.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0403" published="1999-02-01" seq="1999-0403" severity="Medium" type="CVE"><desc><descript source="cve">A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1716.php">cyrix-hang(1716)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91821080015725&amp;w=2">19990204 Cyrix bug: freeze in hell, badboy</ref></refs><vuln_soft><prod name="Linux" vendor="Cyrix"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0404" published="1999-02-14" seq="1999-0404" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1773.php">mailmax-bo(1773)</ref></refs><vuln_soft><prod name="MailMax" vendor="SmartMax Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0405" published="1999-02-18" seq="1999-0405" severity="High" type="CVE"><desc><descript source="cve">A buffer overflow in lsof allows local users to obtain root privilege.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/496">bugtraq id 496</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1791.php">lsof-bo(1791)</ref><ref source="OSVDB" url="http://www.osvdb.org/3163">3163</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.2.8"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.1.7.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="5.2"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4.1"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0.5"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0406" published="1999-02-19" seq="1999-0406" severity="High" type="CVE"><desc><descript source="cve">Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1807.php">digital-networker-bo(1807)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-6.phpdigital-networker-bo">digital-networker-bo(1807)</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0407" published="1999-02-09" seq="1999-0407" severity="High" type="CVE"><desc><descript source="cve">By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91983486431506&amp;w=2">19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92000623021036&amp;w=2">19990209 Re: IIS4 allows proxied password attacks over NetBIOS</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0408" published="1999-02-25" seq="1999-0408" severity="High" type="CVE"><desc><descript source="cve">Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Wired" url="http://www.wired.com/news/news/technology/story/18109.html"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1831.php">cobalt-raq-history-exposure(1831)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/337">bugtraq id 337</ref><ref source="BID" url="http://www.securityfocus.com/bid/337">337</ref></refs><vuln_soft><prod name="Cobalt RaQ" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0409" published="1999-03-04" seq="1999-0409" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1888.php">gnuplot-home-overflow(1888)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/319">BID 319</ref><ref source="BID" url="http://www.securityfocus.com/bid/319">319</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="5.2"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0410" published="1999-03-05" seq="1999-0410" severity="High" type="CVE"><desc><descript source="cve">The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/293">bugtraq id 293</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1900.php">sol-cancel(1900)</ref><ref source="BID" url="http://www.securityfocus.com/bid/293">293</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0411" published="1999-03-07" seq="1999-0411" severity="High" type="CVE"><desc><descript source="cve">Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1930.php">sco-startup-scripts(1930)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-7.phpsco-startup-scripts">sco-startup-scripts</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="3.0"/><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0412" published="1999-02-19" seq="1999-0412" severity="High" type="CVE"><desc><descript source="cve">In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/501">bugtraq id 501</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1950.php">iis-isapi-execute(1950)</ref><ref source="BID" url="http://www.securityfocus.com/bid/501">501</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0413" published="1999-03-01" seq="1999-0413" severity="High" type="CVE"><desc><descript source="cve">A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1929.php">irix-font-path-overflow(1929)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX">19990301-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.3"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0414" published="1999-03-01" seq="1999-0414" severity="Medium" type="CVE"><desc><descript source="cve">In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/580">bugtraq id 580</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1932.php">linux-blind-spoof(1932)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0.37"/><vers num="2.0.36"/><vers num="2.0.35"/><vers num="2.0.30"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0415" published="1999-03-11" seq="1999-0415" severity="High" type="CVE"><desc><descript source="cve">The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router&apos;s configuration.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS" url="http://xforce.iss.net/alerts/vol-3_num-7.php">cisco-router-commands</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1951.php">cisco-router-commands(1951)</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref></refs><vuln_soft><prod name="Cisco 7xx Routers" vendor="Cisco"><vers num="4.2" prev="1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0416" published="1999-03-11" seq="1999-0416" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router&apos;s TELNET port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS" url="http://xforce.iss.net/alerts/vol-3_num-7.php">cisco-router-dos</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1886.php">cisco-web-crash(1886)</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref></refs><vuln_soft><prod name="Cisco 7xx Routers" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0417" published="1999-03-09" seq="1999-0417" severity="Low" type="CVE"><desc><descript source="cve">64 bit Solaris 7 procfs allows local users to perform a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1935.php">solaris-psinfo-crash(1935)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/448.com">BID 448</ref><ref source="BID" url="http://www.securityfocus.com/bid/448">448</ref><ref source="OSVDB" url="http://www.osvdb.org/1001">1001</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0418" published="1999-03-08" seq="1999-0418" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many &quot;RCPT TO&quot; commands in the same connection.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100018214316&amp;w=2">19990308 SMTP server account probing</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0419" published="1999-03-01" seq="1999-0419" severity="Medium" type="CVE"><desc><descript source="cve">When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3499.php">smtp-4xx-error-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/12874"></ref></refs></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0420" published="1999-03-17" seq="1999-0420" severity="High" type="CVE"><desc><descript source="cve">umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="NetBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-006.txt.asc"></ref></refs><vuln_soft><prod name="umapfs" vendor="NetBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0421" published="1999-03-17" seq="1999-0421" severity="High" type="CVE"><desc><descript source="cve">During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/338">BID 338</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2040.php">linux-slackware-install(2040)</ref><ref source="OSVDB" url="http://www.osvdb.org/981">981</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0422" published="1999-03-17" seq="1999-0422" severity="Medium" type="CVE"><desc><descript source="cve">In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the &quot;noexec&quot; flag set.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="NetBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-007.txt.asc"></ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0423" published="1994-06-01" seq="1999-0423" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2182.php">hp-hpterm-files(2182)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093">HPSBUX9903-093</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0424" published="1999-03-18" seq="1999-0424" severity="Low" type="CVE"><desc><descript source="cve">talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2006.php">netscape-talkback-overwrite(2006)</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0425" published="1999-03-18" seq="1999-0425" severity="Medium" type="CVE"><desc><descript source="cve">talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2005.php">netscape-talkback-kill(2005)</ref><ref adv="1" source="SuSE Linux" url="http://www.suse.de/de/support/security/suse_security_announce_2.txt">19.03.1999</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0426" published="1999-03-01" seq="1999-0426" severity="High" type="CVE"><desc><descript source="cve">The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3500.php">linux-dev-kmem-spoof</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0427" published="2000-05-01" seq="1999-0427" severity="High" type="CVE"><desc><descript source="cve">Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4482.php">eudora-long-attachment-filename(4482)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1210">BID 1210</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num="4.3"/><vers num="4.2"/></prod><prod name="Eudora Light" vendor="Qualcomm"><vers num="3.0"/></prod><prod name="Eudora Pro" vendor="Qualcomm"><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0428" published="1999-03-22" seq="1999-0428" severity="High" type="CVE"><desc><descript source="cve">OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1991.php">ssl-session-reuse(1991)</ref><ref patch="1" source="OpenSSL" url="http://www.openssl.org/news/announce.html"></ref><ref adv="1" patch="1" source="Listserv at NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9903d&amp;L=bugtraq&amp;F=&amp;S=&amp;P=65">OpenSSL and SSLeay Security Alert</ref><ref source="OSVDB" url="http://www.osvdb.org/3936">3936</ref></refs><vuln_soft><prod name="OpenSSL" vendor="OpenSSL Project"><vers num=""/></prod><prod name="SSLeay" vendor="SSLeay"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0429" published="1999-03-01" seq="1999-0429" severity="High" type="CVE"><desc><descript source="cve">The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the &quot;Encrypt Saved Mail&quot; preference.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2047.php">lotus-client-encryption(2047)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92221437025743&amp;w=2">19990323</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92241547418689&amp;w=2">19990324 Re: LNotes encryption</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92246997917866&amp;w=2">19990326 Lotus Notes Encryption Bug</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92249282302994&amp;w=2">19990326 Re: Lotus Notes security advisory</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0430" published="1999-03-01" seq="1999-0430" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/705">bugtraq id 705</ref><ref adv="1" patch="1" source="Cisco" url="http://securityfocus.com/templates/advisory.html?id=1770">CI-99.03</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/sec_incident_response.shtml"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2019.php">cisco-catalyst-crash(2019)</ref><ref source="OSVDB" url="http://www.osvdb.org/1103">1103</ref></refs><vuln_soft><prod name="Catalyst 29xx supervisor software" vendor="Cisco"><vers num="2.1.502"/><vers num="2.1.501"/><vers num="2.1.5"/><vers num="1.0"/></prod><prod name="Catalyst 12xx supervisor software" vendor="Cisco"><vers num="4.29"/></prod><prod name="Catalyst 5xxx supervisor software" vendor="Cisco"><vers num="2.1.502"/><vers num="2.1.501"/><vers num="2.1.5"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-09" name="CVE-1999-0431" published="1999-03-01" seq="1999-0431" severity="Medium" type="CVE"><desc><descript source="cve">Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.</descript></desc><sols><sol source="nvd">This problem was fixed in Linux kernel 2.2.4 and later releases.</sol></sols><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2041.php">linux-zerolength-fragment(2041)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.1.89"/><vers num="2.2"/><vers num="2.2.10"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15"/><vers num="2.2.15 pre16"/><vers num="2.2.15 pre20"/><vers num="2.2.16"/><vers num="2.2.16 pre6"/><vers num="2.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0432" published="1999-03-01" seq="1999-0432" severity="Medium" type="CVE"><desc><descript source="cve">ftp on HP-UX 11.00 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2009.php">hp-ftp(2009)</ref><ref adv="1" source="HP.com" url="http://us-support.external.hp.com/index.html"></ref><ref adv="1" patch="1" source="HP.com" url="http://us-support.external.hp.com/cki/bin/doc.pl/sid=46ddf44e169cfc3383/screen=ckiDisplayDocument?docId=400000000240811">HPSBUX9903-094</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094">HPSBUX9903-094</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0433" published="1999-03-21" seq="1999-0433" severity="Medium" type="CVE"><desc><descript source="cve">XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/326">BID 326</ref><ref patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.NEB.4.02.9903212108120.5403-100000@stinky"></ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=14075.60480.760010.181394@gargle.gargle.HOWL"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2032.php">xfree86-temp-directories(2032)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="5.2"/><vers num="5.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.1"/><vers num="6.0"/><vers num="5.2"/><vers num="5.1"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3"/><vers num="1.3.2"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="3.3.3"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="4.0"/><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0434" published="1999-03-30" seq="1999-0434" severity="High" type="CVE"><desc><descript source="cve">XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/359">Multiple Vendor xfs Symlink Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3502.php">xfree86-xfs-symlink-dos</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="5.3"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0r5"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0435" published="1999-03-01" seq="1999-0435" severity="High" type="CVE"><desc><descript source="cve">MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2046.php">hp-serviceguard(2046)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-8.php">hp-serviceguard</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.0"/><vers num="10.0.1"/><vers num="10.1"/><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0436" published="1999-03-01" seq="1999-0436" severity="Medium" type="CVE"><desc><descript source="cve">Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2045.php">hp-desms-servers(2045)</ref><ref adv="1" source="HP.com" url="http://us-support.external.hp.com/index.html"></ref><ref adv="1" patch="1" source="HP.com" url="http://us-support.external.hp.com/cki/bin/doc.pl/sid=74be24a31db1e23efe/screen=ckiDisplayDocument?docId=400000000241129">HPSBUX9903-095</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095">HPSBUX9903-095</ref></refs><vuln_soft><prod name="DESMS" vendor="HP"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0437" published="1999-03-01" seq="1999-0437" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2050.php">webramp-device-crash(2050)</ref></refs><vuln_soft><prod name="WebRamp" vendor="Ramp Networks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0438" published="1999-03-01" seq="1999-0438" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/577">bugtraq id 577</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.SUN.3.96.990803112821.17628B-100000@grex.cyberspace.org"></ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=000d01bee028$2fa68b30$9a65fdcf@slacky"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2051.php">webramp-ipchange(2051)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise25.php"></ref></refs><vuln_soft><prod name="WebRamp M3" vendor="Ramp Networks"><vers num="1.0"/></prod><prod name="WebRamp 200i" vendor="Ramp Networks"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0439" published="1999-04-05" seq="1999-0439" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2082.php">procmail-overflow(2082)</ref><ref patch="1" source="procmail.org" url="http://www.procmail.org/"></ref><ref adv="1" patch="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904a&amp;L=bugtraq&amp;D=0&amp;P=2003"></ref></refs><vuln_soft><prod name="procmail" vendor="procmail"><vers num="3.12" prev="1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0440" published="1999-03-01" seq="1999-0440" severity="High" type="CVE"><desc><descript source="cve">The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2025.php">java-unverified-code(2025)</ref><ref source="CONFIRM" url="http://java.sun.com/pr/1999/03/pr990329-01.html">http://java.sun.com/pr/1999/03/pr990329-01.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92333596624452&amp;w=2">19990405 Security Hole in Java 2 (and JDK 1.1.x)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1939">1939</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.5"/></prod><prod name="Navigator" vendor="Netscape"><vers num="4.0"/><vers num="4.01"/><vers num="4.02"/><vers num="4.03"/><vers num="4.04"/><vers num="4.05"/><vers num="4.06"/><vers num="4.07"/><vers num="4.08"/><vers num="4.5"/><vers num="4.61"/></prod><prod name="Java" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0441" published="1999-02-22" seq="1999-0441" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/509">bugtraq id 509</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/advisory.html?id=1594">AD02221999</ref><ref patch="1" source="deerfield.com" url="http://wingate.deerfield.com/support/index.cfm"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2066.php">wingate-redirector-dos(2066)</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02221999.html">AD02221999</ref><ref source="BID" url="http://www.securityfocus.com/bid/509">509</ref></refs><vuln_soft><prod name="WinGate" vendor="Qbik"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0442" published="1999-01-07" seq="1999-0442" severity="Low" type="CVE"><desc><descript source="cve">Solaris ff.core allows local users to modify files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/327">BID 327</ref><ref patch="1" source="SUN" url="http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access"></ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.GSO.4.05.9901081235340.880-100000@naur.csee.wvu.edu"></ref><ref patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=199901151320.OAA11141@romulus"></ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.OSF.4.05.9901070946310.11222-100000@osprey.unf.edu"></ref><ref source="BID" url="http://www.securityfocus.com/bid/327">327</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0443" published="1999-04-01" seq="1999-0443" severity="High" type="CVE"><desc><descript source="cve">Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2078.php">bmc-patrol-replay(2078)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref></refs><vuln_soft><prod name="PATROL Agent" vendor="BMC Software"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0444" published="1999-04-12" seq="1999-0444" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3328.php">windows-arp-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/13232"></ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0445" published="1999-04-01" seq="1999-0445" severity="Medium" type="CVE"><desc><descript source="cve">In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/706">BID 706</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/advisory.html?id=1429"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2071.php">cisco-natacl-leakage(2071)</ref><ref source="OSVDB" url="http://www.osvdb.org/1104">1104</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0.2XG"/><vers num="12.0.2XF"/><vers num="12.0.2XD"/><vers num="12.0.2XC"/><vers num="12.0.1XE"/><vers num="12.0.1XB"/><vers num="12.0.1XA3"/><vers num="12.0.1W"/><vers num="12.0T"/><vers num="12.0S"/><vers num="12.0DB"/><vers num="12.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0446" published="1999-04-12" seq="1999-0446" severity="Low" type="CVE"><desc><descript source="cve">Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2062.php">netbsd-vfslocking-panic(2062)</ref><ref adv="1" patch="1" source="NetBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-008.txt.asc">1999-008</ref><ref source="OSVDB" url="http://www.osvdb.org/7051">7051</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.1"/><vers num="1.3.3"/><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0447" published="1999-04-01" seq="1999-0447" severity="Medium" type="CVE"><desc><descript source="cve">Local users can gain privileges using the debug utility in the MPE/iX operating system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2073.php">mpeix-debug(2073)</ref><ref adv="1" source="HP.com" url="http://us-support.external.hp.com/cki/bin/doc.pl/sid=22660f44193e555c40/screen=ckiDisplayDocument?docId=400000000241549">HPSBMP9904-006</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006">HPSBMP9904-006</ref></refs><vuln_soft><prod name="MPE iX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0448" published="1999-01-01" seq="1999-0448" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/191">bugtraq id 191</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1656.php">iis-http-request-logging(1656)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0449" published="1999-01-26" seq="1999-0449" severity="High" type="CVE"><desc><descript source="cve">The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/193">bugtraq id 193</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2229.php">iis-exair-dos(2229)</ref><ref source="BID" url="http://www.securityfocus.com/bid/193">193</ref><ref source="OSVDB" url="http://www.osvdb.org/2">2</ref><ref source="OSVDB" url="http://www.osvdb.org/3">3</ref><ref source="OSVDB" url="http://www.osvdb.org/4">4</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0450" published="1999-01-26" seq="1999-0450" severity="High" type="CVE"><desc><descript source="cve">In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe) .</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/194">194</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0451" published="1999-01-19" seq="1999-0451" severity="Low" type="CVE"><desc><descript source="cve">Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/343">Linux TCP port DoS Vulnerability</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0452" published="1999-01-01" seq="1999-0452" severity="High" type="CVE"><desc><descript source="cve">A service or application has a backdoor password that was placed there by the developer.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-08-20" name="CVE-1999-0453" published="1999-01-01" seq="1999-0453" severity="Medium" type="CVE"><desc><descript source="cve">An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Cisco router" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0454" published="1999-01-01" seq="1999-0454" severity="High" type="CVE"><desc><descript source="cve">A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0455" published="1999-12-25" seq="1999-0455" severity="High" type="CVE"><desc><descript source="cve">The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1740.php">coldfusion-expression-evaluator(1740)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/115">Allaire ColdFusion Remote File Display, Deletion, Upload and Execution Vulnerability</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0457" published="1999-01-17" seq="1999-0457" severity="High" type="CVE"><desc><descript source="cve">Linux ftpwatch program allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/317">bugtraq id 317</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.GSO.3.96.990217191538.18872B-100000@borg"></ref><ref patch="1" source="Debian" url="http://cgi.debian.org/www-master/debian.org/Packages/stable/net/ftpwatch"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1607.php">ftpwatch-vuln(1607)</ref><ref source="BID" url="http://www.securityfocus.com/bid/317">317</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/><vers num="1.3.1"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0458" published="1999-01-06" seq="1999-0458" severity="Low" type="CVE"><desc><descript source="cve">L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1606.php">l0phtcrack-temp-files(1606)</ref><ref patch="1" source="L0pht" url="http://www.l0pht.com/l0phtcrack/"></ref><ref adv="1" patch="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9901A&amp;L=bugtraq&amp;P=R7175"></ref><ref source="OSVDB" url="http://www.osvdb.org/915">915</ref></refs><vuln_soft><prod name="L0phtCrack" vendor="L0pht"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0459" published="1999-02-01" seq="1999-0459" severity="Medium" type="CVE"><desc><descript source="cve">Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1717.php">linux-milo-halt(1717)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-5.php">linux-milo-halt(1717)</ref></refs></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0460" published="1999-02-19" seq="1999-0460" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/312">Linux autofs Vulnerability</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0"/><vers num="2.1"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0461" published="1999-01-28" seq="1999-0461" severity="High" type="CVE"><desc><descript source="cve">Versions of rpcbind including Linux, IRIX, and Wietse Venema&apos;s rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2308.php">pmap-sset(2308)</ref><ref adv="1" patch="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9901E&amp;L=bugtraq&amp;P=R125"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0462" published="1999-03-17" seq="1999-0462" severity="High" type="CVE"><desc><descript source="cve">suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/339">Perl suidmount Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3544.php">perl-suidperl-bo(3544)</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0463" published="1998-12-01" seq="1999-0463" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service using IRIX fcagent.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/144">bugtraq id 144</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1443.php">sgi-fcagent-dos(1443)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981201-01-PX">19981201-01-PX</ref></refs><vuln_soft><prod name="L0phtCrack" vendor="L0pht"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0464" published="1999-01-04" seq="1999-0464" severity="Low" type="CVE"><desc><descript source="cve">Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91553066310826&amp;w=2">19990104 Tripwire mess..</ref><ref source="OSVDB" url="http://www.osvdb.org/6609">6609</ref></refs><vuln_soft><prod name="Tripwire" vendor="Tripwire"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0465" published="1999-01-01" seq="1999-0465" severity="High" type="CVE"><desc><descript source="cve">Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0466" published="1999-04-21" seq="1999-0466" severity="High" type="CVE"><desc><descript source="cve">The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/114">bugtraq id 114</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/templates/advisory.html?id=328">NetBSD-SA1999-009</ref><ref source="OSVDB" url="http://www.osvdb.org/905">905</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0467" published="1999-04-01" seq="1999-0467" severity="Medium" type="CVE"><desc><descript source="cve">The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the &quot;template&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2072.php">http-cgi-webcom-guestbook(2072)</ref></refs><vuln_soft><prod name="CGI Guestbook" vendor="Webcom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0468" published="1999-04-09" seq="1999-0468" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 5.0 allows a remote server to read arbitrary files on the client&apos;s file system using the Microsoft Scriptlet Component.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2070.php">ie-scriplet-fileread(2070)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904b&amp;L=bugtraq&amp;F=&amp;S=&amp;P=1504"></ref><ref patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q226/3/25.asp"></ref><ref adv="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS99-012</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/windows/ie/security/mshtml.asp">MSHTML</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0469" published="1999-04-01" seq="1999-0469" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2069.php">ie-window-spoof</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0470" published="1999-04-09" seq="1999-0470" severity="Medium" type="CVE"><desc><descript source="cve">A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2081.php">netware-remotenlm-passwords(2081)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904B&amp;L=bugtraq&amp;P=R1516"></ref><ref source="BID" url="http://www.securityfocus.com/bid/482">482</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0471" published="1999-04-09" seq="1999-0471" severity="Medium" type="CVE"><desc><descript source="cve">The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the &quot;cancel&quot; button.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2079.php">winroute-config(2079)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904B&amp;L=bugtraq&amp;P=R1283"></ref><ref patch="1" source="TINY Software" url="http://www.winroute.com/"></ref></refs><vuln_soft><prod name="WinRoute" vendor="WinRoute"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0472" published="1999-04-07" seq="1999-0472" severity="Medium" type="CVE"><desc><descript source="cve">The SNMP default community name &quot;public&quot; is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2080.php">netcache-snmp(2080)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904A&amp;L=bugtraq&amp;P=R4014"></ref></refs><vuln_soft><prod name="SNMP" vendor="SNMP"><vers num=""/></prod><prod name="NetCache" vendor="Network Appliance"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0473" published="1999-04-07" seq="1999-0473" severity="Low" type="CVE"><desc><descript source="cve">The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client&apos;s working directory to the permissions of the directory being transferred.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2074.php">rsync-permissions(2074)</ref><ref adv="1" patch="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904A&amp;L=bugtraq&amp;P=R3834"></ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/1999/19990823">19990823</ref><ref source="BID" url="http://www.securityfocus.com/bid/145">145</ref></refs><vuln_soft><prod name="rsync" vendor="Andrew Tridgell"><vers num="2.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0474" published="1999-04-05" seq="1999-0474" severity="Medium" type="CVE"><desc><descript source="cve">The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user&apos;s personal directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2085.php">icq-webserver-read(2085)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904a&amp;L=bugtraq&amp;F=&amp;S=&amp;P=3795"></ref><ref patch="1" source="Mirabilis ICQ" url="http://www.icq.com/download/"></ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="99a 2.13Build1700"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0475" published="1999-04-05" seq="1999-0475" severity="Low" type="CVE"><desc><descript source="cve">A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2083.php">procmail-race(2083)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904a&amp;L=bugtraq&amp;F=&amp;S=&amp;P=4470"></ref></refs><vuln_soft><prod name="procmail" vendor="procmail"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0476" published="1999-03-01" seq="1999-0476" severity="High" type="CVE"><desc><descript source="cve">A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2063.php">sco-termvision-password(2063)</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0477" published="1999-12-25" seq="1999-0477" severity="High" type="CVE"><desc><descript source="cve">The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/115">Allaire ColdFusion Remote File Display, Deletion, Upload and Execution Vulnerability</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="2.0"/><vers num="3.0"/><vers num="3.01"/><vers num="3.11"/><vers num="3.12"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0478" published="1998-12-01" seq="1999-0478" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2300.php">sendmail-headers-dos(2300)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-12-08&amp;msg=Pine.LNX.4.05.9812121913580.294-200000@nimue.ids.pl"></ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9904-097">HPSBUX9904-097</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="8.9.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0479" published="1999-03-01" seq="1999-0479" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1964.php">netscape-server-dos(1964)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-092">HPSBUX9903-092</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.6"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.24"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0480" published="1999-04-01" seq="1999-0480" severity="Low" type="CVE"><desc><descript source="cve">Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3505.php">midnight-commander-symlink-dos(3505)</ref></refs><vuln_soft><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0481" published="1999-03-22" seq="1999-0481" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in &quot;poll&quot; in OpenBSD.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.htmlpoll"></ref><ref source="OSVDB" url="http://www.osvdb.org/7556">7556</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0482" published="1999-03-21" seq="1999-0482" severity="Medium" type="CVE"><desc><descript source="cve">OpenBSD kernel crash through TSS handling, as caused by the crashme program.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.htmltss"></ref><ref source="OSVDB" url="http://www.osvdb.org/7557">7557</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0483" published="1999-02-25" seq="1999-0483" severity="Low" type="CVE"><desc><descript source="cve">OpenBSD crash using nlink value in FFS and EXT2FS filesystems.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.htmltss"></ref><ref source="OSVDB" url="http://www.osvdb.org/6129">6129</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0484" published="1999-02-23" seq="1999-0484" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in OpenBSD ping.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/6130">6130</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0485" published="1999-02-19" seq="1999-0485" severity="Low" type="CVE"><desc><descript source="cve">Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1829.php">openbsd-ipintr-race(1829)</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.htmltss"></ref><ref source="OSVDB" url="http://www.osvdb.org/7558">7558</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0486" published="1998-02-01" seq="1999-0486" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4877.php">aolim-malformed-ascii-dos(4877)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/819.php">aol-im(819)</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0487" published="1999-05-01" seq="1999-0487" severity="Low" type="CVE"><desc><descript source="cve">The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/116">bugtraq id 116</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-011.asp">MS99-011</ref><ref source="Cuartango" url="http://pages.whowhere.com/computers/cuartangojc/dhtmle1.html"></ref><ref adv="1" patch="1" source="Microsoft Knowledge Base" url="http://support.microsoft.com/support/kb/articles/q226/3/26.asp">q226326</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2161.php">ie-dhtml-control(2161)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-011.mspx">MS99-011</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0488" published="1999-04-21" seq="1999-0488" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the &quot;cross frame&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2216.php">ie-mshtml-crossframe(2216)</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS99-012</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/><vers num="4.0.0.1"/><vers num="4.0.0.1SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0489" published="1999-05-17" seq="1999-0489" severity="High" type="CVE"><desc><descript source="cve">MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of &quot;untrusted scripted paste&quot; as described in MS:MS98-013.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-015.asp">MS:MS99-015</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0490" published="1999-04-21" seq="1999-0490" severity="High" type="CVE"><desc><descript source="cve">MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user&apos;s files via an IMG SRC tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2070.php">ie-scriplet-fileread</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS:MS99-012</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-1999-0491" published="1999-04-20" seq="1999-0491" severity="Medium" type="CVE"><desc><descript source="cve">The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/119">bugtraq id 119</ref><ref adv="1" patch="1" source="Caldera" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt">CSSA-1999:008.0</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9904202114070.6623-100000@smooth.Operator.org">19990420 Bash Bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/119">119</ref></refs><vuln_soft><prod name="bash" vendor="bash"><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0492" published="1999-04-23" seq="1999-0492" severity="High" type="CVE"><desc><descript source="cve">The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0493" published="1999-06-07" seq="1999-0493" severity="High" type="CVE"><desc><descript source="cve">rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/450">BID 450</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05-statd-automountd</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/186&amp;type=0&amp;nav=sec.sba">00186</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-045.shtml">J-045</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref><ref source="BID" url="http://www.securityfocus.com/bid/450">450</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0494" published="1998-07-01" seq="1999-0494" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in WinGate proxy through a buffer overflow in POP3.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1847.php">wingate-pop3-user-bo(1847)</ref><ref source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9807A&amp;L=bugtraq&amp;F=&amp;S=&amp;P=4317"></ref></refs><vuln_soft><prod name="WinGate" vendor="WinGate"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0495" published="1999-01-01" seq="1999-0495" severity="High" type="CVE"><desc><descript source="cve">A remote attacker can gain access to a file system using ..  (dot dot) when accessing SMB shares.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0496" published="1997-01-01" seq="1999-0496" severity="Medium" type="CVE"><desc><descript source="cve">A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user&apos;s permissions, aka GetAdmin.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft Knowledge Base" url="http://support.microsoft.com/support/kb/articles/q146/9/65.ASP">q146965</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q146965">Q146965</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0497" published="1999-01-01" seq="1999-0497" severity="Low" type="CVE"><desc><descript source="cve">Anonymous FTP is enabled.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">Anonymous FTP is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0498" published="1991-09-27" seq="1999-0498" severity="High" type="CVE"><desc><descript source="cve">TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/308.php">linux-tftp(308)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-18.html">CERT:CA-91.18.Active.Internet.tftp.Attacks</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0499" published="1997-01-01" seq="1999-0499" severity="High" type="CVE"><desc><descript source="cve">NETBIOS share information may be published through SNMP registry keys in NT.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/215.php">snmp-netbios</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0501" published="1998-06-01" seq="1999-0501" severity="Medium" type="CVE"><desc><descript source="cve">A Unix account has a guessable password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1005.php">default-unix-lp(1005)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0502" published="1998-03-01" seq="1999-0502" severity="High" type="CVE"><desc><descript source="cve">A Unix account has a default, null, blank, or missing password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/774.php">passwd-blank(774)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2941.php">passwd-blank-lines(2941)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers num="2.6"/><vers num="7.0"/><vers num="8.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0503" published="1997-01-01" seq="1999-0503" severity="High" type="CVE"><desc><descript source="cve">A Windows NT local user or administrator account has a guessable password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/282.php">nt-guess-admin(282)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1328.php">nt-guessed-powerwd(1328)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0504" published="1997-01-01" seq="1999-0504" severity="High" type="CVE"><desc><descript source="cve">A Windows NT local user or administrator account has a default, null, blank, or missing password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/159.php">nt-guestblankpw(159)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/163.php">nt-guestnopw</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0505" published="1998-10-01" seq="1999-0505" severity="High" type="CVE"><desc><descript source="cve">A Windows NT domain user or administrator account has a guessable password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1329.php">nt-guessed-domain-userpwd(1329)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3421.php">win2k-certpub-usrpwd(3421)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0506" published="1998-10-01" seq="1999-0506" severity="High" type="CVE"><desc><descript source="cve">A Windows NT domain user or administrator account has a default, null, blank, or missing password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1355.php">nt-domain-admin-blankpwd(1355)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3422.php">win2k-dhcpadm-blnkpwd(3422)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0507" published="1998-04-01" seq="1999-0507" severity="High" type="CVE"><desc><descript source="cve">An account on a router, firewall, or other network device has a guessable password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/388.php">firewall-tisopen(388)</ref></refs></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0508" published="1998-06-01" seq="1999-0508" severity="Medium" type="CVE"><desc><descript source="cve">An account on a router, firewall, or other network device has a default, null, blank, or missing password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/980.php">default-netranger(980)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2002.php">motorola-cable-default-pass</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1816.php">cayman-gatorbox</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0509" published="1996-05-29" seq="1999-0509" severity="High" type="CVE"><desc><descript source="cve">Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1996-11.html">CERT:CA-96.11</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0510" published="1997-01-01" seq="1999-0510" severity="High" type="CVE"><desc><descript source="cve">A router or firewall allows source routed packets from arbitrary hosts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/639.php">source-routing(639)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3577.php">source-routing-disable(3577)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0511" published="1997-01-01" seq="1999-0511" severity="High" type="CVE"><desc><descript source="cve">IP forwarding is enabled on a machine which is not a router or firewall.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/193.php">ip-forwarding(193)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0512" published="1999-01-01" seq="1999-0512" severity="High" type="CVE"><desc><descript source="cve">A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0513" published="1998-01-05" seq="1999-0513" severity="Medium" type="CVE"><desc><descript source="cve">ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.01.smurf.html">CA-98.01</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.91.971012142256.3522B-100000@tap.net"></ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/147">BID 147</ref><ref adv="1" source="Craig Huegen" url="http://users.quadrunner.com/chuegen/smurf.txt"></ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.1.7.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="1.1.5.1"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/><vers num="3.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.1"/><vers num="2.0"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0D"/><vers num="4.0C"/><vers num="4.0B"/><vers num="4.0A"/><vers num="4.0"/><vers num="3.2G"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.2"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.20"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0514" published="1998-03-01" seq="1999-0514" severity="Medium" type="CVE"><desc><descript source="cve">UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/815.php">fraggle(815)</ref><ref adv="1" source="Craig Huegen" url="http://users.quadrunner.com/chuegen/smurf.txt"></ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0515" published="1999-01-01" seq="1999-0515" severity="High" type="CVE"><desc><descript source="cve">An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0516" published="1998-08-01" seq="1999-0516" severity="High" type="CVE"><desc><descript source="cve">An SNMP community name is guessable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1241.php">snmp-get-guess(1241)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0517" published="1997-01-01" seq="1999-0517" severity="High" type="CVE"><desc><descript source="cve">An SNMP community name is the default (e.g. public), null, or missing.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1387.php">hpov-hidden-snmp-comm(1387)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/133.php">snmp-comm(133)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="10"/><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0518" published="1997-01-01" seq="1999-0518" severity="High" type="CVE"><desc><descript source="cve">A NETBIOS/SMB share password is guessable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/182.php">nt-netbios-perm(182)</ref></refs><vuln_soft><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0519" published="1997-01-01" seq="1999-0519" severity="High" type="CVE"><desc><descript source="cve">A NETBIOS/SMB share password is the default, null, or missing.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1.php">nt-netbios-everyoneaccess(1)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2.php">nt-netbios-guestaccess(2)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/19.php">nt-netbios-write(19)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/12.php">nt-netbios-share(12)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/20.php">nt-netbios-shareguest(20)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2000"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0520" published="1999-01-01" seq="1999-0520" severity="Medium" type="CVE"><desc><descript source="cve">A system-critical NETBIOS/SMB share has inappropriate access control.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0521" published="1997-01-01" seq="1999-0521" severity="High" type="CVE"><desc><descript source="cve">An NIS domain name is easily guessable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/85.php">nis-dom(85)</ref></refs></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0522" published="1996-05-28" seq="1999-0522" severity="High" type="CVE"><desc><descript source="cve">The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.10.nis+_configuration.html">NIS+ Configuration Vulnerability</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0523" published="1999-01-01" seq="1999-0523" severity="High" type="CVE"><desc><descript source="cve">ICMP echo (ping) is allowed from arbitrary hosts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2008-04-10" name="CVE-1999-0524" published="1997-08-01" seq="1999-0524" severity="Low" type="CVE"><desc><descript source="cve">ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.</descript></desc><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/306.php">icmp-netmask(306)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/322.php">icmp-timestamp(322)</ref><ref source="" url="http://descriptions.securescout.com/tc/11010"></ref><ref source="" url="http://descriptions.securescout.com/tc/11011"></ref><ref source="" url="http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&amp;externalId=1434"></ref><ref source="OSVDB" url="http://www.osvdb.org/95">95</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/306">icmp-netmask(306)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/322">icmp-timestamp(322)</ref></refs><vuln_soft><prod name="Linux" vendor="Linux"><vers num=""/></prod><prod name="OS2" vendor="IBM"><vers num=""/></prod><prod name="Tru64 UNIX" vendor="HP"><vers num=""/></prod><prod name="Cisco IOS" vendor="Cisco"><vers num=""/></prod><prod name="NetWare" vendor="Novell"><vers num=""/></prod><prod name="BSD" vendor="Wind River Systems"><vers num=""/></prod><prod name="Mac OS X" vendor="Apple"><vers num=""/></prod><prod name="Mac OS" vendor="Apple"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num=""/></prod><prod name="ALL Windows" vendor="Microsoft"><vers num="Abstract CPE"/></prod><prod name="AIX" vendor="IBM"><vers num=""/></prod><prod name="SCO Unix" vendor="Santa Cruz Operation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0525" published="1997-01-01" seq="1999-0525" severity="High" type="CVE"><desc><descript source="cve">IP traceroute is allowed from arbitrary hosts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/142.php">traceroute(142)</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0526" published="1997-07-01" seq="1999-0526" severity="High" type="CVE"><desc><descript source="cve">An X server&apos;s access control is disabled (e.g. through an &quot;xhost +&quot; command) and allows anyone to connect to the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/155.php">xcheck-keystroke(155)</ref><ref adv="1" source="Unix Workstation Support Group - Indiana University" url="http://www.uwsg.indiana.edu/usail/external/recommended/Xsecure.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/704969">VU#704969</ref></refs><vuln_soft><prod name="X11" vendor="X.Org"><vers num="7.1_1.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0527" published="1999-01-01" seq="1999-0527" severity="High" type="CVE"><desc><descript source="cve">The permissions for system-critical data in an anonymous FTP account are inappropriate.  For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as &quot;ls&quot; can be overwritten.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0528" published="1999-01-01" seq="1999-0528" severity="High" type="CVE"><desc><descript source="cve">A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0529" published="1999-01-01" seq="1999-0529" severity="High" type="CVE"><desc><descript source="cve">A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0530" published="1999-01-01" seq="1999-0530" severity="High" type="CVE"><desc><descript source="cve">A system is operating in &quot;promiscuous&quot; mode which allows it to perform packet sniffing.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0531" published="1999-01-01" reject="1" seq="1999-0531" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">This functionality should be disabled, because these commands can be used for attack reconnaissance.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2008-05-19" name="CVE-1999-0532" published="1997-07-01" seq="1999-0532" severity="Low" type="CVE"><desc><descript source="cve">A DNS server allows zone transfers.</descript></desc><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/212.php">dns-zonexfer(212)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0533" published="1997-07-01" seq="1999-0533" severity="High" type="CVE"><desc><descript source="cve">A DNS server allows inverse queries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/206.php">dns-iquery(206)</ref></refs></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0534" published="1997-01-01" seq="1999-0534" severity="Medium" type="CVE"><desc><descript source="cve">A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/235.php">nt-lock-memory(235)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/236.php">nt-increase-quota(236)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/237.php">nt-unsol-input(237)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0535" published="1997-01-01" seq="1999-0535" severity="High" type="CVE"><desc><descript source="cve">A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/97.php">nt-pwlen(97)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/220.php">nt-maxage(220)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/221.php">nt-minage(221)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0537" published="1998-04-01" seq="1999-0537" severity="High" type="CVE"><desc><descript source="cve">A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/365.php">nav-java-enabled(365)</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num=""/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0539" published="1999-01-01" seq="1999-0539" severity="High" type="CVE"><desc><descript source="cve">A trust relationship exists between two Unix hosts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0541" published="1997-07-01" seq="1999-0541" severity="High" type="CVE"><desc><descript source="cve">A password for accessing a WWW URL is guessable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/59.php">http-password(59)</ref></refs></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0546" published="1998-10-01" seq="1999-0546" severity="Medium" type="CVE"><desc><descript source="cve">The Windows NT guest account is enabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1326.php">nt-guest-account(1326)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0547" published="1999-01-01" seq="1999-0547" severity="High" type="CVE"><desc><descript source="cve">An SSH server allows authentication through the .rhosts file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0548" published="1999-01-01" seq="1999-0548" severity="High" type="CVE"><desc><descript source="cve">A superfluous NFS server is running, but it is not importing or exporting any file systems.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0549" published="1999-01-01" seq="1999-0549" severity="High" type="CVE"><desc><descript source="cve">Windows NT automatically logs in an administrator upon rebooting.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0550" published="1997-01-01" seq="1999-0550" severity="High" type="CVE"><desc><descript source="cve">A router&apos;s routing tables can be obtained from arbitrary hosts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/107.php">routed(107)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/103.php">rip(103)</ref></refs></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0551" published="1998-04-01" seq="1999-0551" severity="Medium" type="CVE"><desc><descript source="cve">HP OpenMail can be misconfigured to allow users to run arbitrary commands using malicious print requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/96">bugtraq id 96</ref><ref adv="1" patch="1" source="HEWLETT-PACKARD" url="http://securityfocus.com/templates/advisory.html?id=248">#00078</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/965.php">hp-openmail(965)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9804-078">HPSBUX9804-078</ref></refs><vuln_soft><prod name="OpenMail" vendor="HP"><vers num="5.10"/><vers num="5.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0554" published="1999-01-01" seq="1999-0554" severity="High" type="CVE"><desc><descript source="cve">NFS exports system-critical data to the world, e.g. / or a password file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0555" published="1999-01-01" seq="1999-0555" severity="High" type="CVE"><desc><descript source="cve">A Unix account with a name other than &quot;root&quot; has UID 0, i.e. root privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0556" published="1999-01-01" seq="1999-0556" severity="High" type="CVE"><desc><descript source="cve">Two or more Unix accounts have the same UID.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0559" published="1999-01-01" seq="1999-0559" severity="High" type="CVE"><desc><descript source="cve">A system-critical Unix file or directory has inappropriate permissions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0560" published="1999-01-01" seq="1999-0560" severity="High" type="CVE"><desc><descript source="cve">A system-critical Windows NT file or directory has inappropriate permissions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0561" published="1999-01-01" seq="1999-0561" severity="High" type="CVE"><desc><descript source="cve">IIS has the #exec function enabled for Server Side Include (SSI) files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0562" published="1997-01-01" seq="1999-0562" severity="High" type="CVE"><desc><descript source="cve">The registry in Windows NT can be accessed remotely by users who are not administrators.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/151.php">nt-winreg-all(151)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/152.php">nt-winreg-net(152)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1023.html">OVAL1023</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1023">oval:org.mitre.oval:def:1023</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0564" published="1999-01-01" seq="1999-0564" severity="High" type="CVE"><desc><descript source="cve">An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn&apos;t require a password) or to become disabled.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0565" published="1999-01-01" seq="1999-0565" severity="High" type="CVE"><desc><descript source="cve">A Sendmail alias allows input to be piped to a program.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0566" published="1997-08-01" seq="1999-0566" severity="Medium" type="CVE"><desc><descript source="cve">An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/493.php">ibm-syslogd(493)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0568" published="1999-01-01" seq="1999-0568" severity="High" type="CVE"><desc><descript source="cve">rpc.admind in Solaris is not running in a secure mode.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Solaris" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0569" published="1999-01-01" seq="1999-0569" severity="High" type="CVE"><desc><descript source="cve">A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0570" published="1999-01-01" seq="1999-0570" severity="High" type="CVE"><desc><descript source="cve">Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0571" published="1999-01-01" seq="1999-0571" severity="High" type="CVE"><desc><descript source="cve">A router&apos;s configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0572" published="1997-01-01" seq="1999-0572" severity="High" type="CVE"><desc><descript source="cve">.reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/178.php">nt-regfile(178)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0575" published="1997-01-01" seq="1999-0575" severity="High" type="CVE"><desc><descript source="cve">A Windows NT system&apos;s user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/226.php">nt-system-audit(226)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/228.php">nt-object-audit(228)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/229.php">nt-privil-audit(229)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/230.php">nt-process-audit(230)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/231.php">nt-policy-audit(231)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0576" published="1997-01-01" seq="1999-0576" severity="High" type="CVE"><desc><descript source="cve">A Windows NT system&apos;s file audit policy does not log an event success or failure for security-critical files or directories.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/228.php">nt-object-audit(228)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0577" published="1999-01-01" seq="1999-0577" severity="High" type="CVE"><desc><descript source="cve">A Windows NT system&apos;s file audit policy does not log an event success or failure for non-critical files or directories.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0578" published="1999-01-01" seq="1999-0578" severity="Medium" type="CVE"><desc><descript source="cve">A Windows NT system&apos;s registry audit policy does not log an event success or failure for security-critical registry keys.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0579" published="1999-01-01" seq="1999-0579" severity="High" type="CVE"><desc><descript source="cve">A Windows NT system&apos;s registry audit policy does not log an event success or failure for non-critical registry keys.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0580" published="1999-01-01" seq="1999-0580" severity="High" type="CVE"><desc><descript source="cve">The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0581" published="1999-01-01" seq="1999-0581" severity="High" type="CVE"><desc><descript source="cve">The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0582" published="1997-01-01" seq="1999-0582" severity="Medium" type="CVE"><desc><descript source="cve">A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/68.php">nt-thres-lockout(68)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0583" published="1999-01-01" seq="1999-0583" severity="High" type="CVE"><desc><descript source="cve">There is a one-way or two-way trust relationship between Windows NT domains.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0584" published="1999-01-01" seq="1999-0584" severity="High" type="CVE"><desc><descript source="cve">A Windows NT file system is not NTFS.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0585" published="2000-07-01" seq="1999-0585" severity="Low" type="CVE"><desc><descript source="cve">A Windows NT administrator account has the default name of Administrator.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/28.php">nt-adminexists(28)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/><vers num="3.5.1 SP5"/><vers num="3.5.1 SP3"/><vers num="3.5.1 SP2"/><vers num="3.5.1 SP1"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0586" published="1999-01-01" seq="1999-0586" severity="High" type="CVE"><desc><descript source="cve">A network service is running on a nonstandard port.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0587" published="1999-01-01" seq="1999-0587" severity="High" type="CVE"><desc><descript source="cve">A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0588" published="1999-01-01" seq="1999-0588" severity="High" type="CVE"><desc><descript source="cve">A filter in a router or firewall allows unusual fragmented packets.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0589" published="1999-01-01" seq="1999-0589" severity="High" type="CVE"><desc><descript source="cve">A system-critical Windows NT registry key has inappropriate permissions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0590" published="2000-06-01" seq="1999-0590" severity="High" type="CVE"><desc><descript source="cve">A system does not present an appropriate legal message or warning to a user who is accessing it.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-043.shtml">J-043g: Creating Login Banners</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/><vers num="3.5.1 SP5"/><vers num="3.5.1 SP3"/><vers num="3.5.1 SP2"/><vers num="3.5.1 SP1"/></prod><prod name="Mac OS" vendor="Apple"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0591" published="1999-01-01" seq="1999-0591" severity="High" type="CVE"><desc><descript source="cve">An event log in Windows NT has inappropriate access permissions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0592" published="1999-01-01" seq="1999-0592" severity="High" type="CVE"><desc><descript source="cve">The Logon box of a Windows NT system displays the name of the last user who logged in.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-03-14" name="CVE-1999-0593" published="1999-01-01" seq="1999-0593" severity="Low" type="CVE"><desc><descript source="cve">The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="" url="http://www.microsoft.com/technet/archive/winntas/deploy/confeat/06wntpcc.mspx?mfr=true"></ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0594" published="1999-01-01" seq="1999-0594" severity="High" type="CVE"><desc><descript source="cve">A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0595" published="2000-01-20" seq="1999-0595" severity="Low" type="CVE"><desc><descript source="cve">A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft Knowledge Base" url="http://support.microsoft.com/support/kb/articles/Q182/0/86.ASP?LN=EN-US&amp;SD=gn&amp;FR=0"></ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="3.5.1"/><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0596" published="1999-01-01" seq="1999-0596" severity="High" type="CVE"><desc><descript source="cve">A Windows NT log file has an inappropriate maximum size or retention period.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0597" published="1999-01-01" seq="1999-0597" severity="High" type="CVE"><desc><descript source="cve">A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0598" published="1999-01-01" seq="1999-0598" severity="High" type="CVE"><desc><descript source="cve">A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0599" published="1999-01-01" seq="1999-0599" severity="High" type="CVE"><desc><descript source="cve">A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0600" published="1999-01-01" seq="1999-0600" severity="High" type="CVE"><desc><descript source="cve">A network intrusion detection system (IDS) does not verify the checksum on a packet.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0601" published="1999-01-01" seq="1999-0601" severity="High" type="CVE"><desc><descript source="cve">A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0602" published="1999-01-01" seq="1999-0602" severity="High" type="CVE"><desc><descript source="cve">A network intrusion detection system (IDS) does not properly reassemble fragmented packets.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0603" published="1999-01-01" seq="1999-0603" severity="High" type="CVE"><desc><descript source="cve">In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0604" published="1999-04-20" seq="1999-0604" severity="Medium" type="CVE"><desc><descript source="cve">An incorrect configuration of the WebStore 1.0 shopping cart CGI program &quot;web_store.cgi&quot; could disclose private information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.96.990420132956.13470B-100000@gonzo.blarg.net">Shopping Carts exposing CC data</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref></refs><vuln_soft><prod name="Selena Sol WebStore" vendor="Selena Sol"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0605" published="1999-04-01" seq="1999-0605" severity="Medium" type="CVE"><desc><descript source="cve">An incorrect configuration of the Order Form 1.0 shopping cart  CGI program could disclose private information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.96.990420132956.13470B-100000@gonzo.blarg.net">Shopping Carts exposing CC data</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref></refs><vuln_soft><prod name="Merchant Order Form" vendor="Austin Contract Computing"><vers num="1.0"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0606" published="1999-04-01" seq="1999-0606" severity="Medium" type="CVE"><desc><descript source="cve">An incorrect configuration of the EZMall 2000 shopping cart  CGI program &quot;mall2000.cgi&quot; could disclose private information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.96.990420132956.13470B-100000@gonzo.blarg.net">Shopping Carts exposing CC data</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref></refs><vuln_soft><prod name="EZMall" vendor="Seaside Enterprises"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-1999-0607" published="1999-04-20" seq="1999-0607" severity="Medium" type="CVE"><desc><descript source="cve">quikstore.cgi in QuikStore shopping cart stores quikstore.cfg under the web document root with insufficient access control, which allows remote attackers to obtain the cleartext administrator password and gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.96.990420132956.13470B-100000@gonzo.blarg.net">Shopping Carts exposing CC data</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref></refs><vuln_soft><prod name="QuikStore" vendor="I-Soft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0608" published="1999-04-01" seq="1999-0608" severity="Medium" type="CVE"><desc><descript source="cve">An incorrect configuration of the PDG Shopping Cart CGI program &quot;shopper.cgi&quot; could disclose private information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.96.990420132956.13470B-100000@gonzo.blarg.net">Shopping Carts exposing CC data</ref><ref source="CONFIRM" url="http://www.pdgsoft.com/Security/security.html.">http://www.pdgsoft.com/Security/security.html.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3857">pdgsoftcart-misconfig(3857)</ref></refs><vuln_soft><prod name="PDG Shopping Cart" vendor="PDGSoft"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0609" published="1999-04-01" seq="1999-0609" severity="Medium" type="CVE"><desc><descript source="cve">An incorrect configuration of the SoftCart CGI program &quot;SoftCart.exe&quot; could disclose private information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.96.990420132956.13470B-100000@gonzo.blarg.net">Shopping Carts exposing CC data</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref></refs><vuln_soft><prod name="SoftCart" vendor="Mercantec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0610" published="1999-04-01" seq="1999-0610" severity="Medium" type="CVE"><desc><descript source="cve">An incorrect configuration of the Webcart CGI program could disclose private information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.96.990420132956.13470B-100000@gonzo.blarg.net">Shopping Carts exposing CC data</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92462991805485&amp;w=2">19990420 Shopping Carts exposing CC data</ref></refs><vuln_soft><prod name="Webcart" vendor="Mountain Network Systems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0611" published="1999-01-01" seq="1999-0611" severity="High" type="CVE"><desc><descript source="cve">A system-critical Windows NT registry key has an inappropriate value.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0612" published="1997-03-01" seq="1999-0612" severity="Low" type="CVE"><desc><descript source="cve">A version of finger is running that exposes valid user information to any entity on the network.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The FTP Service should be disabled because it could reveal information about a host&apos;s users, which could be used as reconnaissance information for attacks. </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/46.php">finger-running(46)</ref></refs><vuln_soft><prod name="fingerd" vendor="GNU"><vers num=""/></prod><prod name="Finger Service" vendor="GNU"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0613" published="1999-01-01" seq="1999-0613" severity="Low" type="CVE"><desc><descript source="cve">The rpc.sprayd service is running.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">rpc.sprayd is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.  </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0614" published="1999-01-01" reject="1" seq="1999-0614" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The FTP service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The FTP Service is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  Secure alternatives that encrypt communications are available.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0615" published="1999-01-01" reject="1" seq="1999-0615" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The SNMP service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">SNMPv3 is a secure protocol for management of networked systems, provided the cryptographic security mechanisms are used.  SNMPv1 and SNMPv2 are unsecured protocols for Internet facing systems and should  only be used on a trusted network segment.  For all versions, the software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0616" published="1999-01-01" reject="1" seq="1999-0616" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The TFTP service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The TFTP Service is an unsecured protocol and it should used only on a limited basis on rare occasion to provide a specific functional requirement, otherwise disabled.  Secure alternatives are available. </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0617" published="1999-01-01" reject="1" seq="1999-0617" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The SMTP service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The SMTP Service is an unsecured protocol for Internet facing systems (e.g., user authentication not required, communications not encrypted) and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0618" published="1999-01-01" seq="1999-0618" severity="High" type="CVE"><desc><descript source="cve">The rexec service is running.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0619" published="1999-01-01" reject="1" seq="1999-0619" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The Telnet service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The Telnet Service is an unsecured and obsolete protocol and it should be disabled.  Secure alternatives such as SSH are available.  </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0620" published="1999-01-01" reject="1" seq="1999-0620" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A component service related to NIS is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">These protocols, such as RPC ypbind, yppasswd, ypserv, ypupdated, and ypxfrd, are unsecured protocols for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0621" published="1999-01-01" reject="1" seq="1999-0621" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A component service related to NETBIOS is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">This component service should not be allowed to communicate over untrusted networks, such as the Internet, because it is an unsecured protocol (e.g., communications not encrypted).   The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1024">oval:org.mitre.oval:def:1024</ref></refs></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0622" published="1999-01-01" reject="1" seq="1999-0622" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A component service related to DNS service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">DNS is a critical network service.  It should be fully patched and properly configured for Internet facing servers to avoid common attacks such as DNS spoofing, poisoning, and unauthorized zone transfers.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0623" published="1999-01-01" reject="1" seq="1999-0623" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The X Windows service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The XWindows service is an unsecured protocol for Internet facing system and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0624" published="1999-01-01" seq="1999-0624" severity="Low" type="CVE"><desc><descript source="cve">The rstat/rstatd service is running.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">These are unsecured and obsolete protocols and they should be disabled.  </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0625" published="1999-01-01" seq="1999-0625" severity="Low" type="CVE"><desc><descript source="cve">The rpc.rquotad service is running.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">rpc.rquotad is an unsecured and obsolete protocol and it should be disabled.  </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0626" published="1997-01-01" seq="1999-0626" severity="Low" type="CVE"><desc><descript source="cve">A version of rusers is running that exposes valid user information to any entity on the network.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">rusers is an unsecured and obsolete protocol and it should be disabled. </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/183.php">ruser(183)</ref></refs><vuln_soft><prod name="ruserd" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0627" published="1992-03-01" seq="1999-0627" severity="Low" type="CVE"><desc><descript source="cve">The rexd service is running, which uses weak authentication that can allow an attacker to execute commands.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The rexd service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/37">bugtraq id 37</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-92.05.AIX.REXD.Daemon.vulnerability.html">CA-92.05</ref><ref patch="1" source="IBM" url="http://service.software.ibm.com/rs6k/fixes.html"></ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0628" published="1997-07-01" seq="1999-0628" severity="Medium" type="CVE"><desc><descript source="cve">The rwho/rwhod service is running, which exposes machine status and user information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/118.php">rwhod-vuln(118)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9608D&amp;L=bugtraq&amp;P=R472"></ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0629" published="1999-01-01" seq="1999-0629" severity="High" type="CVE"><desc><descript source="cve">The ident/identd service is running.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0630" published="1999-01-01" seq="1999-0630" severity="High" type="CVE"><desc><descript source="cve">The NT Alerter and Messenger services are running.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0631" published="1999-01-01" reject="1" seq="1999-0631" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The NFS service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">NFS Service is an unsecured protocol for Internet facing systems (e.g., user authentication not required, communications not encrypted) and should only be used on a trusted managed network, otherwise disabled.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0632" published="1999-01-01" seq="1999-0632" severity="Low" type="CVE"><desc><descript source="cve">The RPC portmapper service is running.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The RPC portmapper service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly. </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0633" published="1999-01-01" reject="1" seq="1999-0633" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The HTTP/WWW service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The software should be patched and configured properly.  SSL/TLS should be used to protect transmissions of sensitive data.  The presence of HTTP may be an indication that an web application server is running on the system.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0634" published="1999-01-01" reject="1" seq="1999-0634" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The SSH service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">SSH is a secure protocol, provided it is fully patched, properly configured, and uses FIPS approved algorithms.  SSH version 2 is preferred over SSH version 1 because of known flaws in version 1.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0635" published="1999-01-01" seq="1999-0635" severity="Low" type="CVE"><desc><descript source="cve">The echo service is running.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The Echo Service is an unsecured and obsolete protocol and it should be disabled.  Historically it has been used to perform denial of service attacks.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="FULLDISC" url="http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041434.html">20060116 ACT P202S VoIP wireless phone multiple undocumented ports/services</ref><ref adv="1" source="SECUNIA" url="http://secunia.com/advisories/18514">18514</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0636" published="1999-01-01" seq="1999-0636" severity="High" type="CVE"><desc><descript source="cve">The discard service is running.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0637" published="1999-01-01" seq="1999-0637" severity="Low" type="CVE"><desc><descript source="cve">The systat service is running.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The systat service is an unsecured and obsolete protocol and it should be disabled because it can reveal information about a host&apos;s operations.  </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0638" published="1999-01-01" seq="1999-0638" severity="Low" type="CVE"><desc><descript source="cve">The daytime service is running.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The daytime service is an unsecured and obsolete protocol and it should be disabled.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0639" published="1999-01-01" seq="1999-0639" severity="Low" type="CVE"><desc><descript source="cve">The chargen service is running.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">chargen service is an unsecured and obsolete protocol and it should be disabled.  Historically it has been used to perform denial of service attacks.  Ping and traceroute can be used to provide the same functionality.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0640" published="1999-01-01" seq="1999-0640" severity="High" type="CVE"><desc><descript source="cve">The Gopher service is running.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0641" published="1999-01-01" seq="1999-0641" severity="Low" type="CVE"><desc><descript source="cve">The UUCP service is running.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The UUCP Service is an unsecured and obsolete protocol and it should be disabled.  </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0642" published="1999-01-01" reject="1" seq="1999-0642" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A POP service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">POP3 is an unsecured protocol for Internet facing systems that does not encrypt its transmissions.  POP3 should be tunneled over SSL/TLS or another encrypted tunnel.  The software should be patched and configured properly.  Earlier versions of POP, such as POP2, are unsecured and obsolete, and should be disabled.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0643" published="1999-01-01" reject="1" seq="1999-0643" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The IMAP service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">IMAP Service is an unsecured protocol for Internet facing systems that does not encrypt its transmissions.  IMAP should be tunneled over SSL/TLS or another encrypted tunnel.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0644" published="1999-01-01" reject="1" seq="1999-0644" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The NNTP news service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">NNTP news service is an unsecured protocol for Internet facing systems (e.g., user authentication not required, communications not encrypted).  It could be tunneled over SSL/TLS.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0645" published="1999-01-01" reject="1" seq="1999-0645" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The IRC service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">IRC Service is an unsecured protocol that typically does not authenticate the identity of users and does not encrypt its network communications.  IRC is not commonly deployed on enterprise networks.  If an organization decides to use it, it should be patched and configured properly, otherwise it should be disabled.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0646" published="1999-01-01" reject="1" seq="1999-0646" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The LDAP service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The software should be patched and configured properly to prevent information disclosure.  It can be tunneled over SSL/TLS.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0647" published="1999-01-01" reject="1" seq="1999-0647" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The bootparam (bootparamd) service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The bootparam service is an unsecured protocol for Internet facing systems and should only be used on a trusted network segment, otherwise disabled.  The software should be patched and configured properly.  </sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0648" published="1999-01-01" reject="1" seq="1999-0648" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The X25 service is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">X25 is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0 incomplete approximation" modified="2008-08-01" name="CVE-1999-0649" published="1999-01-01" reject="1" seq="1999-0649" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;The FSP service is running.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-1999-0650" published="1999-01-01" seq="1999-0650" severity="Medium" type="CVE"><desc><descript source="cve">The netstat service is running, which provides sensitive information to remote attackers.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0651" published="1999-01-01" seq="1999-0651" severity="High" type="CVE"><desc><descript source="cve">The rsh/rlogin service is running.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0652" published="1999-01-01" reject="1" seq="1999-0652" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A database service is running, e.g. a SQL server, Oracle, or mySQL.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">The software should be patched and configured properly to prevent information leakage and unauthorized access.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0653" published="1999-01-01" seq="1999-0653" severity="High" type="CVE"><desc><descript source="cve">A component service related to NIS+ is running.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0654" published="1999-01-01" seq="1999-0654" severity="High" type="CVE"><desc><descript source="cve">The OS/2 or POSIX subsystem in NT is enabled.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0655" published="1999-01-01" reject="1" seq="1999-0655" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE.  Notes: the former description is: &quot;A service may include useful information in its banner or help function (such as the name and version), making it useful for information gathering activities.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0656" published="1999-01-01" seq="1999-0656" severity="Medium" type="CVE"><desc><descript source="cve">The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref source="" url="http://ca.com/au/securityadvisor/vulninfo/Vuln.aspx?ID=1638"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/348">linux-ugidd(348)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-21" name="CVE-1999-0657" published="1999-01-01" seq="1999-0657" severity="Low" type="CVE"><desc><descript source="cve">WinGate is being used.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0658" published="1999-01-01" reject="1" seq="1999-0658" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;DCOM is running.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0659" published="1999-01-01" reject="1" seq="1999-0659" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A Windows NT Primary Domain Controller (PDC) or Backup Domain Controller (BDC) is present.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="0.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_version="2.0" modified="2008-08-01" name="CVE-1999-0660" published="1999-01-01" reject="1" seq="1999-0660" severity="Low" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: None.  Reason: this candidate is not about any specific product, protocol, or design, so it is out of scope of CVE.  It might be more appropriate to cover under the Common Configuration Enumeration (CCE).  Notes: the former description is: &quot;A hacker utility, back door, or Trojan Horse is installed on a system, e.g. NetBus, Back Orifice, Rootkit, etc.&quot;</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0661" published="1999-01-01" seq="1999-0661" severity="High" type="CVE"><desc><descript source="cve">A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="CERT" url="http://www.cert.org/advisories/CA-1994-07.html">CA-1994-07</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1994-14.html">CA-1994-14</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1999-01.html">CA-1999-01</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1999-02.html">CA-1999-02</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2002-28.html">CA-2002-28</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/294539">20021009 Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail</ref><ref source="BID" url="http://www.securityfocus.com/bid/5921">5921</ref><ref source="XF" url="http://www.iss.net/security_center/static/10313.php">sendmail-backdoor(10313)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102820843403741&amp;w=2">20020801 trojan horse in recent openssh (version 3.4 portable 1)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=102821663814127&amp;w=2">20020801 OpenSSH Security Advisory:  Trojaned Distribution Files</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0662" published="1999-01-01" seq="1999-0662" severity="High" type="CVE"><desc><descript source="cve">A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0663" published="1999-01-01" seq="1999-0663" severity="High" type="CVE"><desc><descript source="cve">A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0664" published="1999-01-01" seq="1999-0664" severity="High" type="CVE"><desc><descript source="cve">An application-critical Windows NT registry key has inappropriate permissions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0665" published="1999-01-01" seq="1999-0665" severity="High" type="CVE"><desc><descript source="cve">An application-critical Windows NT registry key has an inappropriate value.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0667" published="1997-09-19" seq="1999-0667" severity="High" type="CVE"><desc><descript source="cve">The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="ARP protocol" vendor="ARP protocol"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0668" published="1999-08-21" seq="1999-0668" severity="Medium" type="CVE"><desc><descript source="cve">The scriptlet.typelib ActiveX control is marked as &quot;safe for scripting&quot; for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3244.php">ms-scriptlet-eyedog-unsafe(3244)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/598">BID 598</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-032.asp">MS99-032</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref><ref source="BID" url="http://www.securityfocus.com/bid/598">598</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q240308">Q240308</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0669" published="1999-09-01" seq="1999-0669" severity="Medium" type="CVE"><desc><descript source="cve">The Eyedog ActiveX control is marked as &quot;safe for scripting&quot; for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q240/3/08.asp">Update Available for Scriptlet.Typelib and Eyedog Security Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3244.php">ms-scriptlet-eyedog-unsafe(3244)</ref><ref adv="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0670" published="1999-09-01" seq="1999-0670" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q240/3/08.asp">Update Available for Scriptlet.Typelib and Eyedog Security Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/static/3244.php">ms-scriptlet-eyedog-unsafe(3244)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-032.asp">MS99-032</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-064.shtml">J-064</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0671" published="1999-08-03" seq="1999-0671" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in ToxSoft NextFTP client through CWD command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D572">ToxSoft NextFTP Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4286.php">toxsoft-nextftp-cwd-bo(4286)</ref><ref source="BID" url="http://www.securityfocus.com/bid/572">572</ref></refs><vuln_soft><prod name="NextFTP" vendor="ToxSoft"><vers num="1.82"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0672" published="1999-08-01" seq="1999-0672" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4287.php">fujitsu-topic-bo(4287)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D573">Fujitsu Chocoa &quot;Topic&quot; Buffer Overflow Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/573">573</ref></refs><vuln_soft><prod name="Chocoa" vendor="Fujitsu"><vers num="1.0beta7R"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0673" published="1999-08-08" seq="1999-0673" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in ALMail32 POP3 client via From: or To: headers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=574">CREAR ALMail32 Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3541.php">almail-bo(3541)</ref><ref source="BID" url="http://www.securityfocus.com/bid/574">574</ref></refs><vuln_soft><prod name="ALMail32" vendor="CREAR"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0674" published="1999-08-09" seq="1999-0674" severity="High" type="CVE"><desc><descript source="cve">The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/570">BID 570</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/advisory.html?id=1673">1999-011</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=199908101928.MAA27587@elbe.ghs.com"></ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-067.shtml">J-067</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-1999-0675" published="1999-08-09" seq="1999-0675" severity="Medium" type="CVE"><desc><descript source="cve">Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D576">Firewall-1 Port 0 Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3233.php">checkpoint-port(3233)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/23615">19990809 FW1 UDP Port 0 DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/576">576</ref><ref source="OSVDB" url="http://www.osvdb.org/1038">1038</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="3.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0676" published="1999-08-09" seq="1999-0676" severity="Medium" type="CVE"><desc><descript source="cve">sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/575">bugtraq id 575</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=19990809134220.A1191@hades.chaoz.org"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3116.php">sun-sdtcm-convert(3116)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19990809134220.A1191@hades.chaoz.org">19990808 sdtcm_convert</ref><ref source="BID" url="http://www.securityfocus.com/bid/575">575</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0677" published="1999-08-03" seq="1999-0677" severity="High" type="CVE"><desc><descript source="cve">The WebRamp web administration utility has a default password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=577">WebRamp Default Adminstrative Login Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3830.php">webramp-default-password(3830)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-07-28%26msg%3DPine.SUN.3.96.990803112821.17628B-100000@grex.cyberspace.org">Password hunting with webramp</ref><ref source="BID" url="http://www.securityfocus.com/bid/577">577</ref></refs><vuln_soft><prod name="WebRamp M3" vendor="Ramp Networks"><vers num="1.0"/></prod><prod name="WebRamp 200i" vendor="Ramp Networks"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0678" published="1999-01-17" seq="1999-0678" severity="Medium" type="CVE"><desc><descript source="cve">A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2084.php">apache-debian-usrdoc(2084)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904a&amp;L=bugtraq&amp;F=&amp;S=&amp;P=2822"></ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/318">bugtraq id 318</ref><ref source="BID" url="http://www.securityfocus.com/bid/318">318</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="4.0"/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0679" published="1999-08-13" seq="1999-0679" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=581">Ircd hybrid-6 Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4320.php">hybrid-ircd-minvite-bo(4320)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-08-8%26msg%3DPine.LNX.3.95.990813105919.12840A-101000@cannabis.dataforce.net">w00w00&apos;s efnet ircd advisory</ref><ref source="CONFIRM" url="http://www.efnet.org/archive/servers/hybrid/ChangeLog">http://www.efnet.org/archive/servers/hybrid/ChangeLog</ref><ref source="BID" url="http://www.securityfocus.com/bid/581">581</ref></refs><vuln_soft><prod name="Hybrid Ircd" vendor="Hybrid Network"><vers num="6.0Beta58" prev="1"/><vers num="5.03p7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0680" published="1999-08-09" seq="1999-0680" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/571">BID 571</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3104.php">nt-terminal-dos(3104)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/fq99-028.asp">MS99-028</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-028.asp">MS99-028</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-028.mspx">MS99-028</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238600">Q238600</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-057.shtml">J-057</ref></refs><vuln_soft><prod name="Terminal Server" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0681" published="2001-03-12" seq="1999-0681" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote attackers to cause a denial of service via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/568">bid 568</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3117.php">frontpage-pws-dos(3117)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/1999-q3/0381.html">BUGTRAQ:19990807 Crash FrontPage Remotely</ref></refs><vuln_soft><prod name="Personal Web Server" vendor="Microsoft"><vers num="1.0"/><vers num="1.1"/></prod><prod name="FrontPage" vendor="Microsoft"><vers num="98"/><vers num="97"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-1999-0682" published="1999-08-06" seq="1999-0682" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/567">BID 567</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-027.asp">MS99-027</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-027.asp">MS99-027</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3107.php">exchange-relay(3107)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-027.mspx">MS99-027</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q237927">Q237927</ref><ref source="BID" url="http://www.securityfocus.com/bid/567">567</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-056.shtml">J-056</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5 SP2"/><vers num="5.5 SP1"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0683" published="1999-07-30" seq="1999-0683" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Gauntlet Firewall via a malformed ICMP packet.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/556">bugtraq id 556</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3108.php">gauntlet-dos(3108)</ref><ref source="OSVDB" url="http://www.osvdb.org/1029">1029</ref></refs><vuln_soft><prod name="Gauntlet Firewall" vendor="Network Associates"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0684" published="1999-04-19" seq="1999-0684" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Sendmail 8.8.6 in HPUX.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3826.php">hp-sendmail-connect-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/advisory.html%3Fid%3D1463">Security Vulnerability in sendmail</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-040.shtml">HP-UX Security Vulnerability in sendmail</ref></refs><vuln_soft><prod name="sendmail" vendor="HP"><vers num="8.8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0685" published="1999-09-02" seq="1999-0685" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/618">bugtraq id 618</ref><ref source="BID" url="http://www.securityfocus.com/bid/618">618</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.61"/><vers num="4.6"/><vers num="4.51"/><vers num="4.5"/><vers num="4.06"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0686" published="1999-05-07" seq="1999-0686" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2194.php">hp-tgad-dos(2194)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-098">HPSBUX9906-098</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-046.shtml">J-046</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num="10.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0687" published="1999-09-13" seq="1999-0687" severity="High" type="CVE"><desc><descript source="cve">The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/641">bugtraq id 641</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3693.php">cde-ttsession-rpc-auth(3693)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-11-CDE.html">CA-99-11-CDE</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-001.shtml">K-001</ref><ref source="BID" url="http://www.securityfocus.com/bid/637">637</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0f"/><vers num="4.0D"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="CDE" vendor="CDE"><vers num="2.120"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0688" published="1999-07-01" seq="1999-0688" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3125.php">hp-sd-bo(3125)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-101">HPSBUX9907-101</ref><ref source="BID" url="http://www.securityfocus.com/bid/545">545</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.24"/><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0689" published="1999-09-13" seq="1999-0689" severity="High" type="CVE"><desc><descript source="cve">The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-11-CDE.html">CA-99-11-CDE</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3699.php">cde-dtspcd-file-auth(3699)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/636">BID 636</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1880">oval:org.mitre.oval:def:1880</ref><ref source="BID" url="http://www.securityfocus.com/bid/636">636</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/></prod><prod name="CDE" vendor="CDE"><vers num="2.120"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0690" published="1999-07-01" seq="1999-0690" severity="High" type="CVE"><desc><descript source="cve">HP CDE program includes the current directory in root&apos;s PATH variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-053.shtml">HP Current Directory Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2342.php">hp-cde-directory(2342)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9907-100">HPSBUX9907-100</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10"/></prod><prod name="CDE" vendor="CDE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0691" published="1999-09-13" seq="1999-0691" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-11-CDE.html">CA-99-11-CDE</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3241.php">cde-dtaction-username-bo(3241)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/635">BID 635</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref><ref source="BID" url="http://www.securityfocus.com/bid/635">635</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3078">oval:org.mitre.oval:def:3078</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0f"/><vers num="4.0e"/><vers num="4.0D"/></prod><prod name="CDE" vendor="CDE"><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-1999-0692" published="1999-07-19" seq="1999-0692" severity="High" type="CVE"><desc><descript source="cve">The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-09-arrayd.html">CA-99-09-arrayd</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2367.php">sgi-arrayd(2367)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-052.shtml">J-052</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990701-01-P">19990701-01-P</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/><vers num="6.5.4"/></prod><prod name="UNICOS" vendor="Cray"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0693" published="2000-03-02" seq="1999-0693" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-11-CDE.html">CA-99-11-CDE</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3242.php">cde-dtsession-env-bo(3242)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/641">bugtraq id 641</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/192">00192</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9909-103">HPSBUX9909-103</ref><ref source="BID" url="http://www.securityfocus.com/bid/641">641</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4374">oval:org.mitre.oval:def:4374</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4"/></prod><prod name="Unixware" vendor="SCO"><vers num="7"/></prod><prod name="HP-UX" vendor="HP"><vers num="10"/><vers num="11"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0694" published="1999-08-11" seq="1999-0694" severity="Low" type="CVE"><desc><descript source="cve">Denial of service in AIX ptrace system call allows local users to crash the system.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3134.php">aix-ptrace-halt(3134)</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-055.shtml"></ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0695" published="2000-04-11" seq="1999-0695" severity="Medium" type="CVE"><desc><descript source="cve">The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/620">bugtraq id 620</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3169.php">http-powerdynamo-dotdotslash</ref><ref source="BID" url="http://www.securityfocus.com/bid/620">620</ref><ref source="OSVDB" url="http://www.osvdb.org/1064">1064</ref></refs><vuln_soft><prod name="PowerDynamo" vendor="Sybase"><vers num="3.0.652"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0696" published="1999-07-01" seq="1999-0696" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2345.php">sun-cmsd-bo(2345)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-08-cmsd.html">CA-99-08-cmsd</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/188">00188</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9908-102">HPSBUX9908-102</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-051.shtml">J-051</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.6"/><vers edition="x86" num="2.5"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.24"/><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0697" published="1999-09-09" seq="1999-0697" severity="High" type="CVE"><desc><descript source="cve">SCO Doctor allows local users to gain root privileges through a Tools option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3230.php">sco-doctor-execute</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D009501befa15%24915fe270%243177a8c0@webley">SCO 5.0.5 /bin/doctor nightmare</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D621">SCO OpenServer Doctor Command Execution Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/621">621</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.5"/><vers num="5.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0698" published="1999-01-01" seq="1999-0698" severity="High" type="CVE"><desc><descript source="cve">Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0699" published="2000-04-11" seq="1999-0699" severity="High" type="CVE"><desc><descript source="cve">The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/623">BID 623</ref><ref source="BID" url="http://www.securityfocus.com/bid/623">623</ref></refs><vuln_soft><prod name="Sapphire_Web" vendor="Bluestone"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0700" published="1999-07-29" seq="1999-0700" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3109.php">nt-malformed-dialer(3109)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-026.asp">MS99-026</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q237185">Q237185</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-026.mspx">MS99-026</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0"/><vers num="4.0 SP2"/><vers num="4.0 SP4"/><vers num="4.0 SP1"/><vers num="4.0 SP3"/><vers num="Terminal Server 4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0701" published="2000-04-11" seq="1999-0701" severity="High" type="CVE"><desc><descript source="cve">After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/626">bugtraq id 626</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3226.php">nt-install-unattend-file(3226)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-036.asp">MS99-036</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/fq99-036.asp">MS99-036</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-036.mspx">MS99-036</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q173039">Q173039</ref><ref source="BID" url="http://www.securityfocus.com/bid/626">626</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0702" published="1999-09-10" seq="1999-0702" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the &quot;ImportExportFavorites&quot; vulnerability.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/627">bugtraq id 627</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3229.php">ie5-import-export-favorites(3229)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-037.asp">MS99-037</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-037.asp">MS99-037</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-037.mspx">MS99-037</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241361">Q241361</ref><ref source="BID" url="http://www.securityfocus.com/bid/627">627</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="4.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0703" published="1999-08-03" seq="1999-0703" severity="Low" type="CVE"><desc><descript source="cve">OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3344.php">openbsd-chflags-fchflags-permitted(3344)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-07-28&amp;msg=Pine.BSF.3.96.990804111716.22740A-100000@peabody"></ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-066.shtml">J-066</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.2"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.5"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0704" published="1999-09-16" seq="1999-0704" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3171.php">amd-bo(3171)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/614">bugtraq id 614</ref><ref source="BID" url="http://www.securityfocus.com/bid/614">614</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/><vers edition="i386" num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="4.0.1"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0705" published="1999-09-01" seq="1999-0705" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in INN inews program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA1999033_01.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3170.php">inn-inews-bo(3170)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/616">BID 616</ref><ref source="BID" url="http://www.securityfocus.com/bid/616">616</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0706" published="2000-04-27" seq="1999-0706" severity="High" type="CVE"><desc><descript source="cve">Linux xmonisdn package allows local users to gain root privileges by modifying the IFS or PATH environmental variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/616">BID 616</ref><ref source="BID" url="http://www.securityfocus.com/bid/583">583</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.7.2"/><vers num="1.7"/><vers num="1.5.1"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/><vers edition="i386" num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0707" published="1999-07-01" seq="1999-0707" severity="High" type="CVE"><desc><descript source="cve">The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-050.shtml">HP-UX Visualize Conference Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2309.php">hp-visualize-conference-ftp(2309)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9906-099">HPSBUX9906-099</ref><ref source="BID" url="http://www.securityfocus.com/bid/493">493</ref></refs><vuln_soft><prod name="Visualize Conference ftp" vendor="HP"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0708" published="1999-09-21" seq="1999-0708" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-09-15&amp;msg=XFMail.990921161223.secure@FreeBSD.lublin.pl"></ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/651">bugtraq id 651</ref><ref source="BID" url="http://www.securityfocus.com/bid/651">651</ref></refs><vuln_soft><prod name="cfingerd" vendor="Infodrom"><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0710" published="1999-07-25" seq="1999-0710" severity="High" type="CVE"><desc><descript source="cve">The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-07-22&amp;msg=01BED706.2BA71B60.kerb@fnusa.com"></ref><ref source="" url="http://www.redhat.com/support/errata/archives/rh52-errata-general.html#squid"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2004/dsa-576">DSA-576</ref><ref source="FEDORA" url="http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html">FEDORA-2005-373</ref><ref source="FEDORA" url="http://fedoranews.org/updates/FEDORA--.shtml">FLSA-2006:152809</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-025.html">RHSA-1999:025</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-489.html">RHSA-2005:489</ref><ref source="BID" url="http://www.securityfocus.com/bid/2059">2059</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2385">http-cgi-cachemgr(2385)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0711" published="1999-04-29" seq="1999-0711" severity="Medium" type="CVE"><desc><descript source="cve">The oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/159">BID 159</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2177.php">oracle-oratclsh(2177)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?t=92550157100002&amp;w=2&amp;r=1">19990430 *Huge* security hole in Oracle 8.0.5 with Intellegent agent installed</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92609807906778&amp;w=2">19990506 Oracle Security Followup, patch and FAQ: setuid on oratclsh</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.0.5.1"/><vers num="8.0.5"/><vers num="8.0.4"/><vers num="8.0.3"/><vers num="8.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0712" published="1999-04-27" seq="1999-0712" severity="Low" type="CVE"><desc><descript source="cve">A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-1999-009.0.txt">CSSA-1999:009.0</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-10.phplinux-coas">linux-coas</ref></refs><vuln_soft><prod name="OpenLinux" vendor="Caldera"><vers num="2.2"/></prod><prod name="COAS" vendor="Caldera"><vers num="1.0.7"/><vers num="1.0.6"/><vers num="1.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0713" published="1999-06-11" seq="1999-0713" severity="High" type="CVE"><desc><descript source="cve">The dtlogin program in Compaq Tru64 UNIX allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2191.php">cde-dtlogin(2191)</ref><ref adv="1" patch="1" source="Compaq" url="http://www1.support.compaq.com/patches/security-updates/ssrt0600u.html"></ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-044.shtml">J-044</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="5.0"/></prod><prod name="AFS" vendor="Transarc"><vers num=""/></prod><prod name="UNIX" vendor="Digital"><vers num=""/></prod><prod name="CDE" vendor="CDE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0714" published="1999-02-15" seq="1999-0714" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in Compaq Tru64 UNIX edauth command.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2198.php">du-edauth(2198)</ref><ref adv="1" source="Compaq" url="http://www1.support.compaq.com/patches/security-updates/ssrt0588u.html"></ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num="3.2G"/><vers num="4.0"/><vers num="4.0A"/><vers num="4.0B"/><vers num="4.0C"/><vers num="4.0D"/><vers num="4.0e"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0715" published="1999-05-20" seq="1999-0715" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2200.php">nt-ras-bo(2200)</ref><ref adv="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-016.asp">MS99-016</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-016.mspx">MS99-016</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q230677">Q230677</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0716" published="1999-05-17" seq="1999-0716" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2190.php">nt-helpfile-bo(2190)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-015.asp">MS99-015</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231605">Q231605</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0717" published="1999-05-07" seq="1999-0717" severity="Low" type="CVE"><desc><descript source="cve">A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2186.php">excel-virus-warning(2186)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-014.asp">MS99-014</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-014.mspx">MS99-014</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231304">Q231304</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod><prod name="Excel" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-1999-0718" published="2001-03-12" seq="1999-0718" severity="Medium" type="CVE"><desc><descript source="cve">IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/608">bid 608</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3166.php">ibm-gina-group-add(3166)</ref><ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9908&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5534">19990823 IBM Gina security warning</ref></refs><vuln_soft><prod name="GINA" vendor="IBM"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0719" published="1999-08-05" seq="1999-0719" severity="Medium" type="CVE"><desc><descript source="cve">The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4288.php">gnu-guile-plugin-export(4288)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/563">bugtraq id 563</ref><ref source="BID" url="http://www.securityfocus.com/bid/563">563</ref></refs><vuln_soft><prod name="GNUmeric" vendor="Gnu"><vers num="0.27"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0720" published="1999-08-23" seq="1999-0720" severity="Medium" type="CVE"><desc><descript source="cve">The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/597">bugtraq id 597</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3167.php">linux-pt-chown(3167)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=lcamtuf.4.05.9907041223290.355-300000@nimue.ids.pl">19990823 [Linux] glibc 2.1.x / wu-ftpd &lt;=2.5 / BeroFTPD / lynx / vlock / mc / glibc 2.0.x</ref><ref source="BID" url="http://www.securityfocus.com/bid/597">597</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0721" published="1999-07-20" seq="1999-0721" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2291.php">msrpc-lsa-lookupnames-dos(2291)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-020.asp">MS99-020</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231457">Q231457</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-020.mspx">MS99-020</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0 SP4"/><vers num="4.0 SP5"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0722" published="1999-08-08" seq="1999-0722" severity="High" type="CVE"><desc><descript source="cve">The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-10-cobalt-raq2.html">CA-99-10-cobalt-raq2</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3132.php">cobalt-raq2-default-config(3132)</ref><ref source="BID" url="http://www.securityfocus.com/bid/558">558</ref></refs><vuln_soft><prod name="Cobalt RaQ" vendor="Sun"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0723" published="1999-06-23" seq="1999-0723" severity="Medium" type="CVE"><desc><descript source="cve">The Windows NT Client Server Runtime Subsystem (CSRSS) can be subjected to a denial of service when all worker threads are waiting for user input.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2299.php">nt-csrss-dos(2299)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-021.asp">MS99-021</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-021.mspx">MS99-021</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q233323">Q233323</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-049.shtml">J-049</ref><ref source="BID" url="http://www.securityfocus.com/bid/478">478</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0 SP5"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0724" published="1999-08-12" seq="1999-0724" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3341.php">openbsd-uio_offset-bo(3341)</ref><ref source="OSVDB" url="http://www.osvdb.org/6128">6128</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0725" published="1999-08-19" seq="1999-0725" severity="Medium" type="CVE"><desc><descript source="cve">When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. &quot;Double Byte Code Page&quot;.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2302.php">iis-double-byte-code-page(2302)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-022.asp">MS99-022</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q233335">Q233335</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-022.mspx">MS99-022</ref><ref source="BID" url="http://www.securityfocus.com/bid/477">477</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/2302">iis-double-byte-code-page(2302)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="3.0"/><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0726" published="1999-06-30" seq="1999-0726" severity="Medium" type="CVE"><desc><descript source="cve">An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2313.php">nt-malformed-image-header(2313)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-023.asp">MS99-023</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-023.mspx">MS99-023</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q234557">Q234557</ref><ref source="BID" url="http://www.securityfocus.com/bid/499">499</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0"/><vers num="4.0 SP4"/><vers num="Terminal Server 4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0727" published="1999-08-06" seq="1999-0727" severity="Medium" type="CVE"><desc><descript source="cve">A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3342.php">openbsd-ipsec-cleartext(3342)</ref><ref source="OSVDB" url="http://www.osvdb.org/6127">6127</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0728" published="1999-07-06" seq="1999-0728" severity="Medium" type="CVE"><desc><descript source="cve">A Windows NT user can disable the keyboard or mouse by directly calling the IOCTLs which control them.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2340.php">nt-ioctl-dos(2340)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-024.asp">MS99-024</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-024.mspx">MS99-024</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q236359">Q236359</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="Server 4.0"/><vers num="Enterprise 4.0"/><vers num="Terminal Server 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0729" published="2001-03-12" seq="1999-0729" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/601">bid 601</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-7.php">lotus-ldap-bo</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise34.php">19990823 Denial of Service Attack against Lotus Notes Domino Server 4.6</ref><ref adv="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-061.shtml">J-061</ref><ref source="OSVDB" url="http://www.osvdb.org/1057">1057</ref></refs><vuln_soft><prod name="Lotus Domino Server" vendor="IBM"><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0730" published="1999-06-12" seq="1999-0730" severity="High" type="CVE"><desc><descript source="cve">The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0731" published="1999-06-23" seq="1999-0731" severity="Medium" type="CVE"><desc><descript source="cve">The KDE klock program allows local users to unlock a session using malformed input.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/489">BID 489</ref><ref source="BID" url="http://www.securityfocus.com/bid/489">489</ref></refs><vuln_soft><prod name="OpenLinux" vendor="Caldera"><vers num="2.2"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0732" published="1999-08-19" seq="1999-0732" severity="Low" type="CVE"><desc><descript source="cve">The logging facilitity of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3146.php">smtp-refuser-tmp(3146)</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/1999/19990823b">smtp-refuser</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0733" published="1999-06-26" seq="1999-0733" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2301.php">vmware-bo(2301)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-06-22&amp;msg=000601bec01b$85621440$955e2499@default"></ref><ref source="BID" url="http://www.securityfocus.com/bid/490">490</ref></refs><vuln_soft><prod name="VMWare" vendor="VMWare"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0734" published="1999-08-19" seq="1999-0734" severity="High" type="CVE"><desc><descript source="cve">A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3133.php">ciscosecure-read-write(3133)</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/csecure-dbaccess.shtml"></ref></refs><vuln_soft><prod name="CiscoSecure" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-21" name="CVE-1999-0735" published="2000-01-04" seq="1999-0735" severity="Medium" type="CVE"><desc><descript source="cve">KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="XF" url="http://xforce.iss.net/xforce/alerts/id/advise27">KDE K-Mail File Creation Vulnerability</ref><ref patch="1" source="SF" url="http://www.securityfocus.com/bid/300"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA1999015_01.html">RHSA-1999:015-01</ref></refs><vuln_soft><prod name="K-Mail" vendor="KDE"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0736" published="1999-05-07" seq="1999-0736" severity="Medium" type="CVE"><desc><descript source="cve">The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">Microsoft Security Bulletin (MS99-013)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2381.php">iis-samples-showcode(2381)</ref><ref adv="1" patch="1" source="lOpht" url="http://www.l0pht.com/advisories/showcode.txt">L0pht Security Advisory</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval932.html">OVAL932</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:932">oval:org.mitre.oval:def:932</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0737" published="1999-05-07" seq="1999-0737" severity="Medium" type="CVE"><desc><descript source="cve">The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2381.php">iis-samples-showcode(2381)</ref><ref adv="1" patch="1" source="lOpht" url="http://www.l0pht.com/advisories/showcode.txt">L0pht Security Advisory</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">MS99-013</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0738" published="1999-05-07" seq="1999-0738" severity="Medium" type="CVE"><desc><descript source="cve">The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2381.php">iis-samples-showcode(2381)</ref><ref adv="1" patch="1" source="lOpht" url="http://www.l0pht.com/advisories/showcode.txt">L0pht Security Advisory</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">MS99-013</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0739" published="1999-05-07" seq="1999-0739" severity="Medium" type="CVE"><desc><descript source="cve">The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2381.php">iis-samples-showcode(2381)</ref><ref adv="1" patch="1" source="lOpht" url="http://www.l0pht.com/advisories/showcode.txt">L0pht Security Advisory</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">MS99-013</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0740" published="1999-08-19" seq="1999-0740" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Caldera" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-022.0.txt"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3139.php">linux-telnetd-term(3139)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/594">BID 594</ref><ref source="BID" url="http://www.securityfocus.com/bid/594">594</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.2"/><vers num="5.2"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0741" published="1999-08-19" seq="1999-0741" severity="High" type="CVE"><desc><descript source="cve">QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-7.phpqms-2060-no-root-password">qms-2060-no-root-password</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=593">QMS 2060 Printer Passwordless Root Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-08-15%26msg%3D199908181402.KAA03077@alchemy.chem.utoronto.ca">QMS 2060 printer security hole</ref><ref source="BID" url="http://www.securityfocus.com/bid/593">593</ref></refs><vuln_soft><prod name="CrownNet Unix Utilities" vendor="QMS"><vers num="2060"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0742" published="1999-06-22" seq="1999-0742" severity="Medium" type="CVE"><desc><descript source="cve">The Debian mailman package uses weak authentication, which allows attackers to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/480">BID 480</ref><ref source="BID" url="http://www.securityfocus.com/bid/480">480</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0743" published="1999-08-20" seq="1999-0743" severity="Low" type="CVE"><desc><descript source="cve">Trn allows local users to overwrite other users&apos; files via symlinks.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3144.php">trn-symlinks(3144)</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/1999/19990823c">trn: /tmp file creation problem</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3144">trn-symlinks(3144)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0744" published="2000-01-04" seq="1999-0744" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/603">603</ref></refs><vuln_soft><prod name="Enterprise Server" vendor="Netscape"><vers num=""/></prod><prod name="FastTrack" vendor="Netscape"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0745" published="1999-08-18" seq="1999-0745" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/590">BID 590</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3135.php">aix-pdnsd-bo(3135)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-059.shtml">J-059</ref><ref source="BID" url="http://www.securityfocus.com/bid/590">590</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/><vers num="3.1"/><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0746" published="1999-08-16" seq="1999-0746" severity="Medium" type="CVE"><desc><descript source="cve">A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3128.php">linux-identd-dos(3128)</ref><ref adv="1" patch="1" source="SuSE" url="http://www.suse.de/de/support/security/suse_security_announce_12.txt">SUSE:19990824 Security hole in netcfg</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/587">BID 587</ref><ref source="BID" url="http://www.securityfocus.com/bid/587">587</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4.1"/><vers num="4.4"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="3.6"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0747" published="1999-08-18" seq="1999-0747" severity="Low" type="CVE"><desc><descript source="cve">Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.</descript></desc><loss_types><avail/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/589">BID 589</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3145.php">bsdi-smp-dos(3145)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSI.4.10.9908170253560.19291-100000@saturn.psn.net">19990816 Symmetric Multiprocessing (SMP) Vulnerbility in BSDi 4.0.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/589">589</ref></refs><vuln_soft><prod name="BSD_OS" vendor="BSDI"><vers num="4.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0748" published="1999-06-24" seq="1999-0748" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Red Hat net-tools package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4095.php">redhat-net-tool-bo(4095)</ref><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/mailing-lists/redhat-watch-list/1999-6/msg00011.html">Potential security problem in Red Hat 6.0 net-tools.</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0749" published="1999-08-16" seq="1999-0749" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/586">BID 586</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3129.php">win-ie5-telnet-heap-overflow(3129)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-033.asp">MS99-033</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-033.asp">MS99-033</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-033.mspx">MS99-033</ref><ref source="BID" url="http://www.securityfocus.com/bid/586">586</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0750" published="1999-09-13" seq="1999-0750" severity="Medium" type="CVE"><desc><descript source="cve">Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user&apos;s Hotmail account.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D630">Hotmail Javascript STYLE Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-09-8%26msg%3D37DCF0FE.908E4B4F@nat.bg">Hotmail Security Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/630">630</ref></refs><vuln_soft><prod name="Hotmail" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0751" published="1999-09-13" seq="1999-0751" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-09-8&amp;msg=199909130017.IGC05202.XOJBN-@lac.co.jp">BUGTRAQ:19990913 Accept overflow on Netscape Enterprise Server 3.6 SP2</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/631">BID 631</ref><ref source="BID" url="http://www.securityfocus.com/bid/631">631</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3256">netscape-accept-bo(3256)</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.6 SP2"/><vers num="3.51"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0752" published="1999-07-06" seq="1999-0752" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-07-1&amp;msg=19990706215610.7307.qmail@underground.org">BUGTRAQ:19990706 Netscape Enterprise Server SSL Handshake Bug</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0753" published="1999-08-17" seq="1999-0753" severity="High" type="CVE"><desc><descript source="cve">The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3245.php">mini-sql-w3-msql-cgi(3245)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-08-15&amp;msg=19990817171348.8576.qmail@securityfocus.com">BUGTRAQ:19990817 Stupid bug in W3-msql</ref><ref source="BID" url="http://www.securityfocus.com/bid/591">591</ref></refs><vuln_soft><prod name="mSQL" vendor="Hughes"><vers num="2.0.10"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0754" published="1999-05-11" seq="1999-0754" severity="High" type="CVE"><desc><descript source="cve">The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2180.php">inn-innconf-env(2180)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/255">BID 255</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/corp/support/errata/inn99_05_22.html"></ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-011.0.txt">CSSA-1999-011.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/255">255</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0755" published="1999-05-27" seq="1999-0755" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT RRAS and RAS clients cache a user&apos;s password even if the user has not selected the &quot;Save password&quot; option.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2243.php">nt-ras-pwcache(2243)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-017.asp">MS99-017</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q230681">Q230681</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-017.mspx">MS99-017</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0 SP2"/><vers num="4.0 SP4"/><vers num="4.0 SP1"/><vers num="4.0 SP3"/><vers num="4.0 SP5"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0756" published="2001-03-12" seq="1999-0756" severity="Medium" type="CVE"><desc><descript source="cve">ColdFusion Administrator with Advanced Security enabled allows remote users to stop the ColdFusion server via the Start/Stop utility.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2207.php">coldfusion-admin-dos(2207)</ref><ref adv="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=10968&amp;Method=Full">ASB99-07</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.0"/><vers num="4.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0757" published="2001-03-12" seq="1999-0757" severity="Low" type="CVE"><desc><descript source="cve">The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=10969&amp;Method=Full">ASB99-08</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2208.php">coldfusion-encryption(2208)</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0758" published="2001-03-12" seq="1999-0758" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script&apos;s URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=15099&amp;Method=Full">ASB00-06</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2206.php">netscape-space-view(2206)</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.5.1"/></prod><prod name="FastTrack" vendor="Netscape"><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0759" published="1999-09-13" seq="1999-0759" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FuseMAIL POP service via long USER and PASS commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=634">FuseWare FuseMail POP Mail Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3300.php">fuseware-popmail-bo(3300)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-08-8%26msg%3D37DBB7BA1EA.5ADFSHADOWPENGUIN@fox.nightland.net">Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug</ref><ref source="CONFIRM" url="http://www.crosswinds.net/~fuseware/faq.html#8">http://www.crosswinds.net/~fuseware/faq.html#8</ref><ref source="BID" url="http://www.securityfocus.com/bid/634">634</ref></refs><vuln_soft><prod name="FuseMail" vendor="FuseWare"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0760" published="2001-03-12" seq="1999-0760" severity="High" type="CVE"><desc><descript source="cve">Undocumented ColdFusion Markup Language (CFML) tags and functions in the ColdFusion Administrator allow users to gain additional privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3288.php">coldfusion-server-cfml-tags(3288)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/550">bid 550</ref><ref source="ALLAIRE" url="http://www.allaire.com/handlers/index.cfm?ID=11714&amp;Method=Full">ASB99-10</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.0.1"/><vers num="4.0"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0.1"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0761" published="2000-09-16" seq="1999-0761" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/644">BID 644</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3304.php">freebsd-fts-lib-bo(3304)</ref><ref source="BID" url="http://www.securityfocus.com/bid/644">644</ref><ref source="OSVDB" url="http://www.osvdb.org/1074">1074</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.2.8"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.1.7.1"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0762" published="1999-05-24" seq="1999-0762" severity="Low" type="CVE"><desc><descript source="cve">When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the &quot;about&quot; protocol to gain access to browser information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2205.php">BUGTRAQ:19990524 Netscape Communicator JavaScript in &lt;TITLE&gt; security vulnerability</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers edition="Windows 95" num="4.6"/><vers num="4.x"/></prod><prod name="Navigator" vendor="Netscape"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0763" published="1999-05-01" seq="1999-0763" severity="Medium" type="CVE"><desc><descript source="cve">NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2202.php">NETBSD:1999-010,XF:netbsd-arp</ref><ref source="OSVDB" url="http://www.osvdb.org/6540">6540</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0764" published="1999-05-01" seq="1999-0764" severity="Medium" type="CVE"><desc><descript source="cve">NetBSD allows ARP packets to overwrite static ARP entries.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2202.php">netbsd-arp(2202)</ref><ref source="OSVDB" url="http://www.osvdb.org/6539">6539</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0765" published="1999-05-19" seq="1999-0765" severity="High" type="CVE"><desc><descript source="cve">SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2195.php">irix-midikeys(2195)</ref><ref adv="1" patch="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9905c&amp;L=bugtraq&amp;F=&amp;S=&amp;P=2338"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990501-01-A">19990501-01-A</ref><ref source="BID" url="http://www.securityfocus.com/bid/262">262</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0766" published="1999-10-21" seq="1999-0766" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3378.php">msvm-verifier-java(3378)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-045.asp">MS99-045</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/600">BID 600</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-031.mspx">MS99-031</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q240346">Q240346</ref><ref source="BID" url="http://www.securityfocus.com/bid/600">600</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0767" published="1999-09-08" seq="1999-0767" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3235.php">sun-libc-lcmessages(3235)</ref><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=secbull/189">LC_MESSAGES</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-069.shtml">SunOS LC_MESSAGES Environment Variable Vulnerability</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers edition="x86" num="2.6"/><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0768" published="1999-08-25" seq="1999-0768" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/602">BID 602</ref><ref source="BID" url="http://www.securityfocus.com/bid/602">602</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/><vers edition="i386" num="5.2"/><vers num="4.2"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0769" published="1999-08-25" seq="1999-0769" severity="High" type="CVE"><desc><descript source="cve">Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/611">BID 611</ref><ref source="BID" url="http://www.securityfocus.com/bid/611">611</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/><vers edition="i386" num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="Vixie Cron" vendor="Paul Vixie"><vers num="3.0 pl1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="2.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0770" published="1999-07-29" seq="1999-0770" severity="Low" type="CVE"><desc><descript source="cve">Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-07-29&amp;msg=Pine.GSO.4.02.9907291222390.12581-100000@dimension.net">BUGTRAQ:19990729 Simple DOS attack on FW-1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/549">BID 549</ref><ref source="OSVDB" url="http://www.osvdb.org/1027">1027</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0771" published="1999-05-26" seq="1999-0771" severity="Medium" type="CVE"><desc><descript source="cve">The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-05-22&amp;msg=4125677D.0056351A.00@mailgw.backupcentralen.se">BUGTRAQ:19990526 Infosec</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2258.php">management-agent-file-read(2258)</ref></refs><vuln_soft><prod name="Insight Management Agent" vendor="Compaq"><vers num=""/></prod><prod name="Power Management" vendor="Compaq"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0772" published="1999-06-01" seq="1999-0772" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.</descript></desc><loss_types><avail/><conf/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2259.php">management-agent-dos(2259)</ref><ref adv="1" patch="1" source="Compaq" url="http://ftp1.support.compaq.com/public/Digital_UNIX/v4.0f/ssrt0612u_im_upd06991.html">SSRT0612U</ref></refs><vuln_soft><prod name="Insight Management Agent" vendor="Compaq"><vers num=""/></prod><prod name="Power Management" vendor="Compaq"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0773" published="1999-05-11" seq="1999-0773" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris lpset program allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/251">BID 251</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2183.php">sol-lpset-bo(2183)</ref><ref source="BUGTRAQ" url="http://www.netspace.org/cgi-bin/wa?A2=ind9905B&amp;L=bugtraq&amp;P=R2017">19990511 Solaris2.6 and 2.7 lpset overflow</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0774" published="1999-08-31" seq="1999-0774" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-08-29&amp;msg=19990830200449.54656.qmail@lagoon.FreeBSD.lublin.pl">BUGTRAQ:19990830 Babcia Padlina Ltd. security advisory: mars_nwe buffer overf</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/617">BID 617</ref><ref source="BID" url="http://www.securityfocus.com/bid/617">617</ref></refs><vuln_soft><prod name="Mars NWE" vendor="Martin Stover"><vers num="0.99"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0775" published="1999-06-10" seq="1999-0775" severity="High" type="CVE"><desc><descript source="cve">Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the &quot;established&quot; keyword in an access list.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2267.php">cisco-gigaswitch(2267)</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/iosgsracl-pub.shtml">Cisco IOS Software established Access List Keyword Error</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="11.2(14)GS2"/><vers num="11.2(15)G"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0776" published="1999-05-12" seq="1999-0776" severity="Medium" type="CVE"><desc><descript source="cve">Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-10.phphttp-alibaba-dotdot">http-alibaba-dotdot</ref><ref adv="1" source="NTBugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9905&amp;L=NTBUGTRAQ&amp;P=R1533">&quot;..&quot;-hole in Alibaba 2.0</ref></refs><vuln_soft><prod name="Alibaba" vendor="Computer Software Manufaktur"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0777" published="1999-09-23" seq="1999-0777" severity="High" type="CVE"><desc><descript source="cve">IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have &quot;No Access&quot; permissions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/658">BID 658</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q237/9/87.ASP"></ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp">MS99-039</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241407">Q241407</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q242559">Q242559</ref><ref source="BID" url="http://www.securityfocus.com/bid/658">658</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Commercial Internet System" vendor="Microsoft"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0778" published="1999-06-25" seq="1999-0778" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="KSR[T]" url="http://www.ksrt.org/adv11.html">KSRT:011,XF:accelx-display-bo</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2306.php">accelx-display-bo(2306)</ref><ref source="BID" url="http://www.securityfocus.com/bid/488">488</ref></refs><vuln_soft><prod name="Accelerated-X Server" vendor="Xi Graphics"><vers num="4"/><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0779" published="1998-09-03" seq="1999-0779" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in HP-UX SharedX recserv program.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="S.A.F.E.R." url="http://www.siamrelay.com/advisories/advisory_0003.html"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1393.php">hp-sharedx(1393)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9810-086">HPSBUX9810-086</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.1"/><vers num="10.10"/><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0780" published="1998-11-18" seq="1999-0780" severity="Medium" type="CVE"><desc><descript source="cve">KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1647.php">kde-klock-process-kill(1647)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="KDE" vendor="KDE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0781" published="1998-11-18" seq="1999-0781" severity="High" type="CVE"><desc><descript source="cve">KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1648.php">kde-klock-bindir-trojans(1648)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="KDE" vendor="KDE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0782" published="1998-11-18" seq="1999-0782" severity="Low" type="CVE"><desc><descript source="cve">KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=1998-11-15&amp;msg=13907.3585.618865.487999@torrey.cs.utah.edu">BUGTRAQ:19981118 Multiple KDE security vulnerabilities (root compromise),XF:kde-kppp-directory-create</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1649.php">kde-kppp-directory-create(1649)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">19981118 Multiple KDE security vulnerabilities (root compromise)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="KDE" vendor="KDE"><vers num="1.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0783" published="1998-06-16" seq="1999-0783" severity="Medium" type="CVE"><desc><descript source="cve">FreeBSD allows local users to conduct a denial of service by creating a hard link from a device special file to a file on an NFS file system.</descript></desc><loss_types><avail/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3827.php">freebsd-nfs-link-dos(3827)</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-057.shtml">FreeBSD-SA-98:05</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-057.shtml">I-057</ref><ref source="OSVDB" url="http://www.osvdb.org/6090">6090</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0784" published="2001-03-12" seq="1999-0784" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/1999_1/0056.html">19990104 Re: Fw:</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/1998_4/0764.html">19981228 Oracle8 TNSLSNR DoS</ref><ref source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/1998/msg00536.html">19980827 NERP DoS attack possible in Oracle</ref></refs><vuln_soft><prod name="Oracle7i" vendor="Oracle"><vers num="7.3.3"/><vers num="7.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0785" published="1999-05-11" seq="1999-0785" severity="High" type="CVE"><desc><descript source="cve">The INN inndstart program allows local users to gain root privileges via the &quot;pathrun&quot; parameter in the inn.conf file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-05-8&amp;msg=199905111540.LAA28194@ns0.poconos.net">BUGTRAQ:19990511 INN 2.0 and higher. Root compromise potential</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/254">BID 254</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2179.php">inn-pathrun(2179)</ref><ref source="BID" url="http://www.securityfocus.com/bid/254">254</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0786" published="1999-09-22" seq="1999-0786" severity="Medium" type="CVE"><desc><descript source="cve">The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/659">BID 659</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-09-22&amp;msg=19990922211439.A654@tightrope.demon.co.uk">BUGTRAQ:19990922 LD_PROFILE local root exploit for solaris 2.6</ref><ref source="BID" url="http://www.securityfocus.com/bid/659">659</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0787" published="1999-09-17" seq="1999-0787" severity="Low" type="CVE"><desc><descript source="cve">The SSH authentication agent follows symlinks via a UNIX domain socket.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4156.php">ssh-socket-auth-symlink-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D660">SSH Authentication Socket File Creation Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93760201002154&amp;w=2">19990917 A few bugs...</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93832856804415&amp;w=2">19990924 [Fwd: Truth about ssh 1.2.27 vulnerability]</ref><ref source="BID" url="http://www.securityfocus.com/bid/660">660</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.27"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0788" published="1999-09-26" seq="1999-0788" severity="Medium" type="CVE"><desc><descript source="cve">Arkiea nlservd allows remote attackers to conduct a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3321.php">arkiea-backup-nlserverd-remote-dos(3321)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D662">Arkiea Backup nlserverd Remote Denial of Service Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-09-22%26msg%3D06b001bf0621%244e5ae390%243177a8c0@webley">Multiple vendor Knox Arkiea local root/remote DoS</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837184228248&amp;w=2">19990924 Multiple vendor Knox Arkiea local root/remote DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/662">662</ref></refs><vuln_soft><prod name="Arkeia" vendor="Knox Software"><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0789" published="1999-09-28" seq="1999-0789" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX ftpd in the libc library.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3758.php">aix-ftpd-bo(3758)</ref><ref adv="1" patch="1" source="IBM" url="http://www-1.ibm.com/services/continuity/recover1.nsf/advisories/C246FD0FCD6FB7988525680F0077E2E9/$file/sva004.txt"></ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/679">BID 679</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-072.shtml">J-072</ref><ref source="BID" url="http://www.securityfocus.com/bid/679">679</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0790" published="2000-04-01" seq="1999-0790" severity="Low" type="CVE"><desc><descript source="cve">A remote attacker can read information from a Netscape user&apos;s cache via JavaScript.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4308.php">netscape-javascript-cookies(4308)</ref><ref source="MISC" url="http://home.netscape.com/security/notes/jscachebrowsing.html">http://home.netscape.com/security/notes/jscachebrowsing.html</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0791" published="1999-10-06" seq="1999-0791" severity="High" type="CVE"><desc><descript source="cve">Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3361.php">hybrid-anon-cable-modem-reconfig</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-10-01%26msg%3DPine.LNX.4.10.9910060922490.490-100000@www.ksrt.org">KSR[T] Advisories #012: Hybrid Network&apos;s Cable Modems</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/advisory.html%3Fid%3D1787">Hybrid Network&apos;s Cable Modems</ref><ref source="BID" url="http://www.securityfocus.com/bid/695">695</ref></refs><vuln_soft><prod name="HSMP" vendor="Hybrid Network"><vers num=""/></prod><prod name="Cable modem" vendor="Hybrid Network"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0792" published="1998-09-01" seq="1999-0792" severity="Medium" type="CVE"><desc><descript source="cve">ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4290.php">routermate-snmp-community</ref><ref adv="1" patch="1" source="Root Shell" url="http://rootshell.com/archive-j457nxiqi3gq59dv/199809/osicom.txt.html">Osicom Technologies ROUTERmate Security Advisory</ref><ref source="MISC" url="http://www2.merton.ox.ac.uk/~security/rootshell/0022.html">http://www2.merton.ox.ac.uk/~security/rootshell/0022.html</ref></refs><vuln_soft><prod name="ROUTERmate" vendor="Osicom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0793" published="1999-11-17" seq="1999-0793" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.</descript></desc><loss_types><conf/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3327.php">ie-java-redirect(3327)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-043.asp">MS99-043</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-043.mspx">MS99-043</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="4.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0794" published="1999-10-01" seq="1999-0794" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Excel does not warn a user when a macro is present in a Symbolic Link (SYLK) format file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q241/9/02.ASP"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3369.php">excel-sylk-macro(3369)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-044.mspx">MS99-044</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241900">Q241900</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241901">Q241901</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q241902">Q241902</ref></refs><vuln_soft><prod name="Excel" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0795" published="1998-03-01" seq="1999-0795" severity="High" type="CVE"><desc><descript source="cve">The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/812.php">sun-nisplus</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num=""/></prod><prod name="SunOS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0796" published="1998-05-01" seq="1999-0796" severity="High" type="CVE"><desc><descript source="cve">FreeBSD T/TCP Extensions for Transactions can be subjected to spoofing attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3828.php">freebsd-ttcp-spoof(3828)</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-98:03.ttcp.asc">FreeBSD-SA-98:03</ref><ref source="OSVDB" url="http://www.osvdb.org/6089">6089</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0797" published="1998-06-29" seq="1999-0797" severity="Low" type="CVE"><desc><descript source="cve">NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.</descript></desc><loss_types><avail/></loss_types><vuln_types><env/><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise2.php"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1205.php">sun-nis-nisplus(1205)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-070.shtml">I-070</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0798" published="1998-12-04" seq="1999-0798" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91278867118128&amp;w=2">bootp-remote-bo(1608)</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.htmlbootpd">SECURITY FIX</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9812a&amp;L=bugtraq&amp;F=&amp;S=&amp;P=2119">bootpd remote vulnerability</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Linux" vendor="Red Hat"><vers num=""/></prod><prod name="OpenServer" vendor="SCO"><vers num=""/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.3"/><vers num="2.4"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod><prod name="UnixWare" vendor="SCO"><vers num="7.0"/><vers num="7.0.1"/></prod><prod name="Internet FastStart" vendor="SCO"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0799" published="1997-06-01" seq="1999-0799" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4143.php">bootpd-bo(4143)</ref></refs><vuln_soft><prod name="Bootpd" vendor="CMU"><vers num="2.4.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0800" published="2001-03-12" seq="1999-0800" severity="Medium" type="CVE"><desc><descript source="cve">The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=9602&amp;Method=Full">ASB99-05</ref><ref adv="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00332.html">NTBUGTRAQ:19990211 ACFUG List: Alert: Allaire Forums GetFile bug</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1748">allaire-forums-file-read(1748)</ref><ref source="OSVDB" url="http://www.osvdb.org/944">944</ref></refs><vuln_soft><prod name="Forums" vendor="Allaire"><vers num="2.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0801" published="1999-04-09" seq="1999-0801" severity="High" type="CVE"><desc><descript source="cve">BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-9.phpbmc-patrol-frames">bmc-patrol-frames</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904b&amp;L=bugtraq&amp;F=&amp;S=&amp;P=3253">Patrol security bugs</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref><ref source="XF" url="http://www.iss.net/security_center/static/2075.php">bmc-patrol-frames(2075)</ref></refs><vuln_soft><prod name="PATROL Agent" vendor="BMC Software"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0802" published="1999-05-27" seq="1999-0802" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2244.php">ie-favicon(2244)</ref><ref adv="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-018.asp">MS99-018</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx">MS99-018</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231450">Q231450</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0803" published="1999-05-25" seq="1999-0803" severity="Low" type="CVE"><desc><descript source="cve">The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/287">BID 287</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2249.php">ibm-enfirewall-tmpfiles(2249)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92765973207648&amp;w=2">19990525 IBM eNetwork Firewall for AIX</ref><ref source="OSVDB" url="http://www.osvdb.org/962">962</ref></refs><vuln_soft><prod name="AIX eNetwork Firewall" vendor="IBM"><vers num="3.3"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0804" published="1999-06-01" seq="1999-0804" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://securityfocus.com/bid/302">BID 302</ref><ref source="BID" url="http://www.securityfocus.com/bid/302">302</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0805" published="2001-03-12" seq="1999-0805" severity="Medium" type="CVE"><desc><descript source="cve">Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2184.php">novell-tts-dos(2184)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/1999_2/0439.html">19990512 DoS with Netware 4.x&apos;s TTS</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="4.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0806" published="1999-05-10" seq="1999-0806" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris dtprintinfo program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2188.php">cde-dtprintinfo(2188)</ref><ref adv="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9905B&amp;L=bugtraq&amp;P=R1173"></ref><ref source="OSVDB" url="http://www.osvdb.org/6552">6552</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-1999-0807" published="1999-05-01" seq="1999-0807" severity="High" type="CVE"><desc><descript source="cve">The Netscape Directory Server installation procedure leaves sensitive information in a file that is accessible to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2174.php">netscape-dirsvc-password(2174)</ref></refs><vuln_soft><prod name="Netscape Directory Server" vendor="Netscape"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0808" published="1999-12-31" seq="1999-0808" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-053.shtml">I-053</ref><ref patch="1" source="Internet Systems Consortium" url="ftp://ftp.isc.org/isc/dhcp/dhcp-1.0-history/dhcp-1.0.0-1.0pl1.diff.gz"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925960&amp;w=2">19980518 DHCP 1.0 and 2.0 SECURITY ALERT! (fwd)</ref></refs><vuln_soft><prod name="DHCP Client" vendor="ISC"><vers num="1.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0809" published="1999-07-09" seq="1999-0809" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to &quot;Only accept cookies originating from the same server as the page being viewed&quot;.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-07-8&amp;msg=Pine.LNX.4.10.9907022123460.27044-100000@localhost">BUGTRAQ:19990709 Communicator 4.[56]x, JavaScript used to bypass cookie settings</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0810" published="1999-07-21" seq="1999-0810" severity="High" type="CVE"><desc><descript source="cve">Denial of service in Samba NETBIOS name service daemon (nmbd).</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0811" published="1999-07-21" seq="1999-0811" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Samba smbd program via a malformed message command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-07-15&amp;msg=19990721023513Z12865037-4222%2b1570@samba.anu.edu.au"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3225.php">samba-message-bo(3225)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/536">BID 536</ref><ref source="BID" url="http://www.securityfocus.com/bid/536">536</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0812" published="2000-07-12" seq="1999-0812" severity="High" type="CVE"><desc><descript source="cve">Race condition in Samba smbmnt allows local users to mount file systems in arbitrary locations.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0813" published="1999-08-10" seq="1999-0813" severity="High" type="CVE"><desc><descript source="cve">Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=1999-08-08&amp;msg=19990810203437.E10498@finlandia.infodrom.north.de">BUGTRAQ:19990810 Severe bug in cfingerd before 1.4.0</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4112.php">cfingerd-privileges(4112)</ref></refs><vuln_soft><prod name="cfingerd" vendor="Infodrom"><vers num="1.4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0814" published="1999-08-11" seq="1999-0814" severity="High" type="CVE"><desc><descript source="cve">Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA1999027_02.html">REDHAT:RHSA-1999:027</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-1999-027.html">RHSA-1999:027</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0815" published="1999-12-31" seq="1999-0815" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q196/2/70.asp"></ref><ref source="XF" url="http://xforce.iss.net/static/1974.php">nt-snmpagent-leak(1974)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:952">oval:org.mitre.oval:def:952</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers edition="SP5" num="Server 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0816" published="1998-05-10" seq="1999-0816" severity="High" type="CVE"><desc><descript source="cve">The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9805B&amp;L=bugtraq&amp;P=R1621">Security Vulnerability in Motorola CableRouters</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2002.php">motorola-cable-default-pass(2002)</ref></refs><vuln_soft><prod name="Motorola CableRouter" vendor="Motorola"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0817" published="1999-09-15" seq="1999-0817" severity="High" type="CVE"><desc><descript source="cve">Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Lynx" vendor="University of Kansas"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0818" published="1999-11-20" seq="1999-0818" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D38433B7F5A.53F4SHADOWPENGUIN@fox.nightland.net">another hole of Solaris7 kcms_configure</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=831">Solaris kcms_configure</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3651.php">sol-kcms-conf-netpath-bo(3651)</ref><ref source="BID" url="http://www.securityfocus.com/bid/831">831</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38433B7F5A.53F4SHADOWPENGUIN@fox.nightland.net">19991130 another hole of Solaris7 kcms_configure</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0819" published="1999-12-01" seq="1999-0819" severity="Medium" type="CVE"><desc><descript source="cve">NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3719.php">nt-mail-vrfy(3719)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94398141118586&amp;w=2">19991130 NTmail and VRFY</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Mail 4"/><vers num="Mail 5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0820" published="1999-12-01" seq="1999-0820" severity="Medium" type="CVE"><desc><descript source="cve">FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/838">BID 838</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3483.php">freebsd-seyon-dir-add(3483)</ref><ref source="BID" url="http://www.securityfocus.com/bid/838">838</ref><ref source="OSVDB" url="http://www.osvdb.org/5996">5996</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0821" published="1999-11-08" seq="1999-0821" severity="Medium" type="CVE"><desc><descript source="cve">FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D838">FreeBSD Seyon setgid dialer Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-9.phpfreebsd-seyon-dir-add">freebsd-seyon-dir-add</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-8%26msg%3D19991109035038.4631.qmail@www0h.netaddress.usa.net">FreeBSD 3.3&apos;s seyon vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/838">838</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0822" published="1999-11-30" seq="1999-0822" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-10.phpqpopper-auth-bo">qpopper-auth-bo</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D830">Qualcomm qpopper Remote Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-28%26msg%3DPine.LNX.4.04.9911300056540.6421-300000@aviation.net">serious Qpopper 3.0 vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/830">830</ref></refs><vuln_soft><prod name="qpopper" vendor="Qualcomm"><vers num="3.0b20"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0823" published="1999-12-01" seq="1999-0823" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=839">FreeBSD xmindpath Buffer Overflow Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19991130230829.5307.qmail@nw173.netaddress.usa.net">Several FreeBSD-3.3 vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3721.php">freebsd-xmindpath</ref><ref source="BID" url="http://www.securityfocus.com/bid/839">839</ref><ref source="OSVDB" url="http://www.osvdb.org/1150">1150</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0824" published="1999-11-30" seq="1999-0824" severity="Medium" type="CVE"><desc><descript source="cve">A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/833">BID 833</ref><ref source="BID" url="http://www.securityfocus.com/bid/833">833</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0825" published="1999-12-03" seq="1999-0825" severity="Low" type="CVE"><desc><descript source="cve">The default permissions for UnixWare /var/mail allow local users to read and modify other users&apos; mail.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3634.php">sco-mail-permissions(3634)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D849">SCO UnixWare &apos;/var/mail&apos; permissions Vulnerability</ref><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.25a">Security holes in mail clients</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19991204040345.9760.qmail@nwcst091.netaddress.usa.net">UnixWare read/modify users&apos; mail</ref><ref source="BID" url="http://www.securityfocus.com/bid/849">849</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0826" published="1999-12-01" seq="1999-0826" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in FreeBSD angband allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=840">FreeBSD angband Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3723.php">angband-bo</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19991130230829.5307.qmail@nw173.netaddress.usa.net">Several FreeBSD-3.3 vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/840">840</ref><ref source="OSVDB" url="http://www.osvdb.org/1151">1151</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0827" published="1999-11-01" seq="1999-0827" severity="Low" type="CVE"><desc><descript source="cve">By default, Internet Explorer 5.0 and other versions enables the &quot;Navigate sub-frames across different domains&quot; option, which allows frame spoofing.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-4.phphttp-frame-spoof">http-frame-spoof</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/Windows/ie/security/spoof.asp">&quot;Frame Spoof&quot;fix</ref><ref adv="1" patch="1" source="Netscape" url="http://home.netscape.com/products/security/resources/bugs/framespoofing.html">The Frame-Spoofing Vulnerability</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="4.5"/><vers num="4.1"/><vers edition="SP2" num="4.0.1"/><vers edition="a Mac OS" num="4.0"/><vers num="4.0"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0.2"/><vers num="3.0"/></prod><prod name="Navigator" vendor="Netscape"><vers num="4.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0828" published="1999-12-02" seq="1999-0828" severity="Low" type="CVE"><desc><descript source="cve">UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3633.php">sco-pkg-dacread-fileread(3633)</ref><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a">Package Tool Security Patch</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19991204042117.18681.qmail@nw177.netaddress.usa.net">UnixWare and the dacread permission</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-1%26msg%3D19991205014254.17071.qmail@nw178.netaddress.usa.net"> UnixWare pkg* command exploits</ref><ref source="BID" url="http://www.securityfocus.com/bid/853">853</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0829" published="1999-11-01" seq="1999-0829" severity="Medium" type="CVE"><desc><descript source="cve">HP Secure Web Console uses weak encryption.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-29%26msg%3D19991201090540.A3537@freedom.swc.com"> HP Secure Web Console</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3725.php">hp-secure-console(3725)</ref></refs><vuln_soft><prod name="Secure Web Console" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0830" published="1999-11-01" seq="1999-0830" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SCO UnixWare Xsco command via a long argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3726.php">sco-unixware-xsco(3726)</ref><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.26b">Multiple Vulnerabilities Found In SCO OpenServer</ref><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2">SCO OpenServer Security Status</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-22%26msg%3DPine.LNX.3.95.991126042725.31331B-100000@cannabis.dataforce.net">UnixWare 7&apos;s Xsco</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0831" published="1999-11-19" seq="1999-0831" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Linux syslogd via a large number of connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-11-29&amp;msg=19991130192425.N1265@seduction">BUGTRAQ:19991130 [david@slackware.com: New Patches for Slackware 4.0 Available)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/809">BID 809</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-035.0.txt">CSSA-1999-035.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/809">809</ref></refs><vuln_soft><prod name="Qube" vendor="Cobalt"><vers num="2.0"/><vers num="1.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.3"/><vers num="6.2"/></prod><prod name="Cobalt RaQ" vendor="Sun"><vers num="2.0"/><vers num="3.0"/><vers num="1.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-1999-0832" published="1999-11-09" seq="1999-0832" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SuSE" url="http://lists.suse.com/archives/suse-security-announce/1999-Nov/0000.html">S.u.S.E. Linux Redhat nfs-server &lt; 2.2beta47 within nkita</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3501.php">linux-nfs-maxpath-bo(3501)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/782">BID 782</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.20.9911091058140.12964-100000@mail.zigzag.pl">19991109 undocumented bugs - nfsd</ref><ref source="DEBIAN" url="http://www.debian.org/security/1999/19991111">19991111 buffer overflow in nfs server</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_29.html">19991110 Security hole in nfs-server &lt; 2.2beta47 within nkita</ref><ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-033.0.txt">CSSA-1999-033.0</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/rh42-errata-general.html#NFS">RHSA-1999:053-01</ref><ref source="BID" url="http://www.securityfocus.com/bid/782">782</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="5.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0833" published="1999-11-10" seq="1999-0833" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in BIND 8.2 via NXT records.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-14-bind.html">CA-99-14-bind</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/788">BID 788</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3476.php">bind-nxt-bo(3476)</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.2.1"/><vers num="8.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0834" published="1999-12-01" seq="1999-0834" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-15-RSAREF2.html">CA-99-15-RSAREF2</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-11-29&amp;msg=3845D352.95E47E26@core-sdi.com">BUGTRAQ:19991201 Security Advisory: Buffer overflow in RSAREF2</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3514.php">ssh-rsaref-bo(3514)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/843">bugtraq id 843</ref><ref source="BID" url="http://www.securityfocus.com/bid/843">843</ref></refs><vuln_soft><prod name="RSAREF" vendor="RSA"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0835" published="1999-11-10" seq="1999-0835" severity="High" type="CVE"><desc><descript source="cve">Denial of service in BIND named via malformed SIG records.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-14-bind.html">CA-99-14-bind</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/788">BID 788</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3525.php">bind-sigrecord-dos(3525)</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5"/></prod><prod name="Solaris" vendor="Sun"><vers num="7.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="7"/><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0836" published="1998-12-02" seq="1999-0836" severity="High" type="CVE"><desc><descript source="cve">UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3730.php">unixware-uid-admin(3730)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/842">BID 842</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991202160111.20553.qmail@nwcst282.netaddress.usa.net">19991202 UnixWare 7 uidadmin exploit + discussion</ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.22a">SB-99.22a</ref><ref source="BID" url="http://www.securityfocus.com/bid/842">842</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1"/><vers num="7.0.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0837" published="1999-11-10" seq="1999-0837" severity="High" type="CVE"><desc><descript source="cve">Denial of service in BIND by improperly closing TCP sessions via so_linger.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-14-bind.html">CA-99-14-bind</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/788">BID 788</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3511.php">bind-solinger-dos(3511)</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref><ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.2.1"/><vers num="8.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0838" published="1999-12-01" seq="1999-0838" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3647.php">servu-ftp-site-bo(3647)</ref><ref source="BID" url="http://www.securityfocus.com/bid/859">859</ref></refs><vuln_soft><prod name="Serv-U FTP-Server" vendor="Deerfield"><vers num="2.5a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0839" published="1999-11-29" seq="1999-0839" severity="High" type="CVE"><desc><descript source="cve">Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/828">bugtraq id 828</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3664.php">ie-task-scheduler-privs(3664)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-051.asp">MS99-051</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-051.asp">MS99-051</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-051.mspx">MS99-051</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246972">Q246972</ref><ref source="BID" url="http://www.securityfocus.com/bid/828">828</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows NT 4.0" num="50"/><vers edition="Windows 98" num="5.0"/><vers edition="Windows 95" num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0840" published="1999-11-30" seq="1999-0840" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D832">Multiple Vendor CDE dtmail/mailtool Buffer Overflow Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D384249A4334.8C16SHADOWPENGUIN@fox.nightland.net">Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-10.phpsolaris-dtmail-overflow">solaris-dtmail-overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/832">832</ref><ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/1999-q4/0122.html">19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref><ref source="MISC" url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3579">solaris-dtmail-overflow(3579)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3580">solaris-dtmailpr-overflow(3580)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0841" published="1999-11-30" seq="1999-0841" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=832">Multiple Vendor CDE dtmail/mailtool Buffer Overflow Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D384249A4334.8C16SHADOWPENGUIN@fox.nightland.net">Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-10.php">solaris-dtmail-overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/832">832</ref><ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/1999-q4/0122.html">19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow</ref><ref source="MISC" url="http://www.securiteam.com/exploits/3J5QQPPQ0O.html">http://www.securiteam.com/exploits/3J5QQPPQ0O.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3732">cde-mailtool-bo(3732)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0842" published="1999-11-29" seq="1999-0842" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3649.php">symantec-mail-dir-traversal(3649)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/827">BID 827</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEAFCBAA.labs@ussrback.com">19991129 Symantec Mail-Gear 1.0 Web interface Server Directory Traversal Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/827">827</ref><ref source="OSVDB" url="http://www.osvdb.org/1144">1144</ref></refs><vuln_soft><prod name="Mail-Gear" vendor="Symantec"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0843" published="1999-11-04" seq="1999-0843" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3733.php">cisco-nat-dos(3733)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-10-29%26msg%3D38236267.7555C8FF@thievco.com">: Cisco NAT DoS</ref></refs><vuln_soft><prod name="Cisco router" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0844" published="1999-11-24" seq="1999-0844" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in MDaemon WorldClient and WebConfig services via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3555.php">mdaemon-worldclient-dos(3555)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DNCBBKFKDOLAGKIAPMILPOEPCCAAA.labs@ussrback.com">Remote DoS Attack in WorldClient Server v2.0.0.0 Vulnerability</ref><ref adv="1" patch="1" source="Mdaemon" url="http://mdaemon.deerfield.com/helpdesk/hotfix.cfm">Recent DoS attack reported on Mdaemon</ref><ref source="BID" url="http://www.securityfocus.com/bid/823">823</ref><ref source="BID" url="http://www.securityfocus.com/bid/820">820</ref></refs><vuln_soft><prod name="Mdaemon" vendor="Deerfield"><vers num="2.8.5"/><vers num="2.8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0845" published="1999-11-25" seq="1999-0845" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SCO su program allows local users to gain root access via a long username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3584.php">sco-su-username-bo(3584)</ref><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.19a">su Security Patch</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.95.991126035202.24887A-100000@cannabis.dataforce.net">UnixWare 7&apos;s su</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0846" published="1999-12-01" seq="1999-0846" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in MDaemon 2.7 via a large number of connection attempts.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Mdaemon" url="http://mdaemon.deerfield.com/helpdesk/hotfix.cfm">Recent DoS attack reported on Mdaemon</ref><ref source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-28%26msg%3D199912011604.HJI39569.BX-NOJ@lac.co.jp">Multiples Remotes DoS Attacks in MDaemonServer v2.8.5.0Vulnerability</ref></refs><vuln_soft><prod name="Mdaemon" vendor="Deerfield"><vers num="2.8.5"/><vers num="2.8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0847" published="1999-11-29" seq="1999-0847" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in free internet chess server (FICS) program, xboard.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="FICS program" vendor="Freechess.org"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0848" published="1999-11-10" seq="1999-0848" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in BIND named via consuming more than &quot;fdmax&quot; file descriptors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-14-bind.html">CA-99-14-bind</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/788">BID 788</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3512.php">bind-fdmax-dos(3512)</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref><ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.2.1"/><vers num="8.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0849" published="1999-11-10" seq="1999-0849" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in BIND named via maxdname.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-14-bind.html">CA-99-14-bind</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3529.php">bind-maxdname-bo(3529)</ref><ref adv="1" source="ISC" url="http://www.isc.org/products/BIND/bind-security-19991108.html">maxdname bug</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref><ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.2"/><vers num="8.2 P1"/><vers num="8.2.1"/><vers num="4.9.5"/><vers num="4.9.5 P1"/><vers num="4.9.6"/><vers num="4.9.7"/><vers num="8.1"/><vers num="8.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0850" published="1999-12-02" seq="1999-0850" severity="Low" type="CVE"><desc><descript source="cve">The default permissions for Endymion MailMan allow local users to read email or modify files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://seclists.org/bugtraq/1999/Dec/0031.html">Insecure default permissions for MailMan Professional Edition, version 3.0.18</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3736.php">endymion-mailman-perms(3736)</ref><ref source="BID" url="http://www.securityfocus.com/bid/845">845</ref></refs><vuln_soft><prod name="MailMan WebMail" vendor="Endymion"><vers num="3.0.18"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0851" published="1999-11-10" seq="1999-0851" severity="Low" type="CVE"><desc><descript source="cve">Denial of service in BIND named via naptr.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-14-bind.html">CA-99-14-bind</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3527.php">bind-naptr-dos(3527)</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-034.1.txt">CSSA-1999-034.1</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/194">00194</ref><ref source="BID" url="http://www.securityfocus.com/bid/788">788</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5"/></prod><prod name="Solaris" vendor="Sun"><vers num="7.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="7"/><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-21" name="CVE-1999-0852" published="1999-12-02" seq="1999-0852" severity="High" type="CVE"><desc><descript source="cve">IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=844">IBM Websphere Installation Permissions Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3737.php">websphere-protect(3737)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-29%26msg%3D199912021258.NAA15038@chr7ca99.swissre.ch">WebSphere protections from installation</ref><ref source="BID" url="http://www.securityfocus.com/bid/844">844</ref></refs><vuln_soft><prod name="Websphere Application Server" vendor="IBM"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0853" published="1999-12-01" seq="1999-0853" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3586.php">netscape-fasttrack-auth-bo(3586)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/847">BID 847</ref><ref source="BID" url="http://www.securityfocus.com/bid/847">847</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.51"/><vers num="3.6"/><vers num="3.6 SP2"/></prod><prod name="FastTrack" vendor="Netscape"><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0854" published="1999-11-01" seq="1999-0854" severity="Medium" type="CVE"><desc><descript source="cve">Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3738.php">http-ultimate-bbs(3738)</ref><ref source="CONFIRM" url="http://www.ultimatebb.com/home/versions.shtml">http://www.ultimatebb.com/home/versions.shtml</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl">20000225 FW: Important UBB News For Licensed Users</ref></refs><vuln_soft><prod name="Ultimate Bulletin Board" vendor="Infopop"><vers num="5.07"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0855" published="1999-12-01" seq="1999-0855" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FreeBSD gdc program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D834">FreeBSD gdc Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3739.php">freebsd-gdc-bo(3739)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-29%26msg%3D19991130223106.15090.qmail@nwcst323.netaddress.usa.net">FreeBSD 3.3 gated-3.1.5 local exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/834">834</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0856" published="1999-12-01" seq="1999-0856" severity="Medium" type="CVE"><desc><descript source="cve">login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3740.php">slackware-remote-login(3740)</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0857" published="1999-12-01" seq="1999-0857" severity="Low" type="CVE"><desc><descript source="cve">FreeBSD gdc program allows local users to modify files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3741.php">freebsd-gdc(3741)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-29%26msg%3D19991130223106.15090.qmail@nwcst323.netaddress.usa.net">FreeBSD 3.3 gated-3.1.5 local exploit</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=835">FreeBSD gdc Symlink Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/835">835</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0858" published="1999-12-02" seq="1999-0858" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5 allows a remote attacker to modify the IE client&apos;s proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3666.php">ie-wpad-proxy-settings(3666)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/846">BID 846</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-054.asp">MS99-054</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-054.asp">MS99-054</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-054.mspx">MS99-054</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q247333">Q247333</ref><ref source="BID" url="http://www.securityfocus.com/bid/846">846</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0859" published="1999-12-01" seq="1999-0859" severity="Low" type="CVE"><desc><descript source="cve">Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3742.php">sol-arp-parse(3742)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/837">BID 837</ref><ref source="BID" url="http://www.securityfocus.com/bid/837">837</ref><ref source="OSVDB" url="http://www.osvdb.org/6994">6994</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86HW5" num="2.6"/><vers edition="x86HW3" num="2.6"/><vers edition="x86" num="2.6"/><vers edition="HW5" num="2.6"/><vers edition="HW3" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0860" published="1999-12-01" seq="1999-0860" severity="Low" type="CVE"><desc><descript source="cve">Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3743.php">sol-chkperm-vmsys</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D837">Solaris arp Vulnerabilities</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-29%26msg%3D19991130224559.873.qmail@nw175.netaddress.usa.net">Solaris 2.x chkperm/arp vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/837">837</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86HW5" num="2.6"/><vers edition="x86HW3" num="2.6"/><vers edition="x86" num="2.6"/><vers edition="HW5" num="2.6"/><vers edition="HW3" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0861" published="1999-08-11" seq="1999-0861" severity="Low" type="CVE"><desc><descript source="cve">Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-053.asp">MS99-053</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3646.php">iis-ssl-isapi-filter(3646)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-053.mspx">MS99-053</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q244613">Q244613</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Commercial Internet System" vendor="Microsoft"><vers num="2.5"/><vers num="2.0"/></prod><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/><vers num="Commerce 3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0862" published="1999-12-02" seq="1999-0862" severity="Low" type="CVE"><desc><descript source="cve">Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3744.php">postgresql-insecure-perms</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-29%26msg%3D3846E7B2.73FC6B19@wgcr.org">PostgreSQL RPM&apos;s permission problems</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="6.5.3.1"/><vers num="6.5.3"/><vers num="6.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0863" published="1999-11-08" seq="1999-0863" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D838">FreeBSD Seyon setgid dialer Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-9.php">freebsd-seyon-dir-add</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-8%26msg%3D19991109035038.4631.qmail@www0h.netaddress.usa.net">FreeBSD 3.3&apos;s seyon vulnerability</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0864" published="1999-12-03" seq="1999-0864" severity="High" type="CVE"><desc><descript source="cve">UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3637.php">sco-coredump-symlink(3637)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/851">BID 851</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991203020720.13115.qmail@nwcst289.netaddress.usa.net">19991202 UnixWare coredumps follow symlinks</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref><ref source="BID" url="http://www.securityfocus.com/bid/851">851</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1"/><vers num="7.0.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0865" published="1999-12-03" seq="1999-0865" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3746.php">communigate-pro-bo(3746)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/860">BID 860</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94426440413027&amp;w=2">19991203 CommuniGatePro 3.1 for NT DoS</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94454565726775&amp;w=2">19991203 CommuniGatePro 3.1 for NT Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/860">860</ref></refs><vuln_soft><prod name="Communigate Pro" vendor="Stalker"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0866" published="1999-12-03" seq="1999-0866" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in UnixWare xauto program allows local users to gain root privilege.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3635.php">sco-xauto-bo(3635)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/848">BID 848</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94581379905584&amp;w=2">19991220 SCO OpenServer Security Status</ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.24a">SB-99.24a</ref><ref source="BID" url="http://www.securityfocus.com/bid/848">848</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1"/><vers num="7.0.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0867" published="1999-08-11" seq="1999-0867" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3115.php">http-iis-malformed-header(3115)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/579">BID 579</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-029.asp">MS99-029</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-029.asp">MS99-029</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-029.mspx">MS99-029</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238349">Q238349</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-058.shtml">J-058</ref><ref source="BID" url="http://www.securityfocus.com/bid/579">579</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Commercial Internet System" vendor="Microsoft"><vers num="2.5"/><vers num="2.0"/></prod><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/><vers num="Commerce 3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0868" published="1997-02-20" seq="1999-0868" severity="High" type="CVE"><desc><descript source="cve">ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.08.innd.html">CA-97.08.innd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3701.php">inn-ucbmail-shell-meta(3701)</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="1.5.1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.0"/><vers num="4.1"/></prod><prod name="Goah_NetworkSV" vendor="NEC"><vers num="R1.2"/><vers num="R2.2"/><vers num="R3.1"/></prod><prod name="SPARC" vendor="Sun"><vers num=""/></prod><prod name="News Server" vendor="Netscape"><vers num="1.1"/></prod><prod name="Goah_IntraSV" vendor="NEC"><vers num="R1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0869" published="1998-12-01" seq="1999-0869" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.</descript></desc><loss_types><conf/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1598.php">http-frame-spoof(1598)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms98-020.asp">MS98-020</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-020.mspx">MS98-020</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0.0"/><vers num="3.0.0.2"/><vers num="3.0.01"/><vers num="3.0.2"/><vers num="4.0"/><vers num="4.0.0.1"/></prod><prod name="Navigator" vendor="Netscape"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0870" published="1998-10-01" seq="1999-0870" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2213.php">ie-usp-cuartango(2213)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms98-015.asp">MS98-015</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-015.mspx">MS98-015</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0.1"/><vers num="4.0.0.1SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0871" published="1998-09-04" seq="1999-0871" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE&apos;s cross frame security, aka the &quot;Cross Frame Navigate&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3668.php">ie-crossframe-file-read(3668)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms98-013.asp">MS98-013</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-013.mspx">MS98-013</ref><ref source="OSVDB" url="http://www.osvdb.org/7837">7837</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3668">ie-crossframe-file-read(3668)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0"/><vers num="4.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-1999-0872" published="1999-08-25" seq="1999-0872" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D611">Vixie Cron MAILTO Sendmail Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4096.php">cron-sendmail-bo-root(4096)</ref><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/mailing-lists/redhat-watch-list/1999-8/msg00006.html">Buffer overflow in cron daemon</ref><ref adv="1" patch="1" source="Suse" url="http://www.suse.de/de/support/security/suse_security_announce_15.txt">cron-3.0.1-75 (Vixie Cron)</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/1999/19990830">cron: Root exploit in cron</ref><ref source="BID" url="http://www.securityfocus.com/bid/759">759</ref><ref source="BID" url="http://www.securityfocus.com/bid/611">611</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/><vers edition="i386" num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="Vixie Cron" vendor="Paul Vixie"><vers num="3.0 pl1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="2.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0873" published="1999-10-30" seq="1999-0873" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Skyfull mail server via MAIL FROM command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=759">Skyfull Mail Server MAIL FROM Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3430.php">skyfull-mail-from-bo(3430)</ref><ref source="BID" url="http://www.securityfocus.com/bid/759">759</ref></refs><vuln_soft><prod name="Skyfull" vendor="Sky Communications"><vers num="1.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0874" published="1999-06-16" seq="1999-0874" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2281.php">iis-htr-overflow(2281)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-07-IIS-Buffer-Overflow.html">CA-99-07-IIS-Buffer-Overflow</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-019.asp">MS99-019</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q234905">Q234905</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD06081999.html">AD06081999</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-048.shtml">J-048</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:915">oval:org.mitre.oval:def:915</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0875" published="1999-08-11" seq="1999-0875" severity="Medium" type="CVE"><desc><descript source="cve">DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3123.php">irdp-gateway-spoof(3123)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/578">BID 578</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q216141">Q216141</ref><ref source="BID" url="http://www.securityfocus.com/bid/578">578</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="0b"/><vers num="0a"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-21" name="CVE-1999-0876" published="2000-01-04" seq="1999-0876" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Internet Explorer 4.0 via EMBED tag.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q185/9/59.ASP">Description of Internet Explorer 4.01 Service Pack 1</ref><ref source="SF" url="http://www.securityfocus.com/bid/76">Microsoft Internet Explorer EMBED Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/916">Internet Explorer Embed issue</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q185959">Q185959</ref><ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp">Q176697</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.1"/><vers num="4.0"/><vers edition="a" num="4.0"/><vers edition="Mac OS" num="3.1"/><vers edition="Mac OS" num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0877" published="1999-10-01" seq="1999-0877" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.</descript></desc><loss_types><conf/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3313.php">ie-iframe-exec(3313)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-042.asp">MS99-042</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q243638">Q243638</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-042.mspx">MS99-042</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num=""/><vers num="4.0"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.1"/><vers num="5.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0878" published="1999-08-22" seq="1999-0878" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-13-wuftpd.html">CA-99-13-wuftpd</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/599">BID 599</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3158.php">wu-ftpd-dir-name(3158)</ref><ref source="BID" url="http://www.securityfocus.com/bid/599">599</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.5"/><vers num="2.4.2 VR17"/><vers num="2.4.2 VR16"/><vers num="2.4.2 Beta18 VR9"/><vers num="2.4.2 Beta18 VR8"/><vers num="2.4.2 Beta18 VR6"/><vers num="2.4.2 Beta18 VR5"/><vers num="2.4.2 Beta18 VR4"/><vers num="2.4.2 Beta18 VR15"/><vers num="2.4.2 Beta18 VR14"/><vers num="2.4.2 Beta18 VR13"/><vers num="2.4.2 Beta18 VR12"/><vers num="2.4.2 Beta18 VR11"/><vers num="2.4.2 Beta18 VR10"/></prod><prod name="BeroFTPD" vendor="BeroFTPD"><vers num="1.3.4"/><vers num="1.3.3"/><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0879" published="1999-10-01" seq="1999-0879" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-13-wuftpd.html">CA-99-13-wuftpd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3375.php">wuftp-message-file-root(3375)</ref></refs><vuln_soft><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="3.0"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0880" published="1999-10-01" seq="1999-0880" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-13-wuftpd.html">CA-99-13-wuftpd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3376.php">wuftp-site-newer-dos(3376)</ref></refs><vuln_soft><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="3.0"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0881" published="1999-10-26" seq="1999-0881" severity="Medium" type="CVE"><desc><descript source="cve">Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3386.php">falcon-path-parsing(3386)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/743">BID 743</ref><ref source="BID" url="http://www.securityfocus.com/bid/743">743</ref><ref source="OSVDB" url="http://www.osvdb.org/1127">1127</ref></refs><vuln_soft><prod name="Falcon Web Server" vendor="BlueFace"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0882" published="1999-10-28" seq="1999-0882" severity="Medium" type="CVE"><desc><descript source="cve">Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3832.php">falcon-server-long-filename(3832)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-10-22%26msg%3D19991026114331.A88781@pueblo.netect.com">Falcon Web Server</ref><ref adv="1" patch="1" source="BindView" url="http://www.bindview.com/security/advisory/adv_falcon.html">Falcon Web Server Technical Advisory</ref></refs><vuln_soft><prod name="Falcon Web Server" vendor="Falcon"><vers num="1.0.0.1006"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0883" published="1999-10-25" seq="1999-0883" severity="High" type="CVE"><desc><descript source="cve">Zeus web server allows remote attackers to read arbitrary files by specifying the file name in an option to the search engine.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-10-22&amp;msg=Pine.LNX.4.10.9910250755360.23584-100000@7of9.neohapsis.com"></ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/742">BID 742</ref><ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref><ref source="OSVDB" url="http://www.osvdb.org/1126">1126</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3380">zeus-remote-root(3380)</ref></refs><vuln_soft><prod name="Zeus Web Server" vendor="Zeus Technologies"><vers num="3.3.2"/><vers num="3.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0884" published="1999-10-25" seq="1999-0884" severity="Medium" type="CVE"><desc><descript source="cve">The Zeus web server administrative interface uses weak encryption for its passwords.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/742">BID 742</ref><ref source="BID" url="http://www.securityfocus.com/bid/742">742</ref><ref source="OSVDB" url="http://www.osvdb.org/8186">8186</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3833">zeus-weak-password(3833)</ref></refs><vuln_soft><prod name="Zeus Web Server" vendor="Zeus Technologies"><vers num="3.3.2"/><vers num="3.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0885" published="1999-11-03" seq="1999-0885" severity="Low" type="CVE"><desc><descript source="cve">Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-01%26msg%3D01BF261F.928821E0.kerb@fnusa.com">More Alibaba Web Server problems</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D770">Alibaba Multiple CGI Vulnerabilties</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3454.php">alibaba-url-file-manipulation</ref><ref source="BID" url="http://www.securityfocus.com/bid/770">770</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-11-01&amp;msg=01BF261F.928821E0.kerb@fnusa.com">19991103 More Alibaba Web Server problems...</ref></refs><vuln_soft><prod name="Alibaba" vendor="Computer Software Manufaktur"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0886" published="1999-09-17" seq="1999-0886" severity="High" type="CVE"><desc><descript source="cve">The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/645">BID 645</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-041.asp">MS99-041</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3248.php">nt-rasman-pathname(3248)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q242294">Q242294</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-041.mspx">MS99-041</ref><ref source="BID" url="http://www.securityfocus.com/bid/645">645</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0887" published="1999-11-04" seq="1999-0887" severity="Medium" type="CVE"><desc><descript source="cve">FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/772">BID 772</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref><ref source="OSVDB" url="http://www.osvdb.org/1137">1137</ref></refs><vuln_soft><prod name="FTGate" vendor="Floosietek"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0888" published="1999-08-16" seq="1999-0888" severity="Medium" type="CVE"><desc><descript source="cve">dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/585">BID 585</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-7.phporacle-dbsnmp">oracle-dbsnmp</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise35.php"></ref><ref source="BID" url="http://www.securityfocus.com/bid/585">585</ref></refs><vuln_soft><prod name="Oracle7i" vendor="Oracle"><vers num="7.3.4"/><vers num="7.3.3"/></prod><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.5"/><vers num="8.0.5.1"/><vers num="8.0.5"/><vers num="8.0.4"/><vers num="8.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0889" published="1999-07-01" seq="1999-0889" severity="High" type="CVE"><desc><descript source="cve">Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4251.php">cisco-cbos-telnet(4251)</ref><ref source="OSVDB" url="http://www.osvdb.org/39">39</ref></refs><vuln_soft><prod name="Cisco 675 Router" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-21" name="CVE-1999-0890" published="1999-09-16" seq="1999-0890" severity="High" type="CVE"><desc><descript source="cve">iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/><config/><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3273.php">ihtml-merchant-file-access(3273)</ref><ref patch="1" source="iHTML" url="http://www.ihtmlmerchant.com/support_patches_feedback.htm"></ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-09-22&amp;msg=006e01bf0a16$e3c59bc0$665e163f@default">19990928 Team Asylum: iHTML Merchant Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/694">694</ref></refs><vuln_soft><prod name="iHTML Merchant" vendor="iHTML Merchant"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0891" published="1999-09-01" seq="1999-0891" severity="Low" type="CVE"><desc><descript source="cve">The &quot;download behavior&quot; in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.</descript></desc><loss_types><conf/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3278.php">ie-download-behavior(3278)</ref><ref adv="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-040.asp">MS99-040</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-040.mspx">MS99-040</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q242542">Q242542</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/37828">VU#37828</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-002.shtml">K-002</ref><ref source="BID" url="http://www.securityfocus.com/bid/674">674</ref><ref source="OSVDB" url="http://www.osvdb.org/11274">11274</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0892" published="1999-12-24" seq="1999-0892" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/893">BID 893</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0893" published="1999-10-11" seq="1999-0893" severity="Low" type="CVE"><desc><descript source="cve">userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3368.php">sco-openserver-userosa-script(3368)</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0894" published="2000-01-04" seq="1999-0894" severity="High" type="CVE"><desc><descript source="cve">Red Hat Linux screen program does not use Unix98 ptys, allowing local users to write to other terminals.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-1999-0895" published="1999-10-20" seq="1999-0895" severity="High" type="CVE"><desc><descript source="cve">Firewall-1 does not properly restrict access to LDAP attributes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/725">BID 725</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3374.php">checkpoint-ldap-auth(3374)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19991020150002.21047.qmail@tarjan.mediaways.net">19991020 Checkpoint FireWall-1 V4.0: possible bug in LDAP authentication</ref><ref source="BID" url="http://www.securityfocus.com/bid/725">725</ref><ref source="OSVDB" url="http://www.osvdb.org/1117">1117</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-1999-0896" published="1999-11-04" seq="1999-0896" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3448.php">realserver-g2-pw-bo(3448)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/767">BID 767</ref><ref source="MISC" url="http://service.real.com/help/faq/servg260.html">http://service.real.com/help/faq/servg260.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/767">767</ref></refs><vuln_soft><prod name="RealServer G2" vendor="RealNetworks"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0897" published="1998-09-09" seq="1999-0897" severity="Medium" type="CVE"><desc><descript source="cve">iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=1998-09-8&amp;msg=35F70CFF.1957B819@ocol.com">BUGTRAQ:19980908 bug in iChat 3.0 (maybe others)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1623.php">ichat-file-read-vuln(1623)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90538488231977&amp;w=2">19980908 bug in iChat 3.0 (maybe others)</ref></refs><vuln_soft><prod name="iChat ROOMS Server" vendor="Apple"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0898" published="1999-11-04" seq="1999-0898" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-047.asp">MS99-047</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/768">BID 768</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3457.php">nt-printer-spooler-bo(3457)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx">MS99-047</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q243649">Q243649</ref><ref source="BID" url="http://www.securityfocus.com/bid/768">768</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0899" published="1999-11-04" seq="1999-0899" severity="High" type="CVE"><desc><descript source="cve">The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-047.asp">MS99-047</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/769">BID 769</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3457.php">nt-printer-spooler-bo(3457)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-047.mspx">MS99-047</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q243649">Q243649</ref><ref source="BID" url="http://www.securityfocus.com/bid/769">769</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0900" published="1999-10-23" seq="1999-0900" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA1999046-01.html">RHSA1999046-01</ref></refs><vuln_soft><prod name="rpc.yppasswdd" vendor="Linux NIS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0901" published="1999-10-23" seq="1999-0901" severity="High" type="CVE"><desc><descript source="cve">ypserv allows a local user to modify the GECOS and login shells of other users.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA1999046-01.html">REDHAT:RHSA1999046-01</ref></refs><vuln_soft><prod name="ypserv" vendor="Linux NIS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0902" published="1999-10-23" seq="1999-0902" severity="High" type="CVE"><desc><descript source="cve">ypserv allows local administrators to modify password tables.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA1999046-01.html">REDHAT:RHSA1999046-01</ref></refs><vuln_soft><prod name="ypserv" vendor="Linux NIS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0903" published="1999-10-26" seq="1999-0903" severity="High" type="CVE"><desc><descript source="cve">genfilt in the AIX Packet Filtering Module does not properly filter traffic to destination ports greater than 32767.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/744">BID 744</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0904" published="1999-11-03" seq="1999-0904" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D771">Byte Fusion BFTelnet Long Username DoS Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3455.php">bftelnet-username-dos(3455)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-10-29%26msg%3DNCBBKFKDOLAGKIAPMILPIEIGCAAA.labs@ussrback.com">Remote DoS Attack in BFTelnet Server v1.1 for Windows NT</ref><ref source="BID" url="http://www.securityfocus.com/bid/771">771</ref></refs><vuln_soft><prod name="BFTelnet" vendor="Byte Fusion"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0905" published="1999-10-21" seq="1999-0905" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Axent Raptor firewall via malformed zero-length IP options.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3350.php">raptor-ipoptions-dos(3350)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/736">BID 736</ref><ref source="BID" url="http://www.securityfocus.com/bid/736">736</ref><ref source="OSVDB" url="http://www.osvdb.org/1121">1121</ref></refs><vuln_soft><prod name="Raptor Firewall" vendor="Axent"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0906" published="1999-09-23" seq="1999-0906" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/656">BID 656</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4114.php">linux-sccw-bo(4114)</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=05af01bf05fa$650da860$3177a8c0@webley"></ref><ref source="BID" url="http://www.securityfocus.com/bid/656">656</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0907" published="1999-09-16" seq="1999-0907" severity="Low" type="CVE"><desc><descript source="cve">sccw allows local users to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-09-15&amp;msg=043101bf00a3$8088c720$3177a8c0@webley">BUGTRAQ:19990916 SuSE 6.2 /usr/bin/sccw read any file</ref></refs><vuln_soft><prod name="Soundcard CW" vendor="Steven J. Merrifield"><vers edition="Linux" num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0908" published="1999-09-23" seq="1999-0908" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.GSO.3.96.990922114237.12398A-100000@goju.Stanford.EDU">19990921 solaris DoS</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3307.php">sun-tcp-mutex-enter-dos(3307)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/655">BID 655</ref><ref patch="1" source="SunSolve" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=patchrpts%2F2.6&amp;zone_32=Sun%20BugID%204178455">Sun BugID 4178455</ref><ref source="BID" url="http://www.securityfocus.com/bid/655">655</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0909" published="1999-09-20" seq="1999-0909" severity="High" type="CVE"><desc><descript source="cve">Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the &quot;Spoofed Route Pointer&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/646">BID 646</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3251.php">nt-ip-source-route(3251)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-038.asp">MS99-038</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-038.asp">MS99-038</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-038.mspx">MS99-038</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238453">Q238453</ref><ref source="BID" url="http://www.securityfocus.com/bid/646">646</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="0b"/><vers num="0a"/></prod><prod name="Terminal Server" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0910" published="1999-09-10" seq="1999-0910" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-035.asp">Patch Available for </ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=625">Microsoft Site Server and CIS Cookie Caching Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3228.php">siteserver-cis-cookie-cache(3228)</ref><ref source="BID" url="http://www.securityfocus.com/bid/625">625</ref></refs><vuln_soft><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/><vers num="Commerce 3.0 alpha"/></prod><prod name="Commercial Internet System" vendor="Microsoft"><vers num="2.5"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0911" published="1999-08-27" seq="1999-0911" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=612">ProFTPD Remote Buffer Overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3399.php">proftpd-long-dir-bo(3399)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.9909071813590.3522-200000@prof.fr.nessus.org">ProFTP-1.2.0pre4 buffer overflow -- once more</ref><ref source="DEBIAN" url="http://www.debian.org/security/1999/19990210">19990210</ref><ref source="BID" url="http://www.securityfocus.com/bid/612">612</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.2 pre5"/><vers num="1.2 pre4"/><vers num="1.2 pre3"/><vers num="1.2 pre2"/><vers num="1.2 pre1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0912" published="1999-09-22" seq="1999-0912" severity="Low" type="CVE"><desc><descript source="cve">FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=653">FreeBSD vfs_cache Denial of Service Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3441.php">freebsd-vfscache-dos(3441)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-09-15%26msg%3D199909211950.PAA09009@bill-the-cat.mit.edu">FreeBSD-specific denial of service</ref><ref source="BID" url="http://www.securityfocus.com/bid/653">653</ref><ref source="OSVDB" url="http://www.osvdb.org/1079">1079</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0913" published="1999-08-05" seq="1999-0913" severity="High" type="CVE"><desc><descript source="cve">dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=564">Dragon-Fire IDS Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3834.php">dragon-fire-ids-metachar(3834)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-08-1%26msg%3D19990804183220.A10986@asit.ro">NSW Dragon Fire gets drowned</ref><ref source="BID" url="http://www.securityfocus.com/bid/564">564</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93383593909438&amp;w=2">19990804 NSW Dragon Fire gets drowned</ref></refs><vuln_soft><prod name="Dragon-Fire IDS" vendor="Network Security Wizards"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0914" published="1999-01-03" seq="1999-0914" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/324">BID 324</ref><ref source="BID" url="http://www.securityfocus.com/bid/324">324</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0915" published="1999-10-28" seq="1999-0915" severity="Medium" type="CVE"><desc><descript source="cve">URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/746">BID 746</ref><ref source="BID" url="http://www.securityfocus.com/bid/746">746</ref><ref source="OSVDB" url="http://www.osvdb.org/1129">1129</ref></refs><vuln_soft><prod name="URL Live" vendor="Pacific Software"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-24" name="CVE-1999-0916" published="1999-06-29" seq="1999-0916" severity="Low" type="CVE"><desc><descript source="cve">WebTrends software stores account names and passwords in a file which does not have restricted access permissions.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise29.php">Bad Permissions on Passwords Stored by WebTrends Software</ref></refs><vuln_soft><prod name="WebTrends Security Analyzer" vendor="WebTrends"><vers num="v2.0"/></prod><prod name="WebTrends Log Analyzer" vendor="WebTrends"><vers num="v4.51"/></prod><prod name="WebTrends for Firewalls" vendor="WebTrends"><vers num="v1.2"/></prod><prod name="WebTrends Enterprise Suite" vendor="WebTrends"><vers num="v3.5"/></prod><prod name="WebTrends Professional Suite" vendor="WebTrends"><vers num="v3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0917" published="1999-05-27" seq="1999-0917" severity="Medium" type="CVE"><desc><descript source="cve">The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3526.php">legacy-activex-local-drive(3526)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-018.asp">MS99-018</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-018.mspx">MS99-018</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q231452">Q231452</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0918" published="1999-07-03" seq="1999-0918" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in various Windows systems via malformed, fragmented IGMP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/advisory.html?id=1733">BUGTRAQ:19990703 IGMP fragmentation bug in Windows 98/2000</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/514">BID 514</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2341.php">igmp-dos(2341)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238329">Q238329</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-034.mspx">MS99-034</ref><ref source="BID" url="http://www.securityfocus.com/bid/514">514</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0919" published="1998-05-10" seq="1999-0919" severity="High" type="CVE"><desc><descript source="cve">A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2004.php">motorola-cable-crash(2004)</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9805B&amp;L=bugtraq&amp;P=R1621">Security Vulnerability in Motorola CableRouters</ref></refs><vuln_soft><prod name="Motorola CableRouter" vendor="Motorola"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0920" published="1999-05-26" seq="1999-0920" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><env/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-05-22&amp;msg=Pine.LNX.3.96.990526202259.4439A-100000@ferret.lmh.ox.ac.uk"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3114.php">pop2-fold-bo(3114)</ref><ref source="BID" url="http://www.securityfocus.com/bid/283">283</ref></refs><vuln_soft><prod name="pop2d" vendor="University of Washington"><vers num=""/></prod><prod name="IMAP" vendor="University of Washington"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0921" published="1999-04-01" seq="1999-0921" severity="Medium" type="CVE"><desc><descript source="cve">BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4291.php">bmc-patrol-udp-dos(4291)</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904b&amp;L=bugtraq&amp;F=&amp;S=&amp;P=3253">Patrol security bugs</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref><ref source="XF" url="http://www.iss.net/security_center/static/4291.php">bmc-patrol-udp-dos(4291)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1879">1879</ref></refs><vuln_soft><prod name="PATROL Agent" vendor="BMC Software"><vers num="3.25"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0922" published="2001-03-12" seq="1999-0922" severity="Medium" type="CVE"><desc><descript source="cve">An example application in ColdFusion Server 4.0 allows remote attackers to view source code via the sourcewindow.cfm file.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1744.php">coldfusion-sourcewindow(1744)</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0923" published="2001-03-12" seq="1999-0923" severity="High" type="CVE"><desc><descript source="cve">Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0924" published="2001-03-12" seq="1999-0924" severity="Medium" type="CVE"><desc><descript source="cve">The Syntax Checker in ColdFusion Server 4.0 allows remote attackers to conduct a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=8739&amp;Method=Full">ASB99-02</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1742">coldfusion-syntax-checker(1742)</ref><ref source="OSVDB" url="http://www.osvdb.org/3236">3236</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0925" published="1999-09-03" seq="1999-0925" severity="Medium" type="CVE"><desc><descript source="cve">UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1630.php">unitymail-web-dos(1630)</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9809A&amp;L=bugtraq&amp;P=R2611">Re: Web servers / possible DOS Attack / mime header flooding</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90486243124867&amp;w=2">19980903 Web servers / possible DOS Attack / mime header flooding</ref></refs><vuln_soft><prod name="UnityMail" vendor="MessageMedia"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0926" published="1999-09-03" seq="1999-0926" severity="High" type="CVE"><desc><descript source="cve">Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html"></ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0927" published="1999-05-26" seq="1999-0927" severity="Medium" type="CVE"><desc><descript source="cve">NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2242.php">ntmail-fileread(2242)</ref><ref adv="1" source="eEye Digital Security" url="http://www.eeye.com/database/advisories/ad05261999/ad05261999.html">Multiple Web Interface Security Holes</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD05261999.html">AD05261999</ref><ref source="BID" url="http://www.securityfocus.com/bid/279">279</ref></refs><vuln_soft><prod name="NTMail" vendor="Gordano"><vers num="4.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0928" published="1999-05-23" seq="1999-0928" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2280.php">websuite-dos(2280)</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9905d&amp;L=bugtraq&amp;F=&amp;S=&amp;P=4720">Buffer overflow in SmartDesk WebSuite v2.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/278">278</ref></refs><vuln_soft><prod name="WebSuite" vendor="SmartDesk"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0929" published="1999-06-16" seq="1999-0929" severity="Medium" type="CVE"><desc><descript source="cve">Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2287.php">novell-webserver-dos(2287)</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9906c&amp;L=bugtraq&amp;F=&amp;S=&amp;P=835">Novell NetWare webservers DoS</ref></refs><vuln_soft><prod name="Novell-HTTP-Server" vendor="Novell"><vers num="2.51R1"/><vers num="3.1R1"/></prod><prod name="NetWare" vendor="Novell"><vers num="4.1"/><vers num="4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0930" published="1998-09-03" seq="1999-0930" severity="Medium" type="CVE"><desc><descript source="cve">wwwboard allows a remote attacker to delete message board articles via a malformed argument.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-8.phphttp-cgi-wwwboard-default">http-cgi-wwwboard-default</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1998-09-01%26msg%3DPine.LNX.3.95.980903131812.32457A-100000@ankh.samiam.org">wwwboard.pl vulnerability</ref><ref source="CONFIRM" url="http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml">http://www.worldwidemart.com/scripts/faq/wwwboard/q5.shtml</ref><ref source="XF" url="http://xforce.iss.net/static/2344.php">http-cgi-wwwboard(2344)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1795">1795</ref></refs><vuln_soft><prod name="WWWBoard" vendor="Matt Wright"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0931" published="1999-09-30" seq="1999-0931" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/734">BID 734</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3286.php">mediahouse-stats-login-bo(3286)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-09-29&amp;msg=19990930212145.23696.qmail@securityfocus.com">BUGTRAQ:19990930 Security flaw in Mediahouse Statistics Server v4.28 &amp; 5.01</ref><ref source="BID" url="http://www.securityfocus.com/bid/734">734</ref></refs><vuln_soft><prod name="Statistics Server" vendor="Mediahouse Software"><vers num="4.28"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0932" published="1999-09-30" seq="1999-0932" severity="High" type="CVE"><desc><descript source="cve">Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-8.php">mediahouse-stats-adminpw-cleartext</ref><ref adv="1" patch="1" source="BigBrother" url="http://w1.855.telia.com/~u85513179/security/exploits/mediahouse/index.html">Mediahouse Statistics Server 4.28 &amp; 5.01</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=735">Mediahouse Statistics Server Cleartext Password Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/735">735</ref></refs><vuln_soft><prod name="Statistics Server" vendor="Mediahouse Software"><vers num="5.1"/><vers num="4.28"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0933" published="1999-10-01" seq="1999-0933" severity="Medium" type="CVE"><desc><descript source="cve">TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/689">BID 689</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-09-29&amp;msg=Pine.LNX.4.10.9910020509150.27879-100000@7of9.neohapsis.com">BUGTRAQ:19991001 RFP9904</ref><ref source="BID" url="http://www.securityfocus.com/bid/689">689</ref><ref source="OSVDB" url="http://www.osvdb.org/1096">1096</ref></refs><vuln_soft><prod name="TeamTrack" vendor="TeamShare"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0934" published="1999-12-15" seq="1999-0934" severity="Medium" type="CVE"><desc><descript source="cve">classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/2020">2020</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3102">http-cgi-classifieds-read(3102)</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0935" published="1999-12-15" seq="1999-0935" severity="High" type="CVE"><desc><descript source="cve">classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0936" published="1998-12-03" seq="1999-0936" severity="High" type="CVE"><desc><descript source="cve">BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0937" published="1998-12-03" seq="1999-0937" severity="High" type="CVE"><desc><descript source="cve">BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0938" published="1999-06-28" seq="1999-0938" severity="High" type="CVE"><desc><descript source="cve">MBone SDR Package allows remote attackers to execute commands via shell metacharacters in Sesion Initiation Protocol (SIP) messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vul_notes/VN-99-03.html">CERT:VN-99-03,XF:sdr-execute</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2338.php">sdr-execute(2338)</ref></refs><vuln_soft><prod name="SDR" vendor="University College London"><vers num="2.6.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0939" published="1999-08-26" seq="1999-0939" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Debian IRC Epic/epic4 client via a long string.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/605">BID 605</ref><ref source="BID" url="http://www.securityfocus.com/bid/605">605</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2 pre potato"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0940" published="1999-09-27" seq="1999-0940" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="Mutt Mail Client" vendor="Mutt"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0941" published="1998-07-28" seq="1999-0941" severity="High" type="CVE"><desc><descript source="cve">Mutt mail client allows a remote attacker to execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19990925093902.A2741@sobolev.rhein.de">mutt-1.0pre3 is out / security fix</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3315.php">mutt-text-enriched-mime-bo(3315)</ref><ref adv="1" patch="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526154&amp;w=2">mutt x.x</ref></refs><vuln_soft><prod name="Mutt" vendor="Mutt"><vers num="0.95.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0942" published="1999-10-04" seq="1999-0942" severity="High" type="CVE"><desc><descript source="cve">UnixWare dos7utils allows a local user to gain root privileges by using the STATICMERGE environmental variable to find a script which it executes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3360.php">sco-unixware-dos7utils-root-privs(3360)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-09-29%26msg%3D19991005183049.1722.qmail@www0r.netaddress.usa.net">SCO UnixWare 7.1 local root exploit</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0943" published="1999-10-15" seq="1999-0943" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-10-15&amp;msg=Pine.SGI.4.05.9910151747150.644081-100000@tiger.coe.missouri.edu">BUGTRAQ:19991015 OpenLink 3.2 Advisory</ref><ref source="BID" url="http://www.securityfocus.com/bid/720">720</ref></refs><vuln_soft><prod name="OpenLink" vendor="OpenLink"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0944" published="1999-10-24" seq="1999-0944" severity="High" type="CVE"><desc><descript source="cve">IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-1999-0945" published="2001-03-12" seq="1999-0945" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or AUTHINFO commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise4.php">19980724 Denial of Service attacks against Microsoft Exchange 5.0 to 5.5</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-080.shtml">I-080</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q169174">Q169174</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1223">exchange-dos(1223)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0946" published="1999-11-02" seq="1999-0946" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=760">Microsoft IE Yamaha MidiPlug Buffer Overflow Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D381EE9AC140.6668SHADOWPENGUIN@fox.nightland.net">Some holes for Win/UNIX softwares</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref><ref source="BID" url="http://www.securityfocus.com/bid/760">760</ref></refs><vuln_soft><prod name="MidiPlug" vendor="Yamaha"><vers num="1.1bj"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0947" published="1999-11-02" seq="1999-0947" severity="High" type="CVE"><desc><descript source="cve">AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/762">BID 762</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2">19991102 Some holes for Win/UNIX softwares</ref><ref source="BID" url="http://www.securityfocus.com/bid/762">762</ref></refs><vuln_soft><prod name="AN-HTTPD" vendor="AN"><vers num="1.2b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0948" published="1999-11-02" seq="1999-0948" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in uum program for Canna input system allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D757">Canna subsystem &apos;uum&apos; Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3424.php">canna-uum-bo(3424)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D381EE9AC140.6668SHADOWPENGUIN@fox.nightland.net">Some holes for Win/UNIX softwares</ref><ref source="BID" url="http://www.securityfocus.com/bid/757">757</ref></refs><vuln_soft><prod name="Turbolinux" vendor="TurboLinux"><vers num="4.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0949" published="1999-11-02" seq="1999-0949" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D757">Canna subsystem &apos;uum&apos; Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3424.php">canna-uum-bo(3424)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D381EE9AC140.6668SHADOWPENGUIN@fox.nightland.net">Some holes for Win/UNIX softwares</ref><ref source="BID" url="http://www.securityfocus.com/bid/757">757</ref></refs><vuln_soft><prod name="Turbolinux" vendor="TurboLinux"><vers num="4.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0950" published="1999-10-28" seq="1999-0950" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via	a series of MKD and CWD commands that create nested directories.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/747">BID 747</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3417.php">wftpd-mkd-bo(3417)</ref><ref source="BID" url="http://www.securityfocus.com/bid/747">747</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="2.40"/><vers num="2.34"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0951" published="1999-10-22" seq="1999-0951" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/739">BID 739</ref><ref source="BID" url="http://www.securityfocus.com/bid/739">739</ref><ref source="OSVDB" url="http://www.osvdb.org/3380">3380</ref></refs><vuln_soft><prod name="OmniHTTPD" vendor="Omnicron"><vers num="2.4Pro"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0952" published="1999-01-28" seq="1999-0952" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91759216618637&amp;w=2">Re: Buffer overflow in Solaris 2.6/2.7 /usr/bin/lpstat</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4115.php">solaris-lpstat-bo(4115)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-01-22%26msg%3DPine.GSO.4.05.9901261448100.548-200000@gorkie">Buffer overflow in Solaris 2.6/2.7 /usr/bin/lpstat</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0953" published="1999-09-16" seq="1999-0953" severity="High" type="CVE"><desc><descript source="cve">WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-09-15&amp;msg=Pine.LNX.4.10.9909170435200.30548-100000@puffer.quadrunner.com">BUGTRAQ:19980903 wwwboard.pl vulnerability,BUGTRAQ:19990916 More fun with WWWBoard</ref></refs><vuln_soft><prod name="WWWBoard" vendor="Matt Wright"><vers num="2.0 ALPHA 2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0954" published="1999-09-16" seq="1999-0954" severity="High" type="CVE"><desc><descript source="cve">WWWBoard has a default username and default password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=649">WWWBoard Password Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-8.phphttp-cgi-wwwboard-default">http-cgi-wwwboard-default</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.9909170435200.30548-100000@puffer.quadrunner.com">More fun with WWWBoard</ref><ref source="BID" url="http://www.securityfocus.com/bid/649">649</ref></refs><vuln_soft><prod name="WWWBoard" vendor="Matt Wright"><vers num="2.0 Alpha 2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0955" published="1997-09-23" seq="1999-0955" severity="High" type="CVE"><desc><descript source="cve">Race condition in wu-ftpd and BSDI ftpd allows remote attackers gain root access via the SITE EXEC command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="ftp://info.cert.org/pub/cert_advisories/CA-94:08.ftpd.vulnerabilities">CA-94:08.ftpd.vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/55.php">ftp-exec(55)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0956" published="1997-09-19" seq="1999-0956" severity="High" type="CVE"><desc><descript source="cve">The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1993-02.html">CA-93.02a.NeXT.NetInfo._writers.vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/520.php">next-netinfo(520)</ref></refs><vuln_soft><prod name="NeXTstep" vendor="NeXT"><vers num="1.0"/><vers num="1.0a"/><vers num="2.0"/><vers num="2.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0957" published="1997-06-18" seq="1999-0957" severity="Low" type="CVE"><desc><descript source="cve">MajorCool mj_key_cache program allows local users to modify files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=1997-06-15&amp;msg=Pine.OSF.3.95q.970618034823.7309A-100000@octane.dasb.fhda.edu"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1626.php">majorcool-file-overwrite-vuln(1626)</ref></refs><vuln_soft><prod name="MajorCool" vendor="Great Circle Associates"><vers num="1.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0958" published="1998-01-12" seq="1999-0958" severity="High" type="CVE"><desc><descript source="cve">sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=1998-01-8&amp;msg=9801121729.AA08545@atlas.cb.lucent.com">BUGTRAQ:19980112 Re: hole in sudo for MP-RAS</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4155.php">sudo-dot-dot-attack(4155)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88465708614896&amp;w=2">19980112 Re: hole in sudo for MP-RAS.</ref></refs><vuln_soft><prod name="Sudo" vendor="Todd Miller"><vers num="1.5.3"/><vers num="1.5.2"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0959" published="1997-02-01" seq="1999-0959" severity="High" type="CVE"><desc><descript source="cve">IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1634.php">irix-startmidi-file-creation(1634)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/469">469</ref><ref source="OSVDB" url="http://www.osvdb.org/8447">8447</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0960" published="1998-03-20" seq="1999-0960" severity="High" type="CVE"><desc><descript source="cve">IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.11.SGI.cdplayer.vul">AUSCERT:AA-96.11,SGI:19980301-01-PX,XF</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1632.php">irix-cdplayer-directory-create(1632)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0961" published="1996-09-21" seq="1999-0961" severity="Medium" type="CVE"><desc><descript source="cve">HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=1996-09-15&amp;msg=3244E32A.6093@pop500.gsfc.nasa.gov">BUGTRAQ:19960921 Vunerability in HP sysdiag ?</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4122.php">hp-sysdiag-symlink(4122)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419906&amp;w=2">19960921 Vunerability in HP sysdiag ?</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.5"/><vers num="9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0962" published="1997-05-14" seq="1999-0962" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.13.HP-UX.passwd.vul">AUSCERT:AA-96.13,HP:HPSBUX9701-045,XF</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3704.php">hp-password-cmd-bo(3704)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9701-045">HPSBUX9701-045</ref><ref source="OSVDB" url="http://www.osvdb.org/6415">6415</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9"/><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0963" published="1999-12-01" seq="1999-0963" severity="High" type="CVE"><desc><descript source="cve">FreeBSD mount_union command allows local users to gain root privileges via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="ftp://info.cert.org/pub/cert_bulletins/VB-96.06.freebsd">VB-96.06.freebsd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3705.php">freebsd-mount-union-root(3705)</ref><ref source="OSVDB" url="http://www.osvdb.org/6088">6088</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0964" published="2000-01-01" seq="1999-0964" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3829.php">freebsd-setlocale-bo(3829)</ref><ref source="OSVDB" url="http://www.osvdb.org/6086">6086</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0965" published="1997-09-19" seq="1999-0965" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in xterm allows local users to modify arbitrary files via the logging option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-93.17.xterm.logging.vulnerability.html">CA-93.17.xterm.logging.vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/550.php">xterm(550)</ref></refs><vuln_soft><prod name="xterm" vendor="X.Org"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-24" name="CVE-1999-0966" published="1997-01-27" seq="1999-0966" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="L0pht" url="http://www.l0pht.com/advisories/getopt.txt">L0PHT:19970127 Solaris libc - getopt(3)</ref><ref adv="1" source="CERT" url="http://www.kb.cert.org/vuls/id/6901">Solaris libc getopt(3) contains buffer overflow</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0967" published="1997-11-01" seq="1999-0967" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="L0pht" url="http://www.l0pht.com/advisories1997.html">L0PHT:19971101 Microsoft Internet Explorer 4.0 Suite</ref></refs><vuln_soft><prod name="Windows Explorer" vendor="Microsoft"><vers num=""/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0968" published="1998-12-26" seq="1999-0968" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-4.phpbnc-proxy-bo">bnc-proxy-bo</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D36849FF4.DD3EAB60@viper.net.au">bnc exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11711">19981226 bnc exploit</ref><ref source="XF" url="http://xforce.iss.net/static/1546.php">bnc-proxy-bo(1546)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1927">1927</ref></refs><vuln_soft><prod name="BNC IRC" vendor="James Seter"><vers num="2.2.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0969" published="1998-09-29" seq="1999-0969" severity="Medium" type="CVE"><desc><descript source="cve">The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1372.php">snork-dos(1372)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms98-014.asp">MS98-014</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-014.mspx">MS98-014</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q193233">Q193233</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0970" published="1999-06-05" seq="1999-0970" severity="Medium" type="CVE"><desc><descript source="cve">The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9906a&amp;L=bugtraq&amp;F=&amp;S=&amp;P=5028">Remote Exploit (Bug) in OmniHTTPd Web Server</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2271.php">omnihttpd-dos(2271)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/14311">19990605 Remote Exploit (Bug) in OmniHTTPd Web Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/1808">1808</ref></refs><vuln_soft><prod name="OmniHTTPD" vendor="Omnicron"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0971" published="1997-07-22" seq="1999-0971" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1893.php">exim-include-overflow(1893)</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9707D&amp;L=bugtraq&amp;P=R365">Security hole in exim 1.62: local root exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7301">19970722 Security hole in exim 1.62: local root exploit</ref></refs><vuln_soft><prod name="Exim" vendor="University of Cambridge"><vers num="1.62" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0972" published="1999-12-09" seq="1999-0972" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Xshipwars xsw program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/863">BID 863</ref><ref source="BID" url="http://www.securityfocus.com/bid/863">863</ref></refs><vuln_soft><prod name="XSHIPWARS" vendor="WolfPack Development"><vers num="1.2.4"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0973" published="1999-12-07" seq="1999-0973" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/858">BID 858</ref><ref source="BID" url="http://www.securityfocus.com/bid/858">858</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0974" published="1999-12-09" seq="1999-0974" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/864">BID  864</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/190">00190</ref><ref source="BID" url="http://www.securityfocus.com/bid/864">864</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0975" published="1999-12-10" seq="1999-0975" severity="Medium" type="CVE"><desc><descript source="cve">The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/868">BID 868</ref><ref source="BID" url="http://www.securityfocus.com/bid/868">868</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0976" published="1999-12-07" seq="1999-0976" severity="Low" type="CVE"><desc><descript source="cve">Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3795.php">sendmail-bi-alias(3795)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/857">bugtraq id 857</ref><ref source="BID" url="http://www.securityfocus.com/bid/857">857</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0977" published="1999-12-10" seq="1999-0977" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/866">BID 866</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-16-sadmind.html">CA-99-16-sadmind</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/191">00191</ref><ref source="BID" url="http://www.securityfocus.com/bid/866">866</ref><ref source="BID" url="http://www.securityfocus.com/bid/2354">2354</ref><ref source="OSVDB" url="http://www.osvdb.org/2558">2558</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0978" published="1999-12-09" seq="1999-0978" severity="High" type="CVE"><desc><descript source="cve">htdig allows remote attackers to execute commands via filenames with shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/867">BID 867</ref><ref source="BID" url="http://www.securityfocus.com/bid/867">867</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0979" published="2000-04-11" seq="1999-0979" severity="High" type="CVE"><desc><descript source="cve">The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/869">bugtraq id 869</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94530783815434&amp;w=2">19991215 Recent postings about SCO UnixWare 7</ref><ref source="BID" url="http://www.securityfocus.com/bid/869">869</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1"/><vers num="7.0.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0980" published="2000-05-16" seq="1999-0980" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource enumeration request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q246/0/45.ASP"></ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/fq99-055.asp">MS99-055</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-055.mspx">MS99-055</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246045">Q246045</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Terminal Server 4.0"/><vers num="Server 4.0"/><vers num="4.0"/><vers num="Enterprise 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0981" published="1999-12-08" seq="1999-0981" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka &quot;Server-side Page Reference Redirect.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-050.asp">MS99-050</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-050.mspx">MS99-050</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246094">Q246094</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0.1"/><vers num="5.0"/><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0982" published="1999-12-05" seq="1999-0982" severity="High" type="CVE"><desc><descript source="cve">The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-01&amp;msg=19991206113245.C29162@cae.wisc.edu"></ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="Beta" num="8.0"/></prod><prod name="Web-Based Enterprise Management" vendor="Sun"><vers num="1.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0983" published="1999-11-09" seq="1999-0983" severity="High" type="CVE"><desc><descript source="cve">Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3798.php">http-cgi-whois-meta(3798)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-8%26msg%3D19991210025310.B82291F23E@lists.securityfocus.com">Whois.cgi - ADVISORY.</ref></refs><vuln_soft><prod name="Whois Lookup" vendor="Internic"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0984" published="1999-11-09" seq="1999-0984" severity="High" type="CVE"><desc><descript source="cve">Matt&apos;s Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3799.php">http-cgi-matts-whois-meta(3799)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-8%26msg%3D19991210025310.B82291F23E@lists.securityfocus.com">Whois.cgi - ADVISORY.</ref></refs><vuln_soft><prod name="Matts Whois" vendor="Matts Whois"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0985" published="1999-11-09" seq="1999-0985" severity="High" type="CVE"><desc><descript source="cve">CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3800.php">cc-whois-meta(3800)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-8%26msg%3D19991210025310.B82291F23E@lists.securityfocus.com">Whois.cgi - ADVISORY.</ref></refs><vuln_soft><prod name="CC Whois" vendor="CC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0986" published="1999-12-08" seq="1999-0986" severity="Medium" type="CVE"><desc><descript source="cve">The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/870">BID 870</ref><ref source="BID" url="http://www.securityfocus.com/bid/870">870</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="5.2"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.0.38"/><vers num="2.0.37"/><vers num="2.0.36"/><vers num="2.0.35"/><vers num="2.0.34"/><vers num="2.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0987" published="1999-11-18" seq="1999-0987" severity="High" type="CVE"><desc><descript source="cve">Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q237923">Q237923</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0988" published="1999-12-04" seq="1999-0988" severity="High" type="CVE"><desc><descript source="cve">UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3802.php">unixware-pkgtrans-symlink(3802)</ref><ref patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a">Package Tool Security Patch</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-1%26msg%3D19991205014254.17071.qmail@nw178.netaddress.usa.net">UnixWare pkg* command exploits</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.1.16"/><vers num="7.1.1"/><vers num="7.1"/><vers num="7.0.1"/><vers num="7.0"/><vers num="2.1"/><vers num="2.0.3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0989" published="1999-12-06" seq="1999-0989" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://securityfocus.com/bid/861">BID 861</ref><ref source="BID" url="http://www.securityfocus.com/bid/861">861</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows NT 4.0" num="50"/><vers edition="Windows 98" num="5.0"/><vers edition="Windows 95" num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0990" published="1999-12-05" seq="1999-0990" severity="Low" type="CVE"><desc><descript source="cve">Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-1%26msg%3DPine.LNX.4.20.9912052128210.3574-100000@nerdland.dhis.org">gdm thing</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3804.php">verbose-auth-identify-user(3804)</ref></refs><vuln_soft><prod name="gdm" vendor="GNOME"><vers num="2.0 Beta4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0991" published="1999-12-06" seq="1999-0991" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://securityfocus.com/bid/862">BID 862</ref><ref source="BID" url="http://www.securityfocus.com/bid/862">862</ref></refs><vuln_soft><prod name="Telnet Server NT" vendor="GoodTech"><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0992" published="2000-01-18" seq="1999-0992" severity="High" type="CVE"><desc><descript source="cve">HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9912-107">HPSBUX9912-107</ref></refs><vuln_soft><prod name="VVOS" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-1999-0993" published="1999-12-13" seq="1999-0993" severity="Medium" type="CVE"><desc><descript source="cve">Modifications to ACLs (Access Control Lists) in Microsoft Exchange  5.5 do not take effect until the directory store cache is refreshed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3916.php">exchange-acl-changes(3916)</ref><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R1753">Changing ACL&apos;s in Exchange Server</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.0"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0994" published="1999-12-16" seq="1999-0994" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-056.asp">MS99-056</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/873">BID 873</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-056.mspx">MS99-056</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q248183">Q248183</ref><ref source="BID" url="http://www.securityfocus.com/bid/873">873</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="Server 4.0"/><vers num="Enterprise 4.0"/><vers num="Terminal Server 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0995" published="1999-12-16" seq="1999-0995" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka &quot;Malformed Security Identifier Request.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-057.asp">MS99-057</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/875">BID 875</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-057.mspx">MS99-057</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q248185">Q248185</ref><ref source="BID" url="http://www.securityfocus.com/bid/875">875</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="Server 4.0"/><vers num="Enterprise 4.0"/><vers num="Terminal Server 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0996" published="1999-12-15" seq="1999-0996" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="eEye" url="http://www.eeye.com/html/advisories/AD19991215.html">AD19991215</ref><ref adv="1" source="Infoseek" url="http://software.infoseek.com/products/ultraseek/upgrade_nt.htm"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3951.php">infoseek-ultraseek-bo(3951)</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD19991215.html">AD19991215</ref><ref source="OSVDB" url="http://www.osvdb.org/6490">6490</ref></refs><vuln_soft><prod name="Ultraseek Server" vendor="Infoseek"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-0997" published="1999-12-20" seq="1999-0997" severity="High" type="CVE"><desc><descript source="cve">wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-377">DSA-377</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="University of Washington"><vers num="2.4.2"/><vers num="2.5.0"/><vers num="2.6.0"/></prod><prod name="Linux" vendor="Red Hat"><vers num="5.2"/><vers num="6.0"/><vers num="6.1"/></prod><prod name="anonftp" vendor="Millenux GmbH"><vers num="2.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0998" published="1999-12-16" seq="1999-0998" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Cache Engine allows an attacker to replace content in the cache.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cacheauth.shtml">CISCO:19991216 Cisco Cache Engine Authentication Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3918.php">cisco-cache-engine-replace(3918)</ref></refs><vuln_soft><prod name="Cache Engine" vendor="Cisco"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-1999-0999" published="1999-11-19" seq="1999-0999" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-059.asp">MS99-059</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/817">BID 817</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-059.mspx">MS99-059</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q248749">Q248749</ref><ref source="BID" url="http://www.securityfocus.com/bid/817">817</ref></refs><vuln_soft><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1000" published="1999-12-16" seq="1999-1000" severity="Medium" type="CVE"><desc><descript source="cve">The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cacheauth.shtml">CISCO:19991216 Cisco Cache Engine Authentication Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3919.php">cisco-cache-engine-performance(3919)</ref></refs><vuln_soft><prod name="Cache Engine" vendor="Cisco"><vers num="2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1001" published="1999-12-16" seq="1999-1001" severity="Low" type="CVE"><desc><descript source="cve">Cisco Cache Engine allows a remote attacker to gain access via a null username and password.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cacheauth.shtml">CISCO:19991216 Cisco Cache Engine Authentication Vulnerabilities</ref></refs><vuln_soft><prod name="Cache Engine" vendor="Cisco"><vers num="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1002" published="2000-01-12" seq="1999-1002" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Navigator uses weak encryption for storing a user&apos;s Netscape mail password.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="RSTCorp" url="http://www.rstcorp.com/news/bad-crypto.html">Reliable Software Technologies Discovers Security Flaw in Netscape Navigator</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4385.php">netscape-mail-notify-plaintext(4385)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-15%26msg%3D387E245C.F279E367@digsigtrust.com">Misleading sense of security in Netscape</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94536309217214&amp;w=2">19991216 Reinventing the wheel (aka &quot;Decoding Netscape Mail passwords&quot;)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94570673523998&amp;w=2">19991220 Netscape password scrambling</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1003" published="1999-12-13" seq="1999-1003" severity="Medium" type="CVE"><desc><descript source="cve">War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3953.php">warftp-connection-flood(3953)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-15%26msg%3DNCBBIJAIBDGCMNAHBHJPGEKKFEAA.jgaa@jgaa.com">Local / Remote D.o.S Attack in War FTP Daemon 1.70 Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-8%26msg%3DNCBBKFKDOLAGKIAPMILPGEGGCBAA.labs@ussrback.com">Statement: Local / Remote D.o.S Attack in War FTP Daemon</ref></refs><vuln_soft><prod name="WarFTPd" vendor="Jgaa"><vers num="1.70"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1004" published="1999-12-16" seq="1999-1004" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3807.php">nav-pop-user(3807)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-15%26msg%3DPine.BSF.4.20.9912171129210.56827-100000@rageout.org">NAV2000 Email Protection DoS</ref><ref adv="1" source="w00w00" url="http://www.w00w00.org/advisories/nortonav.html">[w00giving &apos;99 #11] Norton Antivirus&apos; POProxy</ref><ref source="" url="http://service1.symantec.com/SUPPORT/nav.nsf/df0a595864594c86852567ac0063608c/6206f660a1f2516a882568660082c930?OpenDocument&amp;Highlight=0,poproxy"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/38970">19991217 NAV2000 Email Protection DoS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39194">19991220 Norton Email Protection Remote Overflow (Addendum)</ref><ref source="OSVDB" url="http://www.osvdb.org/6267">6267</ref></refs><vuln_soft><prod name="Norton Antivirus" vendor="Symantec"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1005" published="1999-12-19" seq="1999-1005" severity="Medium" type="CVE"><desc><descript source="cve">Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://securityfocus.com/bid/879">bugtraq id 879</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94571433731824&amp;w=2">19991219 Groupewise Web Interface</ref><ref source="BID" url="http://www.securityfocus.com/bid/879">879</ref><ref source="OSVDB" url="http://www.osvdb.org/3413">3413</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.0.7a"/></prod><prod name="GroupWise" vendor="Novell"><vers num="5.5"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1006" published="1999-12-19" seq="1999-1006" severity="Medium" type="CVE"><desc><descript source="cve">Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94571433731824&amp;w=2">Groupewise Web Interface</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3923.php">groupwise-web-read-files(3923)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-15%26msg%3DA39CA57849A9D1118A9C0060081695B00613D509@MULTI005">Groupewise Web Interface</ref></refs><vuln_soft><prod name="GroupWise" vendor="Novell"><vers num="5.2"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1007" published="1999-12-13" seq="1999-1007" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/872">BID 872</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3924.php">vdolive-bo-execute(3924)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94512259331599&amp;w=2">19991213 VDO Live Player 3.02 Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/872">872</ref></refs><vuln_soft><prod name="VDOLive Player" vendor="VDOnet"><vers num="3.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1008" published="2000-05-17" seq="1999-1008" severity="High" type="CVE"><desc><descript source="cve">xsoldier program allows local users to gain root access via a long argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/871">BID 871</ref><ref source="" url="http://marc.theaimsgroup.com/?l=freebsd-security&amp;m=94531826621620&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/871">871</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.3"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1009" published="1999-12-12" seq="1999-1009" severity="Low" type="CVE"><desc><descript source="cve">The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user&apos;s system.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3955.php">disney-search-info(3955)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-08%26msg%3DPine.GSO.4.10.9912131451280.26938-100000@www.securityfocus.com">Privacy hole in Go Express Search</ref><ref adv="1" source="MobileUnit" url="http://www.mobileunit.org/advisories/001/">Privacy hole in Go Express Search</ref></refs><vuln_soft><prod name="Go Express Search" vendor="Disney"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1010" published="1999-12-14" seq="1999-1010" severity="Low" type="CVE"><desc><descript source="cve">An SSH 1.2.27 server allows a client to use the &quot;none&quot; cipher, even if it is not allowed by the server policy.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-8&amp;msg=19991214164332.A3513@faui01.informatik.uni-erlangen.de"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94519142415338&amp;w=2">19991214 sshd1 allows unencrypted sessions regardless of server policy</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="1.2.27"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-1011" published="1999-07-19" seq="1999-1011" severity="High" type="CVE"><desc><descript source="cve">The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1212.php">nt-iis-rds(1212)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/529">BID 529</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms98-004.asp">MS98-004</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-025.asp">MS99-025</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/fq99-025.asp">MS99-025</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-054.shtml">J-054</ref><ref source="OSVDB" url="http://www.osvdb.org/272">272</ref></refs><vuln_soft><prod name="Index Server" vendor="Microsoft"><vers num="2.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/></prod><prod name="MDAC" vendor="Microsoft"><vers num="2.1 UPGRADE"/><vers num="2.1 CLEAN"/><vers num="2.0"/><vers num="1.5"/></prod><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1012" published="1999-05-04" seq="1999-1012" severity="Medium" type="CVE"><desc><descript source="cve">SMTP component of Lotus Domino 4.6.1 on AS/400, and possibly other operating systems, allows a remote attacker to crash the mail server via a long string.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/13527"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/173">bid173</ref></refs><vuln_soft><prod name="Domino" vendor="Lotus"><vers edition="AS_400" num="4.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1013" published="1999-09-23" seq="1999-1013" severity="High" type="CVE"><desc><descript source="cve">named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/673">bid673</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837026726954&amp;w=2"></ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1.5"/><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1014" published="1999-09-13" seq="1999-1014" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93727925026476&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93846422810162&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3297.php">sun-usrbinmail-local-bo(3297)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/672">bid672</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1015" published="1998-04-08" seq="1999-1015" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service (crash) via a long HELO command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89200657216213&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/61">bid61</ref></refs><vuln_soft><prod name="AppleShare IP Mail Server" vendor="Apple"><vers num="5.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1016" published="1999-08-27" seq="1999-1016" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93578772920970&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/606">bid606</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num=""/></prod><prod name="FrontPage Express" vendor="Microsoft"><vers num=""/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1017" published="1999-07-28" seq="1999-1017" severity="High" type="CVE"><desc><descript source="cve">Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93316253431588&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/544">bid544</ref></refs><vuln_soft><prod name="Emurl" vendor="Seattle Lab Software"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1018" published="1999-07-27" seq="1999-1018" severity="High" type="CVE"><desc><descript source="cve">IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93312523904591&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/543">bid543</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.2.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1019" published="1999-06-23" seq="1999-1019" severity="High" type="CVE"><desc><descript source="cve">SpectroSERVER in Cabletron Spectrum Enterprise Manager 5.0 installs a directory tree with insecure permissions, which allows local users to replace a privileged executable (processd) with a Trojan horse, facilitating a root or Administrator compromise.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398713491&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93024398513475&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/495">bid495</ref></refs><vuln_soft><prod name="Spectrum Enterprise Manager" vendor="Cabletron"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1020" published="1998-09-18" seq="1999-1020" severity="High" type="CVE"><desc><descript source="cve">The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90613355902262&amp;w=2">NMRC Advisory - Default NDS Rights</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/484">bid 484</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1364.php">novell-nds(1364)</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="4.1"/><vers num="4.11 SP5B"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-06-24" name="CVE-1999-1021" published="1992-12-30" seq="1999-1021" severity="High" type="CVE"><desc><descript source="cve">NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-15.html">CA-1992-15</ref><ref patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/117&amp;type=0&amp;nav=sec.sba">#00117</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/47">bid47</ref><ref source="XF" url="http://xforce.iss.net/static/82.php">nfs-uid(82)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1022" published="1994-10-02" seq="1999-1022" severity="Medium" type="CVE"><desc><descript source="cve">serial_ports administrative program in IRIX 4.x and 5.x trusts the user&apos;s PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/930">IRIX Race Conditions</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2111.php">sgi-serialports (2111)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/464">bid464</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="4"/><vers num="5.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1023" published="1999-06-10" seq="1999-1023" severity="Medium" type="CVE"><desc><descript source="cve">useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the &quot;-e&quot; (expiration date) argument, which could allow users to login after their accounts have expired.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92904175406756&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/426">bid426</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1024" published="2001-11-28" seq="1999-1024" severity="High" type="CVE"><desc><descript source="cve">ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infinite loop and core dump when tcpdump prints the packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92955903802773&amp;w=2"></ref><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92963447601748&amp;w=2"></ref><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92989907627051&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/313">bid313</ref></refs><vuln_soft><prod name="Tcpdump" vendor="LBL"><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1025" published="1998-11-12" seq="1999-1025" severity="Medium" type="CVE"><desc><descript source="cve">CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user&apos;s console session when the host is an NIS+ client, which allows others with physical access to login with any string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fpatches%2F106027&amp;zone_32=411568%2A%20">106027-10</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/294">bid294</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90831127921062&amp;w=2">19981012 Annoying Solaris/CDE/NIS+ bug</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1026" published="1996-12-20" seq="1999-1026" severity="High" type="CVE"><desc><descript source="cve">aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420343&amp;w=2">Solaris 2.5 x86 aspppd</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/292">bid292</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.4"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1027" published="1998-05-07" seq="1999-1027" severity="High" type="CVE"><desc><descript source="cve">Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925880&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/290">bid290</ref><ref source="XF" url="http://xforce.iss.net/static/7296.php">solaris-admintool-world-writable(7296)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1028" published="1999-05-28" seq="1999-1028" severity="Medium" type="CVE"><desc><descript source="cve">Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92807524225090&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/288">bid288</ref><ref source="XF" url="http://www.iss.net/security_center/static/2256.php">pcanywhere-dos(2256)</ref></refs><vuln_soft><prod name="PCAnywhere" vendor="Symantec"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1029" published="1999-05-13" seq="1999-1029" severity="High" type="CVE"><desc><descript source="cve">SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92663402004280&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/277">bid277</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2193.php">ssh2-bruteforce(2193)</ref></refs><vuln_soft><prod name="SSH2" vendor="SSH Communications Security"><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.2"/><vers num="2.0.3"/><vers num="2.0.4"/><vers num="2.0.5"/><vers num="2.0.6"/><vers num="2.0.7"/><vers num="2.0.8"/><vers num="2.0.9"/><vers num="2.0.10"/><vers num="2.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1030" published="1999-05-19" seq="1999-1030" severity="Medium" type="CVE"><desc><descript source="cve">counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92713790426690&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92707671717292&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/267">bid267</ref></refs><vuln_soft><prod name="Web Page Counter" vendor="Behold Software"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1031" published="1999-05-19" seq="1999-1031" severity="Medium" type="CVE"><desc><descript source="cve">counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92713790426690&amp;w=2"></ref><ref source="" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92707671717292&amp;w=2"></ref><ref source="" url="http://www.securityfocus.com/bid/267"></ref></refs><vuln_soft><prod name="Web Page Counter" vendor="Behold Software"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1032" published="1991-12-31" seq="1999-1032" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-11.html">CA-1991-11</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/26">bid26</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-36.shtml">B-36</ref><ref source="XF" url="http://xforce.iss.net/static/584.php">ultrix-telnet(584)</ref></refs><vuln_soft><prod name="Ultrix" vendor="Digital"><vers num="4.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1033" published="1999-05-11" seq="1999-1033" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92647407427342&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/252">bid252</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92663402004275&amp;w=2">19990512 Outlook Express Win98 bug, addition.</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="4.72.3612.1700" prev="1"/><vers num="4.27.3110.1"/><vers num="4.72.3120"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-1999-1034" published="1991-05-23" seq="1999-1034" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in login in AT&amp;T System V Release 4 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-08.html">CA-1991-08</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/23">bid23</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/b-28.shtml">B-28</ref><ref source="XF" url="http://xforce.iss.net/static/583.php">sysv-login(583)</ref></refs><vuln_soft><prod name="SVR4" vendor="ATT"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1035" published="1999-12-31" seq="1999-1035" severity="Medium" type="CVE"><desc><descript source="cve">IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS &quot;GET&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms98-019.asp">MS98-019</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q192/2/96.asp"></ref><ref source="XF" url="http://xforce.iss.net/static/1823.php">iis-get-dos(1823)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1036" published="1998-06-26" seq="1999-1036" severity="High" type="CVE"><desc><descript source="cve">COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref></refs><vuln_soft><prod name="COPS" vendor="COPS"><vers num="1.04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-1037" published="1998-06-26" seq="1999-1037" severity="High" type="CVE"><desc><descript source="cve">rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2">vulnerability in satan, cops &amp; tiger</ref><ref source="lists.nas.nasa.gov" url="http://lists.nas.nasa.gov/archives/ext/linux-security-audit/1998/06/msg00217.html">Re: vulnerability in satan v1.1.1</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125986&amp;w=2">19980627 Re: vulnerability in satan, cops &amp; tiger</ref><ref source="XF" url="http://www.iss.net/security_center/static/7167.php">satan-rexsatan-symlink(7167)</ref><ref source="OSVDB" url="http://www.osvdb.org/3147">3147</ref></refs><vuln_soft><prod name="SATAN" vendor="COAST"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-1038" published="1998-06-26" seq="1999-1038" severity="High" type="CVE"><desc><descript source="cve">Tiger 2.2.3 allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger&apos;s default working directory, as defined by the WORKDIR variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125976&amp;w=2">19980626 vulnerability in satan, cops &amp; tiger</ref></refs><vuln_soft><prod name="Tiger" vendor="TAMU"><vers num="2.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1039" published="1998-05-27" seq="1999-1039" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030">19980502-01-P3030</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2103.php">sgi-diskperf (2103)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1040" published="1998-04-08" seq="1999-1040" severity="High" type="CVE"><desc><descript source="cve">Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Silicon Graphics, Inc." url="ftp://patches.sgi.com/support/free/security/advisories/19980501-01-P2869">19980501-01-P2869</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-055.shtml">SGI IRIX Vulnerabilities (NetWare Client,diskperf/diskalign)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89217373930054&amp;w=2">19980408 SGI O2 ipx security issue</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1041" published="1998-08-27" seq="1999-1041" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10420"></ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vendor_bulletins/VB-98.10.sco.mscreen"></ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-98.05a">SB-98.05a</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90686250717719&amp;w=2">19980926 Root exploit for SCO OpenServer.</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod><prod name="Unix" vendor="SCO"><vers num="3.2v4"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1042" published="1999-12-31" seq="1999-1042" severity="Low" type="CVE"><desc><descript source="cve">Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/crmtmp-pub.shtml"></ref></refs><vuln_soft><prod name="Resource Manager" vendor="Cisco"><vers num="1.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-1999-1043" published="1999-12-31" seq="1999-1043" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms98-007.asp">MS98-007</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1044" published="1998-05-07" seq="1999-1044" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-050.shtml">I-050</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7431.php">dgux-advfs-softlinks (7431)</ref><ref source="XF" url="http://www.iss.net/security_center/static/7431.php">dgux-advfs-softlinks(7431)</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num="V4.0"/><vers num="V4.0d" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-1999-1045" published="1998-01-15" seq="1999-1045" severity="High" type="CVE"><desc><descript source="cve">pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88492978527261&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88490880523890&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90338245305236&amp;w=2"></ref><ref patch="1" source="MISC" url="http://service.real.com/help/faq/serv501.html">http://service.real.com/help/faq/serv501.html</ref><ref source="XF" url="http://www.iss.net/security_center/static/7297.php">realserver-pnserver-remote-dos(7297)</ref><ref source="OSVDB" url="http://www.osvdb.org/6979">6979</ref></refs><vuln_soft><prod name="RealServer" vendor="RealNetworks"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1046" published="1999-03-01" seq="1999-1046" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92038879607336&amp;w=2">19990302 Multiple IMail Vulnerabilites</ref><ref source="BID" url="http://www.securityfocus.com/bid/504">504</ref><ref source="XF" url="http://xforce.iss.net/static/1897.php">imail-imonitor-overflow(1897)</ref></refs><vuln_soft><prod name="IMail" vendor="Ipswitch"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1047" published="1999-10-18" seq="1999-1047" severity="High" type="CVE"><desc><descript source="cve">When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94026690521279&amp;w=2"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94036662326185&amp;w=2">19991019 Re: Gauntlet 5.0 BSDI warning</ref><ref source="XF" url="http://www.iss.net/security_center/static/3397.php">gauntlet-bsdi-bypass(3397)</ref></refs><vuln_soft><prod name="Gauntlet" vendor="BSDI"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1048" published="1998-09-05" seq="1999-1048" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10542">BASH buffer overflow, LiNUX x86 exploit</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602746719555&amp;w=2">Buffer overflow in /bin/bash</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/1998/19980909">problem with very long pathnames</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3414.php">linux-bash-bo (3414)</ref><ref source="OSVDB" url="http://www.osvdb.org/8345">8345</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="1.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1049" published="1999-02-21" seq="1999-1049" severity="High" type="CVE"><desc><descript source="cve">ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91972006211238&amp;w=2">19990222 Severe Security Hole in ARCserve NT agents (fwd)</ref><ref patch="1" source="XFORCE" url="http://xforce.iss.net/xforce/xfdb/1822">ARCserve 6.5 NT Client Agent Security Protocol Enhancements</ref></refs><vuln_soft><prod name="ARCserve NT Agents" vendor="Computer Associates"><vers num="6.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1050" published="1999-11-12" seq="1999-1050" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/34939"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/798">bid798</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/799">bid799</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3550.php">formhandler-cgi-absolute-path(3550)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/34600">19991112 FormHandler.cgi</ref></refs><vuln_soft><prod name="FormHandler.cgi" vendor="Matt Wright"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1051" published="1999-11-16" seq="1999-1051" severity="Medium" type="CVE"><desc><descript source="cve">Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/34939"></ref></refs><vuln_soft><prod name="FormHandler.cgi" vendor="Matt Wright"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1052" published="1999-08-24" seq="1999-1052" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93582550911564&amp;w=2"></ref></refs><vuln_soft><prod name="Frontpage" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-1053" published="1999-09-13" seq="1999-1053" severity="High" type="CVE"><desc><descript source="cve">guestbook.pl cleanses user-inserted SSI commands by removing text between &quot;&lt;!--&quot; and &quot;--&gt;&quot; separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides &quot;--&gt;&quot;.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><env/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/82/27296"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/82/27560"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/33674"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/776">bid776</ref></refs><vuln_soft><prod name="Matt Wright GuestBook" vendor="Matt Wright"><vers num="2.3"/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1054" published="1998-09-25" seq="1999-1054" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90675672323825&amp;w=2">Globetrotter FlexLM &apos;Imdown&apos; bogosity</ref></refs><vuln_soft><prod name="FLEXlm" vendor="GLOBEtrotter"><vers num="6.0d"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1055" published="1999-12-31" seq="1999-1055" severity="High" type="CVE"><desc><descript source="cve">Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel &quot;CALL Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms98-018.asp">MS98-018</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=179">bid179</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1737.php">excel-call(1737)</ref><ref source="BID" url="http://www.securityfocus.com/bid/179">179</ref></refs><vuln_soft><prod name="Excel" vendor="Microsoft"><vers num="97"/></prod></vuln_soft></entry><entry modified="2005-10-31" name="CVE-1999-1056" published="1992-12-31" reject="1" seq="1999-1056" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1395.  Reason: This candidate is a duplicate of CVE-1999-1395.  Notes: All CVE users should reference CVE-1999-1395 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1057" published="1990-10-25" seq="1999-1057" severity="Medium" type="CVE"><desc><descript source="cve">VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1990-07.html">CA-1990-07</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-04.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/12">12</ref><ref source="XF" url="http://www.iss.net/security_center/static/7137.php">vms-analyze-processdump-privileges(7137)</ref></refs><vuln_soft><prod name="VMS" vendor="Digital"><vers num="5.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1058" published="1999-11-22" seq="1999-1058" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94329968617085&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3543.php">vermillion-ftp-cwd-overflow(3543)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/818">bid818</ref><ref source="BID" url="http://www.securityfocus.com/bid/818">818</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94337185023159&amp;w=2">19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability</ref></refs><vuln_soft><prod name="Vermillion FTP Daemon" vendor="Arcane Software"><vers num="1.23"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-1999-1059" published="1992-02-25" seq="1999-1059" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in rexec daemon (rexecd) in AT&amp;T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-04.html">CA-1992-04</ref><ref source="BID" url="http://www.securityfocus.com/bid/36">36</ref><ref source="XF" url="http://www.iss.net/security_center/static/3159.php">att-rexecd(3159)</ref></refs><vuln_soft><prod name="SVR4" vendor="ATT"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1060" published="1999-02-17" seq="1999-1060" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91937090211855&amp;w=2">19990217 Tetrix 1.13.16 is Vulnerable</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/340">340</ref></refs><vuln_soft><prod name="TetriNet" vendor="Tetrix"><vers num="1.13.16"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1061" published="1997-10-04" seq="1999-1061" severity="High" type="CVE"><desc><descript source="cve">HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248518480&amp;w=2">HP Laserjet 4M Plus DirectJet Problem</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1876.php">laserjet-unpassworded (1876)</ref></refs><vuln_soft><prod name="JetDirect" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1062" published="1997-10-04" seq="1999-1062" severity="High" type="CVE"><desc><descript source="cve">HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248518480&amp;w=2">HP Laserjet 4M Plus DirectJet Problem</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1876.php">laserjet-unpassworded (1876)</ref></refs><vuln_soft><prod name="JetDirect" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-1063" published="1999-06-01" seq="1999-1063" severity="High" type="CVE"><desc><descript source="cve">CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/14019"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2251.php">http-cgi-cdomain(2251)</ref><ref source="BID" url="http://www.securityfocus.com/bid/304">304</ref></refs><vuln_soft><prod name="CdomainFree" vendor="Cdomain"><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1064" published="1999-08-22" seq="1999-1064" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93555317429630&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93582070508957&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/596">596</ref></refs><vuln_soft><prod name="WindowMaker" vendor="WindowMaker"><vers num="0.60.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1065" published="1999-11-04" seq="1999-1065" severity="High" type="CVE"><desc><descript source="cve">Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94175465525422&amp;w=2"></ref></refs><vuln_soft><prod name="HotSync Manager" vendor="Palm Pilot"><vers num="3.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1066" published="1999-12-22" seq="1999-1066" severity="Medium" type="CVE"><desc><descript source="cve">Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a &quot;Smurf&quot; style attack on another host, by spoofing the connection request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94589559631535&amp;w=2"></ref></refs><vuln_soft><prod name="Quake 1 server" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1067" published="1997-05-07" seq="1999-1067" severity="Medium" type="CVE"><desc><descript source="cve">SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1730.php">sgi-machineinfo (1730)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420919&amp;w=2">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in webdist.cgi</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1068" published="1997-07-23" seq="1999-1068" severity="Medium" type="CVE"><desc><descript source="cve">Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419366&amp;w=2">DoS against Oracle Webserver 2.1 with PL/SQL stored procedures</ref></refs><vuln_soft><prod name="Oracle Webserver" vendor="Oracle"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1069" published="1997-11-08" seq="1999-1069" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/7943">Security bug in iCat Suite version 3.0</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2126">bid2126</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1620.php">icat-carbo-server-vuln (1620)</ref></refs><vuln_soft><prod name="Electronic Commerce Suite" vendor="iCat"><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1070" published="1998-07-25" seq="1999-1070" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10021">Annex DoS</ref></refs><vuln_soft><prod name="Annex" vendor="Xylogics"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1071" published="1998-11-30" seq="1999-1071" severity="High" type="CVE"><desc><descript source="cve">Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91248445931140&amp;w=2">Security bugs in Excite for Web Servers 1.1</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1417.php">excite-world-write(1417)</ref></refs><vuln_soft><prod name="EWS" vendor="Excite"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1072" published="1998-11-30" seq="1999-1072" severity="High" type="CVE"><desc><descript source="cve">Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91248445931140&amp;w=2">Security bugs in Excite for Web Servers 1.1</ref></refs><vuln_soft><prod name="EWS" vendor="Excite"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1073" published="1998-11-30" seq="1999-1073" severity="High" type="CVE"><desc><descript source="cve">Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91248445931140&amp;w=2">Security bugs in Excite for Web Servers 1.1</ref></refs><vuln_soft><prod name="EWS" vendor="Excite"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1074" published="1999-12-31" seq="1999-1074" severity="High" type="CVE"><desc><descript source="cve">Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/9138"></ref><ref adv="1" source="Webmin" url="http://www.webmin.com/webmin/changes.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=98">bid98</ref><ref source="BID" url="http://www.securityfocus.com/bid/98">98</ref></refs><vuln_soft><prod name="Webmin" vendor="Webmin"><vers num="0.42"/><vers num="0.41"/><vers num="0.4"/><vers num="0.31"/><vers num="0.3"/><vers num="0.22"/><vers num="0.21"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1075" published="1998-03-18" seq="1999-1075" severity="Medium" type="CVE"><desc><descript source="cve">inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89025820612530&amp;w=2"></ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1076" published="1999-10-26" seq="1999-1076" severity="Medium" type="CVE"><desc><descript source="cve">Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the &quot;Log Out&quot; option and selecting a &quot;Cancel&quot; option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94096348604173&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/745">bid745</ref></refs><vuln_soft><prod name="Mac OS" vendor="Apple"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1077" published="1999-11-01" seq="1999-1077" severity="Medium" type="CVE"><desc><descript source="cve">Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer&apos;s switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94149318124548&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/756">bid756</ref></refs><vuln_soft><prod name="Mac OS" vendor="Apple"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-1078" published="1999-07-29" seq="1999-1078" severity="High" type="CVE"><desc><descript source="cve">WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9907&amp;L=ntbugtraq&amp;D=0&amp;P=10370&amp;F=P"></ref><ref source="BID" url="http://www.securityfocus.com/bid/547">547</ref></refs><vuln_soft><prod name="WS_FTP Pro" vendor="Ipswitch"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1079" published="1999-05-06" seq="1999-1079" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/439">bid439</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92601792420088&amp;w=2">19990506 AIX Security Fixes Update</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93587956513233&amp;w=2">19990825 AIX security summary</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/servlet/support/manager?rs=0&amp;rt=0&amp;org=apars&amp;doc=08E0B1A1B85472A1852567C90031BB36">IX80470</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/><vers num="3.2.5"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/><vers num="4.2"/><vers num="4.2.1"/><vers num="4.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1080" published="1995-05-10" seq="1999-1080" severity="High" type="CVE"><desc><descript source="cve">rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92633694100270&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93971288323395&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/250">250</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/8350">solaris-rmmount-gain-root(8350)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="5.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1081" published="2002-01-15" seq="1999-1081" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2054.php">http-nov-files (2054)</ref><ref source="MISC" url="http://www.w3.org/Security/Faq/wwwsf8.html#Q87">http://www.w3.org/Security/Faq/wwwsf8.html#Q87</ref><ref source="MISC" url="http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35">http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35</ref></refs><vuln_soft><prod name="Web Server Examples Toolkit" vendor="Novell"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1082" published="1999-10-08" seq="1999-1082" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a &quot;......&quot; (modified dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/699">bid699</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93941794201059&amp;w=2">19991008 Jana webserver exploit</ref></refs><vuln_soft><prod name="Jana Web Server" vendor="T. Hauck"><vers num="1.0"/><vers num="1.45"/><vers num="1.46"/><vers num="1.40"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1083" published="1999-10-08" seq="1999-1083" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95730430727064&amp;w=2">20000502 Security Bug in Jana HTTP Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/699">699</ref></refs><vuln_soft><prod name="Jana Web Server" vendor="T. Hauck"><vers num="1.0"/><vers num="1.45"/><vers num="1.46"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-1084" published="1999-12-31" seq="1999-1084" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;AEDebug&quot; registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q103/8/61.asp"></ref><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms00-008.asp">MS00-008</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-029.shtml">K-029</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1044">bid1044</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222453431604&amp;w=2">19980622 Yet another </ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0"/><vers num="Server 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-1999-1085" published="1998-06-12" seq="1999-1085" severity="Medium" type="CVE"><desc><descript source="cve">SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the &quot;SSH insertion attack.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125884&amp;w=2">CORE-SDI-04</ref><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525878&amp;w=2"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/13877">VU#13877</ref><ref source="XF" url="http://www.iss.net/security_center/static/1126.php">ssh-insert(1126)</ref></refs><vuln_soft><prod name="Secure Shell" vendor="SSH Communications Security"><vers num="1.2.25"/><vers num="1.2.23"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1086" published="1999-07-15" seq="1999-1086" severity="High" type="CVE"><desc><descript source="cve">Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93214475111651&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/528">bid528</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="4.1"/><vers num="4.11 SP5B"/><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1087" published="1999-12-31" seq="1999-1087" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 4 treats a 32-bit number (&quot;dotless IP address&quot;) in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/MS98-016.asp">MS98-016</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q168/6/17.asp"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2209.php">ie-dotless(2209)</ref><ref source="CONFIRM" url="http://www.microsoft.com/Windows/Ie/security/dotless.asp">http://www.microsoft.com/Windows/Ie/security/dotless.asp</ref><ref source="OSVDB" url="http://www.osvdb.org/7828">7828</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="4.0.01"/><vers num="4.0.01 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1088" published="1997-01-09" seq="1999-1088" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21: HP Security Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2012.php">hp-chsh (2012)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.2" prev="1"/><vers num="10.00"/><vers num="10.01"/><vers num="10.10"/><vers num="10.20"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1089" published="1996-12-13" seq="1999-1089" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420285&amp;w=2">the HP Bug of the Week!</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21: HP Security Vulnerabilities</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-16.shtml">H-16: HP-UX Security Vulnerabilities (chfn, Remote Watch)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.X"/><vers num="10.X"/><vers num="10.20" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1090" published="1991-09-10" seq="1999-1090" severity="High" type="CVE"><desc><descript source="cve">The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an &quot;ftp=yes&quot; line, which allows remote attackers to read and modify arbitrary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-15.html">CA-1991-15</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1844.php">ftp-ncsa(1844)</ref></refs><vuln_soft><prod name="Telnet" vendor="NCSA"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1091" published="2002-01-15" seq="1999-1091" severity="Medium" type="CVE"><desc><descript source="cve">UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/431.php">tin-tmpfile (431)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419835&amp;w=2">19960903 [BUG] Vulnerability in TIN</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419839&amp;w=2">19960903 Re: BoS:      [BUG] Vulnerability in TIN</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420726&amp;w=2">19970329 symlink bug in tin/rtin</ref></refs><vuln_soft><prod name="TIN" vendor="TIN"><vers num="1.2"/></prod><prod name="RTIN" vendor="RTIN"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1092" published="1999-11-17" seq="1999-1092" severity="Medium" type="CVE"><desc><descript source="cve">tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286179032648&amp;w=2"></ref></refs><vuln_soft><prod name="Tin" vendor="Iain Lea"><vers num="1.40"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1093" published="1999-12-31" seq="1999-1093" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/MS98-011.asp">MS98-011</ref><ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q191/2/00.asp">Q191200</ref><ref source="XF" url="http://www.iss.net/security_center/static/1276.php">java-script-patch(1276)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="4.0.01"/><vers num="4.0.01 SP1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1094" published="1999-12-31" seq="1999-1094" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the &quot;mk:&quot; protocol, aka the &quot;MK Overrun security issue.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88480839506155&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/917.php">iemk-bug(917)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1095" published="1997-10-06" seq="1999-1095" severity="High" type="CVE"><desc><descript source="cve">sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87619953510834&amp;w=2">updatedb / crontabs</ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88890116304676&amp;w=2">updatedb stuff</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88886870129518&amp;w=2">overwrite any file with updatedb</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.1"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1096" published="1998-05-16" seq="1999-1096" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1644.php">kde-klock-home-bo(1644)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925954&amp;w=2">19980516 kde exploit</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925959&amp;w=2">19980517 simple kde exploit fix</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1097" published="1999-05-04" seq="1999-1097" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft NetMeeting 2.1 allows one client to read the contents of another client&apos;s clipboard via a CTRL-C in the chat box when the box is empty.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2187.php">netmeeting-clipboard(2187)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92586457816446&amp;w=2">19990504 Microsoft Netmeeting Hole</ref></refs><vuln_soft><prod name="NetMeeting" vendor="Microsoft"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1098" published="1995-03-03" seq="1999-1098" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1995-03.html">CA-1995-03</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/f-12.shtml"></ref><ref source="XF" url="http://www.iss.net/security_center/static/516.php">bsd-telnet(516)</ref><ref source="OSVDB" url="http://www.osvdb.org/4881">4881</ref></refs><vuln_soft><prod name="BSD" vendor="BSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-1999-1099" published="1996-11-22" seq="1999-1099" severity="Medium" type="CVE"><desc><descript source="cve">Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420184&amp;w=2">L0pht Kerberos Advisory</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/65.php">kerberos-user-grab (65)</ref></refs><vuln_soft><prod name="KTH Kerberos" vendor="KTH"><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1100" published="1999-12-31" seq="1999-1100" severity="High" type="CVE"><desc><descript source="cve">Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/pixkey-pub.shtml"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1579.php">cisco-pix-parse-error(1579)</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-056.shtml">I-056</ref></refs><vuln_soft><prod name="PIX Private Link" vendor="Cisco"><vers num="4.1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1101" published="1999-02-19" seq="1999-1101" severity="Medium" type="CVE"><desc><descript source="cve">Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12618">19990219 Yet Another password storing problem (was: Re: Possible Netscape Crypto Security Flaw)</ref><ref adv="1" source="ISS" url="http://xforce.iss.net/xforce/xfdb/7501">lydia-ini-passwords (7501) </ref></refs><vuln_soft><prod name="Lydia" vendor="Kab Software"><vers num="3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1102" published="1999-12-31" seq="1999-1102" severity="Low" type="CVE"><desc><descript source="cve">lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Phreak" url="http://www.phreak.org/archives/security/8lgm/8lgm.lpr"></ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-25.shtml">E-25a: BSD lpr Vulnerability in SGI IRIX</ref><ref source="BUGTRAQ" url="http://www.aenigma.net/resources/maillist/bugtraq/1994/0091.htm">19940307 8lgm Advisory Releases</ref></refs><vuln_soft><prod name="A_UX" vendor="IBM"><vers num="2.0.1"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.1" prev="1"/></prod><prod name="BSD" vendor="BSD"><vers num="4.3"/></prod><prod name="IRIX" vendor="SGI"><vers num="5.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1103" published="1996-04-03" seq="1999-1103" severity="Medium" type="CVE"><desc><descript source="cve">dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.05.dec"></ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-18.shtml">G-18</ref><ref source="MISC" url="http://www.tao.ca/fire/bos/0209.html">http://www.tao.ca/fire/bos/0209.html</ref><ref source="XF" url="http://www.iss.net/security_center/static/7138.php">osf-dxconsole-gain-privileges(7138)</ref></refs><vuln_soft><prod name="OSF_1" vendor="Digital"><vers num="3.2C" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1104" published="1999-12-31" seq="1999-1104" severity="Medium" type="CVE"><desc><descript source="cve">Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418931&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=88540877601866&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88536273725787&amp;w=2"></ref><ref source="MSKB" url="http://support.microsoft.com/support/kb/articles/q140/5/57.asp">Q140557</ref><ref source="XF" url="http://www.iss.net/security_center/static/71.php">win95-nbsmbpwl(71)</ref></refs><vuln_soft><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1105" published="1999-12-31" seq="1999-1105" severity="Medium" type="CVE"><desc><descript source="cve">Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Zdnet" url="http://www.zdnet.com/eweek/reviews/1016/tr42bug.html"></ref><ref adv="1" patch="1" source="Net-Security" url="http://www.net-security.sk/bugs/NT/netware1.html"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7231.php">win95-netware-hidden-share(7231)</ref></refs><vuln_soft><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1106" published="1998-04-29" seq="1999-1106" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/9121"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1643.php">kde-kppp-account-bo(1643)</ref><ref source="BID" url="http://www.securityfocus.com/bid/92">92</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1107" published="1998-11-18" seq="1999-1107" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91141486301691&amp;w=2">Multiple KDE security vulnerabilities (root compromise)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1650.php">kde-kppp-path-bo(1650)</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="1.0"/></prod></vuln_soft></entry><entry modified="2005-10-31" name="CVE-1999-1108" published="1998-11-18" reject="1" seq="1999-1108" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1107.  Reason: This candidate is a duplicate of CVE-1999-1107.  Notes: All CVE users should reference CVE-1999-1107 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1109" published="1999-12-22" seq="1999-1109" severity="Medium" type="CVE"><desc><descript source="cve">Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94632241202626&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780566911948&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/904">904</ref><ref source="XF" url="http://www.iss.net/security_center/static/7760.php">sendmail-etrn-dos(7760)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="8.10.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1110" published="1999-11-14" seq="1999-1110" severity="Medium" type="CVE"><desc><descript source="cve">Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/34675"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/793">bid793</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1111" published="1999-11-09" seq="1999-1111" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94218618329838&amp;w=2">Immunix-1999:01</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3524.php">immunix-stackguard-bo(3524)</ref><ref source="BID" url="http://www.securityfocus.com/bid/786">786</ref></refs><vuln_soft><prod name="StackGuard" vendor="Immunix"><vers num="1.21" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1112" published="1999-11-09" seq="1999-1112" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the &quot;8BPS&quot; image type in a Photo Shop image header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/34066"></ref><ref adv="1" source="IrfanView" url="http://stud4.tuwien.ac.at/~e9227474/main2.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3549.php">irfan-view32-bo(3549)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/781">bid781</ref></refs><vuln_soft><prod name="IrfanView" vendor="IrfanView"><vers num="3.0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1113" published="1998-04-14" seq="1999-1113" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a long USER command to port 106.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89258194718577&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/75">75</ref></refs><vuln_soft><prod name="Internet Mail Server" vendor="Eudora"><vers num="2.01" prev="1"/><vers num="1.2"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1114" published="1998-04-08" seq="1999-1114" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-15a.shtml">Korn Shell (ksh) suid_exec Vulnerability</ref><ref adv="1" patch="1" source="Silicon Graphics Inc." url="ftp://patches.sgi.com/support/free/security/advisories/19980405-01-I">suid_exec Buffer Overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2100.php">ksh-suid_exec (2100)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/467">bid467</ref><ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.17.suid_exec.vul">AA-96.17</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1115" published="1990-12-31" seq="1999-1115" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1990-04.html">CA-1990-04</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/a-30.shtml">A-30</ref><ref source="BID" url="http://www.securityfocus.com/bid/7">7</ref><ref source="XF" url="http://www.iss.net/security_center/static/6721.php">apollo-suidexec-unauthorized-access(6721)</ref></refs><vuln_soft><prod name="Apollo Domain OS" vendor="HP"><vers num="sr10.2"/><vers num="sr10.3 beta" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1116" published="1997-05-03" seq="1999-1116" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Silicon Graphics Inc." url="ftp://patches.sgi.com/support/free/security/advisories/19970503-01-PX">19970503-01-PX</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/462">bid462</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2108.php">sgi-runpriv (2108)</ref><ref source="OSVDB" url="http://www.osvdb.org/1009">1009</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1117" published="1999-12-31" seq="1999-1117" severity="Low" type="CVE"><desc><descript source="cve">lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420196&amp;w=2"></ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13: IBM AIX(r) Security Vulnerabilities (gethostbyname,lquerypv)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=455">bid455</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1752.php">ibm-lquerypv(1752)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;w=2&amp;r=1&amp;s=lquerypv&amp;q=b">19961124</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420195&amp;w=2">19961125 lquerypv fix</ref><ref source="BID" url="http://www.securityfocus.com/bid/455">455</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1.x"/><vers num="4.2.x"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1118" published="1998-03-11" seq="1999-1118" severity="Low" type="CVE"><desc><descript source="cve">ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/165&amp;type=0&amp;nav=sec.sba">#00165</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/433">bid433</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/817.php">sun-ndd (817)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1119" published="1992-04-27" seq="1999-1119" severity="High" type="CVE"><desc><descript source="cve">FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-09.html">CA-1992-09</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3154.php">aix-anon-ftp(3154)</ref><ref source="BID" url="http://www.securityfocus.com/bid/41">41</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="All Versions"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1120" published="1997-01-04" seq="1999-1120" severity="Medium" type="CVE"><desc><descript source="cve">netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420403&amp;w=2">Irix: netprint story</ref><ref adv="1" patch="1" source="Silicon Graphics" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX">19961203-02-PX</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/395">bid395</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2107.php">sgi-netprint (2107)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-01-PX">19961203-01-PX</ref><ref source="OSVDB" url="http://www.osvdb.org/993">993</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4" prev="1"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1121" published="1992-03-19" seq="1999-1121" severity="High" type="CVE"><desc><descript source="cve">The default configuration for UUCP in AIX before 3.2 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-06.html">CA-1992-06</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/554.php">ibm-uucp(554)</ref><ref source="BID" url="http://www.securityfocus.com/bid/38">38</ref><ref source="OSVDB" url="http://www.osvdb.org/891">891</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1122" published="1989-07-26" seq="1999-1122" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in restore in SunOS 4.0.3 and earlier allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1989-02.html">CA-1989-02</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/ciac-08.shtml">CIAC-08</ref><ref source="BID" url="http://www.securityfocus.com/bid/3">3</ref><ref source="XF" url="XF:sun-restore-gain-privileges(6695)">sun-restore-gain-privileges(6695)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6695">sun-restore-gain-privileges(6695)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.0.3" prev="1"/><vers num="4.0"/><vers num="4.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1123" published="1991-05-20" seq="1999-1123" severity="High" type="CVE"><desc><descript source="cve">The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-07.html">CA-1991-07</ref><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/107&amp;type=0&amp;nav=sec.sba">#00107</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/582.php">sun-sourcetapes(582)</ref><ref source="BID" url="http://www.securityfocus.com/bid/21">21</ref><ref source="BID" url="http://www.securityfocus.com/bid/22">22</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.0.3"/><vers num="4.1"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1124" published="1999-12-31" seq="1999-1124" severity="High" type="CVE"><desc><descript source="cve">HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://packetstorm.securify.com/mag/phrack/phrack54/P54-08">http://packetstorm.securify.com/mag/phrack/phrack54/P54-08</ref></refs><vuln_soft><prod name="ColdFusion" vendor="Allaire"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-1125" published="1997-09-19" seq="1999-1125" severity="High" type="CVE"><desc><descript source="cve">Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/7174.php">oracle-webserver-gain-root (7174)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019796&amp;w=2">19970919 Instresting practises of Oracle [Oracle Webserver]</ref></refs><vuln_soft><prod name="Oracle Webserver" vendor="Oracle"><vers num="2.1" prev="1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1126" published="1999-12-31" seq="1999-1126" severity="Low" type="CVE"><desc><descript source="cve">Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with &quot;DPR_&quot;.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/crmtmp-pub.shtml"></ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-086.shtml"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1575.php">cisco-crm-file-vuln(1575)</ref></refs><vuln_soft><prod name="Resource Manager" vendor="Cisco"><vers num="1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1127" published="1999-12-31" seq="1999-1127" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the &quot;Named Pipes Over RPC&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms98-017.asp">MS98-017</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q195/7/33.asp"></ref><ref source="XF" url="http://www.iss.net/security_center/static/523.php">nt-spoolss(523)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1128" published="1997-03-01" seq="1999-1128" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/462.php">http-ie-exec (462)</ref><ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html">http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html</ref><ref source="MISC" url="http://members.tripod.com/~unibyte/iebug3.htm">http://members.tripod.com/~unibyte/iebug3.htm</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1129" published="1999-09-01" seq="1999-1129" severity="High" type="CVE"><desc><descript source="cve">Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/26008"></ref><ref adv="1" source="Cisco" url="http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v8x/eescg8x/aleakyv.htm"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3294.php">cisco-catalyst-vlan-frames(3294)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/615">bid615</ref></refs><vuln_soft><prod name="Catalyst 2900 VLAN" vendor="Cisco"><vers num=""/></prod><prod name="IOS" vendor="Cisco"><vers num="11.2.8SA5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1130" published="1999-07-30" seq="1999-1130" severity="Medium" type="CVE"><desc><descript source="cve">Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93346448121208&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/559">559</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93337389603117&amp;w=2">19990730 Netscape Enterprise Server yeilds source of JHTML</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-1999-1131" published="1997-10-24" seq="1999-1131" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in OSF Distributed Computing Environment (DCE) security demon (secd) in IRIX 6.4 and earlier allows attackers to cause a denial of service via a long principal, group, or organization.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="" url="http://www.cert.org/vendor_bulletins/VB-97.12.opengroup">VB-97.12</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-060.shtml">I-060</ref><ref adv="1" patch="1" source="Silicon Graphics" url="ftp://patches.sgi.com/support/free/security/advisories/19980601-01-PX">19980601-01-PX</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1123.php">sgi-osf-dce-dos(1123)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.3"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1132" published="1999-12-31" seq="1999-1132" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90763508011966&amp;w=2"></ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q179/1/57.asp"></ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90760603030452&amp;w=2">19981002 NMRC Advisory - Lame NT Token Ring DoS</ref><ref source="XF" url="http://www.iss.net/security_center/static/1399.php">token-ring-dos(1399)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1133" published="1997-09-01" seq="1999-1133" severity="Medium" type="CVE"><desc><descript source="cve">HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019776&amp;w=2">ecurity Vulnerability in libXt for HP-UX 9.X &amp; 10.X</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/499.php">hp-vue-dt (499)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9"/><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1134" published="1994-05-18" seq="1999-1134" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2284.php">hp-vue (2284)</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-23.shtml">E-23b</ref><ref source="HP" url="http://packetstorm.securify.com/advisories/hpalert/008">HPSBUX9404-008</ref><ref source="XF" url="http://www.iss.net/security_center/static/2284.php">hp-vue(2284)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1135" published="1994-04-20" seq="1999-1135" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-23.shtml">E-23b</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2284.php">hp-vue (2284</ref><ref source="HP" url="http://packetstorm.securify.com/advisories/hpalert/027">HPSBUX9504-027</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-1999-1136" published="1998-07-30" seq="1999-1136" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Codetalker" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9807-081.html">HPSBUX9807-081</ref><ref adv="1" patch="1" source="CERT" url="http://cert.ip-plus.net/bulletin-archive/msg00040.html">HPSBMP9807-005</ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526177&amp;w=2">HP-UX Predictive &amp; Netscape SSL Vulnerabilities</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-081.shtml">I-081</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1413.php">mpeix-predictive (1413)</ref></refs><vuln_soft><prod name="MPE iX" vendor="HP"><vers num="5.5" prev="1"/><vers num="5.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1137" published="1993-10-01" seq="1999-1137" severity="Low" type="CVE"><desc><descript source="cve">The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/e-01.shtml">E-01</ref><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">#00122</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/549.php">sun-audio (549)</ref><ref source="OSVDB" url="http://www.osvdb.org/6436">6436</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.2" prev="1"/><vers num=""/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1"/><vers num="5.0"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1138" published="1993-09-17" seq="1999-1138" severity="High" type="CVE"><desc><descript source="cve">SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="CERT" url="http://www.cert.org/advisories/CA-1993-13.html">CA-1993-13</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/546.php">sco-homedir(546)</ref></refs><vuln_soft><prod name="Open Desktop Lite" vendor="SCO"><vers num="3.0"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/></prod><prod name="OpenServer" vendor="SCO"><vers num="3.0"/></prod><prod name="Unix" vendor="SCO"><vers num="System V/386 3.2 Operating System"/><vers num="System V/386 3.2 Operating System 2.0"/><vers num="System V/386 3.2 Operating System 4.x"/><vers num="System V/386 3.2 Operating System 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1139" published="1997-09-01" seq="1999-1139" severity="High" type="CVE"><desc><descript source="cve">Character-Terminal User Environment (CUE) in HP-UX 11.0 and earlier allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the IOERROR.mytty file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Codetalker" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9801-074.html">HPSBUX9801-074</ref><ref adv="1" patch="1" source="SecurityArchive" url="http://security-archive.merton.ox.ac.uk/bugtraq-199801/0122.html">HP-UX CUE, CUD and LAND vulnerabilities</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019745&amp;w=2">HP UX Bug</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-027b.shtml">I-027B</ref><ref source="XF" url="http://www.iss.net/security_center/static/2007.php">hp-cue(2007)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1140" published="1997-12-14" seq="1999-1140" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88209041500913&amp;w=2"></ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.16.CrackLib">VB-97.16</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1539.php">cracklib-bo(1539)</ref></refs><vuln_soft><prod name="CrackLib" vendor="Alec Muffet"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1141" published="1997-05-15" seq="1999-1141" severity="High" type="CVE"><desc><descript source="cve">Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1824.php">ascom-timeplex-debug (1824)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420981&amp;w=2">19970515 MicroSolved finds hole in Ascom Timeplex Router Security</ref></refs><vuln_soft><prod name="Timeplex Routers" vendor="Ascom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-1142" published="1992-05-27" seq="1999-1142" severity="High" type="CVE"><desc><descript source="cve">SunOS 4.1.2 and earlier allows local users to gain privileges via &quot;LD_*&quot; environmental variables to certain dynamically linked setuid or setgid programs such as (1) login, (2) su, or (3) sendmail, that change the real and effective user ids to the same user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-11.html">CA-1992-11</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3152.php">sun-env(3152)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/116">00116</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1143" published="1997-05-28" seq="1999-1143" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-65.shtml">H-65: SGI IRIX rld Security Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2109.php">sgi-rld (2109</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970504-01-PX">19970504-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1144" published="1997-01-30" seq="1999-1144" severity="High" type="CVE"><desc><descript source="cve">Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Codetalker" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-051.html">HPSBUX9701-051</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2056.php">hp-mpower (2056)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.00"/><vers num="10.01"/><vers num="10.10"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-1145" published="1997-01-07" seq="1999-1145" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21: HP Security Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2059.php">hp-glanceplus (2059)</ref><ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=1514">HPSBUX9701-044</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20" prev="1"/><vers num="10.01"/><vers num="10.10"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1146" published="1994-05-04" seq="1999-1146" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Glance and gpm programs in GlancePlus for HP-UX 9.x and earlier allows local users to access arbitrary files and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/advisories/1555">Security Vulnerability in HP GlancePlus</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2060.php">hp-glanceplus-gpm (2060)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.x" prev="1"/><vers num="8.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1147" published="1998-12-04" seq="1999-1147" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91273739726314&amp;w=2">[SAFER-981204.DOS.1.3] Buffer Overflow in Platinum PCM 7.0</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1430.php">pcm-dos-execute(1430)</ref><ref source="OSVDB" url="http://www.osvdb.org/3164">3164</ref></refs><vuln_soft><prod name="Policy Compliance Manager" vendor="Platinum"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1148" published="1999-12-31" seq="1999-1148" severity="Medium" type="CVE"><desc><descript source="cve">FTP service in IIS 4.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via many passive (PASV) connections at the same time.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms98-006.asp">MS98-006</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q189/2/62.ASP"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1215.php">iis-passive-ftp(1215)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1149" published="1998-07-16" seq="1999-1149" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in CSM Proxy 4.1 allows remote attackers to cause a denial of service (crash) via a long string to the FTP port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525993&amp;w=2">S.A.F.E.R. Security Bulletin 980708.DOS.1.1</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1422.php">csm-proxy-dos(1422)</ref></refs><vuln_soft><prod name="CSM Proxy" vendor="Computer Software Manufaktur"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1150" published="1998-06-30" seq="1999-1150" severity="High" type="CVE"><desc><descript source="cve">Livingston Portmaster routers running ComOS use the same initial sequence number (ISN) for TCP connections, which allows remote attackers to conduct spoofing and hijack TCP sessions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/9723"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1882.php">portmaster-fixed-isn(1882)</ref></refs><vuln_soft><prod name="Portmaster" vendor="Livingston Portmaster"><vers num="Initial"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1151" published="1998-06-03" seq="1999-1151" severity="Medium" type="CVE"><desc><descript source="cve">Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90296493106214&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2089.php">microcom-dos(2089)</ref></refs><vuln_soft><prod name="Microcom 6000 Access Integrator" vendor="Compaq Microcom"><vers num="Initial"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1152" published="1998-06-03" seq="1999-1152" severity="Medium" type="CVE"><desc><descript source="cve">Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90296493106214&amp;w=2"></ref></refs><vuln_soft><prod name="Microcom 6000 Access Integrator" vendor="Compaq Microcom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1153" published="1998-11-09" seq="1999-1153" severity="High" type="CVE"><desc><descript source="cve">HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1400.php">cgi-perl-mail-programs(1400)</ref></refs><vuln_soft><prod name="HAMcards Postcard CGI" vendor="HAMcards Postcard CGI"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1154" published="1998-11-09" seq="1999-1154" severity="High" type="CVE"><desc><descript source="cve">LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/11175">Several new CGI vulnerabilities</ref><ref adv="1" source="" url="http://lakeweb.com/scripts/"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1400.php">cgi-perl-mail-programs(1400)</ref></refs><vuln_soft><prod name="Filemail CGI script" vendor="LakeWeb"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1155" published="1998-11-09" seq="1999-1155" severity="High" type="CVE"><desc><descript source="cve">LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/11175">Several new CGI vulnerabilities</ref><ref adv="1" source="" url="http://lakeweb.com/scripts/"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1400.php">cgi-perl-mail-programs(1400)</ref></refs><vuln_soft><prod name="Mail List CGI script" vendor="LakeWeb"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1156" published="1999-05-17" seq="1999-1156" severity="Medium" type="CVE"><desc><descript source="cve">BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9905&amp;L=NTBUGTRAQ&amp;P=R2698"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2254.php">bisonware-port-crash(2254)</ref></refs><vuln_soft><prod name="BisonWare FTP Server" vendor="BisonWare"><vers num="4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1157" published="1999-12-31" seq="1999-1157" severity="Medium" type="CVE"><desc><descript source="cve">Tcpip.sys in Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service via an ICMP Subnet Mask Address Request packet, when certain multiple IP addresses are bound to the same network interface.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q192/7/74.ASP"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3894.php">tcpipsys-icmp-dos(3894)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers edition="SP4" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1158" published="1997-05-13" seq="1999-1158" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/139&amp;type=0&amp;nav=sec.sba"></ref><ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.09.Solaris.passwd.buffer.overrun.vul">AA-97.09</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1159" published="1998-12-29" seq="1999-1159" severity="Medium" type="CVE"><desc><descript source="cve">SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91495920911490&amp;w=2">ssh2 security problem (and patch) (fwd)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1471.php">ssh-privileged-port-forward(1471)</ref></refs><vuln_soft><prod name="SSH2" vendor="SSH Communications Security"><vers num="2.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1160" published="1997-02-02" seq="1999-1160" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420581&amp;w=2">HPSBUX9702-055</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-33.shtml">H-33: HP-UX ftpd/kftpd Vulnerability</ref><ref source="XF" url="http://www.iss.net/security_center/static/7437.php">hp-ftpd-kftpd(7437)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1161" published="1996-11-03" seq="1999-1161" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420102&amp;w=2">Untitled</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420103&amp;w=2">ppl bugs</ref><ref adv="1" patch="1" source="Codetalker" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9704-057.html">HPSBUX9704-057</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-32.shtml">H-32: HP-UX ppl Core Dump Vulnerability</ref><ref source="XF" url="http://www.iss.net/security_center/static/7438.php">hp-ppl(7438)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10" prev="1"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1162" published="1993-05-24" seq="1999-1162" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1993-08.html">CA-1993-08 SCO</ref><ref source="XF" url="http://www.iss.net/security_center/static/542.php">sco-passwd-deny(542)</ref></refs><vuln_soft><prod name="Open Desktop" vendor="SCO"><vers num="1.1"/><vers num="2.0"/></prod><prod name="Unix" vendor="SCO"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1163" published="1999-11-24" seq="1999-1163" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94347039929958&amp;w=2">HPSBUX9911-105</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7439.php">hp-ssp (7439)</ref><ref source="XF" url="http://www.iss.net/security_center/static/7439.php">hp-ssp(7439)</ref></refs><vuln_soft><prod name="HP9000" vendor="HP"><vers num="Series 800"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1164" published="1999-06-25" seq="1999-1164" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93041631215856&amp;w=2"></ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="97"/><vers num="98"/><vers num="2000"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1165" published="1999-07-21" seq="1999-1165" severity="High" type="CVE"><desc><descript source="cve">GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/2478">NU finger 1.37 executes ~/.fingerrc with gid root</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/535">bid535</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93268249021561&amp;w=2">19990721 old gnu finger bugs</ref></refs><vuln_soft><prod name="Fingerd" vendor="GNU"><vers num="1.37"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1166" published="1999-07-11" seq="1999-1166" severity="High" type="CVE"><desc><descript source="cve">Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/18156"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/523">bid523</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0.37"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1167" published="1999-12-31" seq="1999-1167" severity="Medium" type="CVE"><desc><descript source="cve">Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Wired" url="http://www.wired.com/news/technology/0,1282,20677,00.html"></ref><ref adv="1" source="Wired" url="http://www.wired.com/news/technology/0,1282,20636,00.html"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7252.php">thirdvoice-cross-site-scripting(7252)</ref></refs><vuln_soft><prod name="Third Voice Web" vendor="Third Voice"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1168" published="1999-02-20" seq="1999-1168" severity="High" type="CVE"><desc><descript source="cve">install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12640">19990220 ISS install.iss security hole</ref></refs><vuln_soft><prod name="Internet Security Scanner" vendor="Internet Security Systems"><vers num="5.3 Linux"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1169" published="1999-02-04" seq="1999-1169" severity="Medium" type="CVE"><desc><descript source="cve">nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12284">19990204 NOBO denial of service</ref><ref patch="1" source="XFORCE" url="http://xforce.iss.net/xforce/xfdb/7502">NOBO large UDP packet denial of service</ref></refs><vuln_soft><prod name="NOBO" vendor="Flavio Veloso"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1170" published="1999-01-02" seq="1999-1170" severity="Medium" type="CVE"><desc><descript source="cve">IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the &quot;flags&quot; registry key to 1920.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91816507920544&amp;w=2">19990204 WS FTP Server Remote DoS Attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/218">218</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="IPSwitch"><vers num="1.0.2.E"/><vers num="1.0.1.E"/></prod><prod name="IMail" vendor="IPSwitch"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1171" published="1999-02-02" seq="1999-1171" severity="Medium" type="CVE"><desc><descript source="cve">IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the &quot;flags&quot; registry key to 1920.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91816507920544&amp;w=2">19990204 WS FTP Server Remote DoS Attack</ref><ref source="XFORCE" url="http://www.securityfocus.com/bid/218">218 IMail Server and WS_FTP Server Privilege Escalation Vulnerability</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="1.0.2.E"/><vers num="1.0.1.E"/></prod><prod name="IMail" vendor="Ipswitch"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1172" published="1999-01-14" seq="1999-1172" severity="Medium" type="CVE"><desc><descript source="cve">By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11947">19990114 security hole in Maximizer</ref></refs><vuln_soft><prod name="Maximizer Enterprise" vendor="Maximizer"><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1173" published="1998-12-18" seq="1999-1173" severity="Low" type="CVE"><desc><descript source="cve">Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91404045014047&amp;w=2">wordperfect 8 for linux security</ref></refs><vuln_soft><prod name="WordPerfect" vendor="Corel"><vers edition="Linux" num="8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1174" published="2001-12-21" seq="1999-1174" severity="Medium" type="CVE"><desc><descript source="cve">ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by inserting a known disk with a known password, waiting for the ZIP drive to power down, manually replacing the known disk with the target disk, and using the known password to access the target disk.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Counterpane" url="http://www.counterpane.com/crypto-gram-9812.htmldoghouse">Iomega Zip Disks</ref><ref source="MISC" url="http://www.counterpane.com/crypto-gram-9812.html#doghouse">http://www.counterpane.com/crypto-gram-9812.html#doghouse</ref></refs><vuln_soft><prod name="ZIP 100 MB drive" vendor="Iomega"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1175" published="1999-12-31" seq="1999-1175" severity="High" type="CVE"><desc><descript source="cve">Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/wccpauth-pub.shtml"></ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-054.shtml">I-054: Cisco Web Cache Control Protocol Router Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/1577.php">cisco-wccp-vuln(1577)</ref></refs><vuln_soft><prod name="Cache Engine" vendor="Cisco"><vers num="11.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1176" published="1998-01-10" seq="1999-1176" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in cidentd ident daemon allows local users to gain root privileges via a long line in the .authlie script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88466930416716&amp;w=2">19980110 Cidentd</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90554230925545&amp;w=2">19980911 Re: security problems with jidentd</ref></refs><vuln_soft><prod name="Jidentd" vendor="Jidentd"><vers num=""/></prod><prod name="Cidentd" vendor="Aaron Ledbetter"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1177" published="1999-12-31" seq="1999-1177" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="W3C" url="http://www.w3.org/Security/Faq/wwwsf4.html"></ref><ref adv="1" patch="1" source="Genome" url="http://www-genome.wi.mit.edu/WWW/tools/CGI_scripts/server_publish/nph-publish"></ref><ref adv="1" source="Genome" url="http://www-genome.wi.mit.edu/"></ref><ref source="XF" url="http://xforce.iss.net/static/2055.php">http-cgi-nphpublish(2055)</ref></refs><vuln_soft><prod name="nph-publish" vendor="Lincoln D. Stein"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1178" published="1998-06-10" seq="1999-1178" severity="Medium" type="CVE"><desc><descript source="cve">Sambar Server 4.1 beta allows remote attackers to obtain sensitive information about the server via an HTTP request for the dumpenv.pl script.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3223.php">sambar-dump-env(3223)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/9505"></ref></refs><vuln_soft><prod name="Sambar Server" vendor="Sambar"><vers num="4.1 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1179" published="1998-05-15" seq="1999-1179" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in man.sh CGI script, included in May 1998 issue of SysAdmin Magazine, allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/9330"></ref></refs><vuln_soft><prod name="man.sh" vendor="SysAdmin Magazine"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1180" published="1999-02-16" seq="1999-1180" severity="Medium" type="CVE"><desc><descript source="cve">O&apos;Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.</descript></desc><sols><sol source="nvd">O&apos;Reilly has corrected this issue in WebSite Professional 2.5, which is now available from:  http://website.oreilly.com</sol></sols><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/advisories/2424">COVERT-2000-08: OReilly WebSite Professional Overflow</ref><ref patch="1" source="BugTraq Mailing List" url="http://archives.neohapsis.com/archives/bugtraq/1999_1/0738.html">Website Pro v2.0 (NT) Configuration Issues</ref></refs><vuln_soft><prod name="WebSite" vendor="OReilly"><vers num="1.1e"/></prod><prod name="Website Pro" vendor="OReilly"><vers num="2.4" prev="1"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1181" published="1998-09-29" seq="1999-1181" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in On-Line Customer Registration software for IRIX 6.2 through 6.4 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-003.shtml">J-003: SGI IRIX On-Line Customer Registration Vulnerabilities</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980901-01-PX">19980901-01-PX</ref><ref source="XF" url="http://www.iss.net/security_center/static/7441.php">irix-register(7441)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/><vers num="6.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1182" published="1997-07-17" seq="1999-1182" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419318&amp;w=2">KSR[T] Advisory #2: ld.so</ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419351&amp;w=2">ld.so vulnerability</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88661732807795&amp;w=2">An old ld-linux.so hole</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="5.0"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/></prod><prod name="LST Power Linux" vendor="LST"><vers num="2.2"/></prod><prod name="DLD" vendor="Delix"><vers num="5.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="4.0"/></prod><prod name="OpenLinux Lite" vendor="Caldera"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1183" published="1998-04-02" seq="1999-1183" severity="High" type="CVE"><desc><descript source="cve">System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user&apos;s Mailcap entry supports the x-sgi-task or x-sgi-exec type.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980403-02-PX">19980403-02-PX</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980403-01-PX">19980403-01-PX</ref><ref source="XF" url="http://www.iss.net/security_center/static/809.php">sgi-mailcap(809)</ref><ref source="OSVDB" url="http://www.osvdb.org/8556">8556</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1184" published="1997-05-13" seq="1999-1184" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420967&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420970&amp;w=2"></ref></refs><vuln_soft><prod name="Elm" vendor="Elm Development Group"><vers num="2.3"/><vers num="2.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1185" published="1998-10-06" seq="1999-1185" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10420"></ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vendor_bulletins/VB-98.10.sco.mscreen">98.05</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1379.php">sco-openserver-mscreen-bo(1379)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90686250717719&amp;w=2">19980926 Root exploit for SCO OpenServer.</ref></refs><vuln_soft><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="OpenServer" vendor="SCO"><vers num="3.0"/><vers num="5.0"/></prod><prod name="OpenServer Enterprise System" vendor="SCO"><vers num="5.0.4p"/></prod><prod name="CMW" vendor="SCO"><vers num="3.0"/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="All Versions"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1186" published="1996-01-02" seq="1999-1186" severity="High" type="CVE"><desc><descript source="cve">rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418966&amp;w=2">rxvt security hole</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="2.1"/></prod><prod name="Rxvt" vendor="Rxvt"><vers num=""/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1187" published="1996-08-26" seq="1999-1187" severity="Medium" type="CVE"><desc><descript source="cve">Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419803&amp;w=2">Vulnerability in PINE</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/416.php">pine-tmpfile (416)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="3.0"/></prod><prod name="Pine" vendor="University of Washington"><vers num="3.94" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-1188" published="1998-12-27" seq="1999-1188" severity="Medium" type="CVE"><desc><descript source="cve">mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91479159617803&amp;w=2">mysql: mysqld creates world readable logs</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1568.php">mysql-readable-log-files(1568)</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-1999-1189" published="1999-11-24" seq="1999-1189" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/36306"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/36608"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/822">bid822</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/7884">Netscape Communicator long URL argument buffer overflow</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.7"/></prod><prod name="Navigator" vendor="Netscape"><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1190" published="1999-11-15" seq="1999-1190" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long &quot;From&quot; header in an e-mail message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Securiteam" url="http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/801">bid801</ref></refs><vuln_soft><prod name="EmailClub" vendor="Admiral Systems"><vers num="1.0.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-1191" published="1997-05-19" seq="1999-1191" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418335&amp;w=2">Finally, most of an exploit for Solaris 2.5.1&apos;s ps</ref><ref adv="1" patch="1" source="Auscert" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.18.solaris.chkey.buffer.overflow.vul">AA-97.18</ref><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/144">#00144</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/207">bid207</ref><ref source="XF" url="http://www.iss.net/security_center/static/7442.php">solaris-chkey-bo(7442)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5.1" prev="1"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1192" published="1997-06-24" seq="1999-1192" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/143">#00143</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/206">bid206</ref><ref source="XF" url="http://www.iss.net/security_center/static/7444.php">solaris-eeprom-bo(7444)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5.1" prev="1"/><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1193" published="1991-05-14" seq="1999-1193" severity="High" type="CVE"><desc><descript source="cve">The &quot;me&quot; user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-06.html">CA-1991-06</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/581.php">next-me(581)</ref><ref source="BID" url="http://www.securityfocus.com/bid/20">20</ref></refs><vuln_soft><prod name="NeXT" vendor="NeXT"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1194" published="1991-05-01" seq="1999-1194" severity="High" type="CVE"><desc><descript source="cve">chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-05.html">CA-1991-05</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/577.php">dec-chroot(577</ref><ref source="BID" url="http://www.securityfocus.com/bid/17">17</ref></refs><vuln_soft><prod name="Ultrix" vendor="Digital"><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1195" published="1999-05-05" seq="1999-1195" severity="Medium" type="CVE"><desc><descript source="cve">NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to believe that the definitions have been updated correctly.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92588169005196&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/169">169</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92587579032534&amp;w=2">19990505 NAI AntiVirus Update Problem</ref></refs><vuln_soft><prod name="VirusScan" vendor="Network Associates"><vers num="4.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1196" published="1999-04-07" seq="1999-1196" severity="Medium" type="CVE"><desc><descript source="cve">Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.</descript></desc><sols><sol source="nvd">Upgrade to a non-vulnerable version of Exceed (Hummingbird Exceed 6.0.1 Hummingbird Exceed 6.0.2 Hummingbird Exceed 6.1)</sol></sols><loss_types><avail/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13451">19990427 NT/Exceed D.O.S.</ref><ref source="BID" url="http://www.securityfocus.com/bid/158">158</ref></refs><vuln_soft><prod name="Exceed" vendor="Hummingbird"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1197" published="1990-12-20" seq="1999-1197" severity="High" type="CVE"><desc><descript source="cve">TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1990-12.html">CA-1990-12</ref><ref source="BID" url="http://www.securityfocus.com/bid/14">14</ref><ref source="XF" url="http://www.iss.net/security_center/static/7140.php">sunos-tioccons-console-redirection(7140)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1198" published="1990-10-03" seq="1999-1198" severity="High" type="CVE"><desc><descript source="cve">BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/11">11</ref><ref source="XF" url="http://www.iss.net/security_center/static/7141.php">nextstep-builddisk-root-access(7141)</ref></refs><vuln_soft><prod name="NeXT" vendor="NeXT"><vers num="2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-1199" published="1998-08-07" seq="1999-1199" severity="High" type="CVE"><desc><descript source="cve">Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the &quot;sioux&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90252779826784&amp;w=2">YA Apache DoS attack</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90276683825862&amp;w=2">Debian Apache Security Update</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90286768232093&amp;w=2">Apache DoS Attack</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90280517007869&amp;w=2">Apache &apos;sioux&apos; DOS fix for TurboLinux</ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#apache">http://www.redhat.com/support/errata/rh51-errata-general.html#apache</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1200" published="1998-07-20" seq="1999-1200" severity="Medium" type="CVE"><desc><descript source="cve">Vintra SMTP MailServer allows remote attackers to cause a denial of service via a malformed &quot;EXPN *@&quot; command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="NT Bugtraq" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222454131610&amp;w=2">DOS in Vintra systems Mailserver software</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1617.php">vintra-mail-dos(1617)</ref></refs><vuln_soft><prod name="SMTP MailServer" vendor="Vintra Systems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-20" name="CVE-1999-1201" published="1999-02-06" seq="1999-1201" severity="Medium" type="CVE"><desc><descript source="cve">Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://securityfocus.com/bid/225">Windows 9x TCP Chorusing Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7542">Windows 95 and 98 with multiple TCP/IP stacks ICMP packet denial of service</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91849617221319&amp;w=2">19990206 New Windows 9x Bug:  TCP Chorusing</ref><ref source="BID" url="http://www.securityfocus.com/bid/225">225</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1202" published="1998-07-03" seq="1999-1202" severity="Medium" type="CVE"><desc><descript source="cve">StarTech (1) POP3 proxy server and (2) telnet server allows remote attackers to cause a denial of service via a long USER command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525873&amp;w=2">Windows95 Proxy DoS Vulnerabilites</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2088.php">startech-pop3-overflow(2088)</ref></refs><vuln_soft><prod name="Telnet Server" vendor="StarTech"><vers num=""/></prod><prod name="POP3 Proxy Server" vendor="StarTech"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-1203" published="1999-02-12" seq="1999-1203" severity="Medium" type="CVE"><desc><descript source="cve">Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12448">PPP/ISDN multilink security issue - summary</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91868964203769&amp;w=2">19990210 Security problems in ISDN equipment authentication</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91888117502765&amp;w=2">19990212 PPP/ISDN multilink security issue - summary</ref><ref source="XF" url="http://www.iss.net/security_center/static/7498.php">ascend-ppp-isdn-dos(7498)</ref></refs><vuln_soft><prod name="Multilink PPP for ISDN" vendor="Ascend"><vers num="4.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-1999-1204" published="1998-05-11" seq="1999-1204" severity="High" type="CVE"><desc><descript source="cve">Check Point Firewall-1 does not properly handle certain restricted keywords (e.g., Mail, auth, time) in user-defined objects, which could produce a rule with a default &quot;ANY&quot; address and result in access to more systems than intended by the administrator.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925912&amp;w=2"></ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/config/keywords.html">http://www.checkpoint.com/techsupport/config/keywords.html</ref><ref source="XF" url="http://xforce.iss.net/static/7293.php">fw1-user-defined-keywords-access(7293)</ref><ref source="OSVDB" url="http://www.osvdb.org/4416">4416</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1205" published="1996-06-07" seq="1999-1205" severity="Low" type="CVE"><desc><descript source="cve">nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419195&amp;w=2">HP-UX B.10.01 vulnerability</ref><ref adv="1" patch="1" source="PacketStorm" url="http://packetstormsecurity.org/advisories/ibm-ers/96-08">ERS-OAR-E01-1996:008.1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/414">hp-nettune(414)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.01"/><vers num="10.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1206" published="1999-12-31" seq="1999-1206" severity="High" type="CVE"><desc><descript source="cve">SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93336970231857&amp;w=2"></ref><ref adv="1" patch="1" source="SystemSoft" url="http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=555">bid555</ref><ref source="BID" url="http://www.securityfocus.com/bid/555">555</ref></refs><vuln_soft><prod name="SystemWizard" vendor="SystemSoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1207" published="1998-02-18" seq="1999-1207" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in web-admin tool in NetXRay 2.6 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/907.php">netxray-bo(907)</ref><ref source="MISC" url="http://www.efri.hr/~crv/security/bugs/NT/netxtray.html">http://www.efri.hr/~crv/security/bugs/NT/netxtray.html</ref></refs><vuln_soft><prod name="NetXRay" vendor="Network General"><vers num="All Versions"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1208" published="1997-07-21" seq="1999-1208" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419337&amp;w=2">AIX ping, lchangelv, xlock fixes</ref><ref source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419330&amp;w=2">AIX ping (Exploit)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/803.php">ping-bo (803)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="4.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1209" published="1997-11-20" seq="1999-1209" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vendor_bulletins/VB-97.14.scoterm"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88131151000069&amp;w=2">19971204 scoterm exploit</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/690">sco-scoterm(690)</ref></refs><vuln_soft><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1210" published="1997-11-12" seq="1999-1210" severity="High" type="CVE"><desc><descript source="cve">xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is created when xterm is called with a DISPLAY environmental variable set to a display that xterm cannot access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87936891504885&amp;w=2">Digital Unix Security Problem</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/613.php">dec-xterm (613)</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num="4.0B"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1211" published="1991-03-27" seq="1999-1211" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-02.html">CA-1991-02</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/574.php">sun-intelnetd(574)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1212" published="1991-03-27" seq="1999-1212" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-02.html">CA-1991-02</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/574.php">sun-intelnetd(574)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.0.3"/><vers num="4.0.3c"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1213" published="1997-10-01" seq="1999-1213" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Dataguard" url="http://www2.dataguard.no/bugtraq/1997_4/0001.html">Security Bulletin for telnet services in HP-UX rel. 10.30</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/571.php">hp-telnetdos (571)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.30"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-1214" published="1997-09-15" seq="1999-1214" severity="Low" type="CVE"><desc><descript source="cve">The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="OpenBSD" url="http://www.openbsd.com/advisories/signals.txt">Vulnerability in I/O Signal Handling</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/556.php">openbsd-iosig (556</ref><ref source="OSVDB" url="http://www.osvdb.org/11062">11062</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.1"/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod><prod name="BSD" vendor="BSD"><vers num="4.4"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1215" published="1993-09-16" seq="1999-1215" severity="Medium" type="CVE"><desc><descript source="cve">LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-21.shtml">D-21</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1993-12.html">CA-1993-12</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/545.php">novell-login(545)</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="4.0"/><vers num="4.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1216" published="1993-04-22" seq="1999-1216" severity="High" type="CVE"><desc><descript source="cve">Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the &quot;no ip source-route&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1993-07.html">CA-1993-07</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-15.shtml">D-15</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/541.php">cisco-sourceroute(541)</ref></refs><vuln_soft><prod name="Cisco router" vendor="Cisco"><vers num="8.2"/><vers num="8.3"/><vers num="9.0"/><vers num="9.1"/><vers num="9.17" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-1999-1217" published="1997-07-25" seq="1999-1217" severity="Medium" type="CVE"><desc><descript source="cve">The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319435&amp;w=2">NT security - why bother?</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602726319426&amp;w=2">NT security - why bother?</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/526.php">nt-path (526)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1218" published="1993-02-18" seq="1999-1218" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1993-04.html">CA-1993-04</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/522.php">amiga-finger(522)</ref></refs><vuln_soft><prod name="Amiga UNIX" vendor="Commodore"><vers num="2.1p2a" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1219" published="1994-08-11" seq="1999-1219" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1994-13.html">CA-1994-13</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/e-33.shtml">E-33</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/511.php">sgi-prn-mgr(511)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/468">bid468</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.1"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1220" published="1997-08-24" seq="1999-1220" severity="High" type="CVE"><desc><descript source="cve">Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/7527">Vulnerability in Majordomo</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/502.php">majordomo-advertise (502)</ref></refs><vuln_soft><prod name="Majordomo" vendor="Great Circle Associates"><vers num="1.94.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1221" published="1996-11-17" seq="1999-1221" severity="Low" type="CVE"><desc><descript source="cve">dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/399.php">dgux-chpwd (399)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420141&amp;w=2">19961117 Digital Unix v3.x (v4.x?) security vulnerability</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num="3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-1222" published="1999-12-31" seq="1999-1222" severity="Medium" type="CVE"><desc><descript source="cve">Netbt.sys in Windows NT 4.0 allows remote malicious DNS servers to cause a denial of service (crash) by returning 0.0.0.0 as the IP address for a DNS host name lookup.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q188/5/71.ASP"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3893.php">dns-netbtsys-dos(3893)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="Terminal Server 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1223" published="1999-12-31" seq="1999-1223" severity="Medium" type="CVE"><desc><descript source="cve">IIS 3.0 allows remote attackers to cause a denial of service via a request to an ASP page in which the URL contains a large number of / (forward slash) characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q187/5/03.asp"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3892.php">url-asp-av(3892)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1224" published="1997-10-08" seq="1999-1224" severity="Low" type="CVE"><desc><descript source="cve">IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87635124302928&amp;w=2">IMAP4rev1 imapd server</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/349.php">imapd-core (349</ref></refs><vuln_soft><prod name="Imapd" vendor="University of Washington"><vers num=""/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1225" published="1997-08-24" seq="1999-1225" severity="Medium" type="CVE"><desc><descript source="cve">rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/archive/1/7535">Serious security flaw in rpc.mountd on several operating systems</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/347.php">mountd-file-exists (347)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/7526">19970824 Serious security flaw in rpc.mountd on several operating systems.</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="Solaris" vendor="Sun"><vers num=""/></prod><prod name="Ultrix" vendor="Digital"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-23" name="CVE-1999-1226" published="1999-10-28" seq="1999-1226" severity="Low" type="CVE"><desc><descript source="cve">Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="Securiteam" url="http://www.securiteam.com/exploits/3O5QCSAPPU.html">Netscape 4.7 and earlier vulnerable to </ref><ref source="XF" url="http://xforce.iss.net/static/3436.php">netscape-huge-key-dos(3436)</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1227" published="1999-07-30" seq="1999-1227" severity="High" type="CVE"><desc><descript source="cve">Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Ethereal" url="http://www.ethereal.com/lists/ethereal-dev/199907/msg00126.html"></ref><ref adv="1" source="Ethereal" url="http://www.ethereal.com/lists/ethereal-dev/199907/msg00130.html"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3334.php">ethereal-dev-capturec-root(3334)</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1228" published="1998-09-27" seq="1999-1228" severity="High" type="CVE"><desc><descript source="cve">Various modems that do not implement a guard time, or are configured with a guard time of 0, can allow remote attackers to execute arbitrary modem commands such as ATH, ATH0, etc., via a &quot;+++&quot; sequence that appears in ICMP packets, the subject of an e-mail message, IRC commands, and others.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90695973308453&amp;w=2">1+2=3, +++ATH0=Old school DoS</ref><ref adv="1" source="" url="http://www.macintouch.com/modemsecurity.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3320.php">global-village-modem-dos(3320)</ref></refs><vuln_soft><prod name="Quicktel" vendor="Logicode"><vers num="28.8"/></prod><prod name="Supra" vendor="Diamond"><vers num="33.6"/><vers num="v.90"/></prod><prod name="US Robotics" vendor="US Robotics"><vers num="33.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1229" published="1998-02-25" seq="1999-1229" severity="Low" type="CVE"><desc><descript source="cve">Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/8590"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/733.php">linux-quake2(733)</ref></refs><vuln_soft><prod name="Quake 2 server" vendor="id Software"><vers num="3.13" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1230" published="1997-12-24" seq="1999-1230" severity="Medium" type="CVE"><desc><descript source="cve">Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/8282">Quake II Remote Denial of Service</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/698.php">quake2-dos (698)</ref></refs><vuln_soft><prod name="Quake 2" vendor="Id Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1231" published="1999-06-09" seq="1999-1231" severity="Medium" type="CVE"><desc><descript source="cve">ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/14758"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2276.php">ssh-leak(2276)</ref></refs><vuln_soft><prod name="SSH2" vendor="SSH Communications Security"><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-1999-1232" published="1997-05-16" seq="1999-1232" severity="High" type="CVE"><desc><descript source="cve">Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420994&amp;w=2">Irix and WWW</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3316.php">sgi-day5datacopier (3316)</ref><ref source="OSVDB" url="http://www.osvdb.org/8559">8559</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1233" published="1999-12-31" seq="1999-1233" severity="High" type="CVE"><desc><descript source="cve">IIS 4.0 does not properly restrict access for the initial session request from a user&apos;s IP address if the address does not resolve to a DNS domain, aka the &quot;Domain Resolution&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms99-039.asp">MS99-039</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q241/5/62.asp"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/657">bid657</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3306.php">iis-unresolved-domain-access(3306)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1234" published="1999-10-26" seq="1999-1234" severity="Medium" type="CVE"><desc><descript source="cve">LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94096671308565&amp;w=2"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3293.php">msrpc-samr-open-dos(3293)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1235" published="1999-08-25" seq="1999-1235" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user&apos;s index.dat, or (2) people who are physically observing (&quot;shoulder surfing&quot;) another user to read the information from the status bar when the user moves the mouse over a link.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="XF" url="http://xforce.iss.net/static/3289.php">nt-ie5-user-ftp-password(3289)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1236" published="1999-10-01" seq="1999-1236" severity="Medium" type="CVE"><desc><descript source="cve">Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9910&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=662"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/731">bid731</ref><ref source="XF" url="http://xforce.iss.net/static/3285.php">iams-passwords-plaintext(3285)</ref></refs><vuln_soft><prod name="Internet Anywhere Mail Server" vendor="True North"><vers num="2.3.1"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-1237" published="1999-06-06" seq="1999-1237" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/14384"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2272.php">smbvalid-bo(2272)</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1238" published="1994-09-21" seq="1999-1238" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/advisories/1531">Security Vulnerability in CORE-DIAG fileset</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2262.php">hp-core-diag-fileset (2262</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.05" prev="1"/><vers num="8"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1239" published="1994-07-13" seq="1999-1239" severity="Medium" type="CVE"><desc><descript source="cve">HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/advisories/1559">Xauthority problem</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2261.php">hp-xauthority (2261)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1240" published="1996-11-26" seq="1999-1240" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2203.php">cddbd-bo (2203)</ref></refs><vuln_soft><prod name="cddbd" vendor="Gracenote"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1241" published="1999-05-06" seq="1999-1241" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2173.php">ie-filesystemobject(2173)</ref><ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html">http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1242" published="1994-02-07" seq="1999-1242" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="PacketStorm" url="http://packetstormsecurity.org/advisories/hpalert/003">Security Vulnerability in Subnetconfig</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2162.php">hp-subnet-config (2162)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.01"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-1243" published="1995-03-03" seq="1999-1243" severity="Medium" type="CVE"><desc><descript source="cve">SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-16.shtml">SGI IRIX Desktop Permissions Tool Vulnerability</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950301-01-P373">19950301-01-P373</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2113.php">sgi-permissions (2113)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.0.1" prev="1"/><vers num="6.0"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1244" published="1999-04-15" seq="1999-1244" severity="High" type="CVE"><desc><descript source="cve">IPFilter 3.2.3 through 3.2.10 allows local users to modify arbitrary files via a symlink attack on the saved output file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13303">19990415 FSA-99.04-IPFILTER-v3.2.10</ref><ref adv="1" source="XF" url="http://xforce.iss.net/static/2087.php">ipfilter-temp-file(2087)</ref></refs><vuln_soft><prod name="IPFilter" vendor="Darren Reed"><vers num="3.2.10"/><vers num="3.2.9"/><vers num="3.2.8"/><vers num="3.2.7"/><vers num="3.2.6"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-1245" published="1999-04-06" seq="1999-1245" severity="Medium" type="CVE"><desc><descript source="cve">vacm ucd-snmp SNMP server, version 3.52, does not properly disable access to the public community string, which could allow remote attackers to obtain sensitive information.</descript></desc><sols><sol source="nvd">This vulnerability was fixed in version 3.6 of ucd-snmpd.</sol></sols><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/static/2086.php">ucd-snmpd-community(2086)</ref></refs><vuln_soft><prod name="ucd-snmp" vendor="ucd-snmp"><vers num="3.52"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1246" published="1999-12-31" seq="1999-1246" severity="High" type="CVE"><desc><descript source="cve">Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q229/9/72.asp"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2068.php">siteserver-directmail-passwords(2068)</ref></refs><vuln_soft><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1247" published="1999-02-24" seq="1999-1247" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="PacketStorm" url="http://packetstormsecurity.org/advisories/hpalert/006">Security Vulnerability in DCE/9000</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2061.php">hp-dce9000 (2061)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1248" published="1994-11-30" seq="1999-1248" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="PacketStorm" url="http://packetstormsecurity.org/advisories/hpalert/019">Security Vulnerability in HP SupportWatch</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2058.php">hp-supportwatch (2058)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="8.0"/><vers num="8.02"/><vers num="8.06"/><vers num="9.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1249" published="1997-01-06" seq="1999-1249" severity="Medium" type="CVE"><desc><descript source="cve">movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Codetalker" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9701-047.html">HPSBUX9701-047</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2057.php">hp-movemail (2057)</ref><ref source="OSVDB" url="http://www.osvdb.org/8099">8099</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1250" published="1997-08-19" seq="1999-1250" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/7506">Lasso CGI security hole</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2044.php">http-cgi-lasso (2044)</ref></refs><vuln_soft><prod name="Lasso CGI" vendor="Blue World Communications"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1251" published="1996-12-24" seq="1999-1251" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Packetstorm" url="http://packetstormsecurity.org/advisories/hpalert/043">Vulnerability with direct audio user space code</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2010.php">hp-audio-panic (2010)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1252" published="1996-09-04" seq="1999-1252" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.15.sco">96:002</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1966.php">sco-system-call(1966)</ref><ref source="SCO" url="ftp://ftp.sco.COM/SSE/security_bulletins/SB.96:02a">96:002</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="2.0.x"/><vers num="2.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1253" published="1996-06-07" seq="1999-1253" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.10.sco">96:001</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1965.php">sco-kernel(1965)</ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB.96:01a">96:001</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0"/><vers num="5.0.2" prev="1"/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1254" published="1999-03-08" seq="1999-1254" severity="Medium" type="CVE"><desc><descript source="cve">Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/static/1947.php">win-redirects-freeze(1947)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92099515709467&amp;w=2">19990308 Winfreeze EXPLOIT  Win9x/NT</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1255" published="1999-02-19" seq="1999-1255" severity="Medium" type="CVE"><desc><descript source="cve">Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/static/1914.php">hyperseek-modify(1914)</ref></refs><vuln_soft><prod name="HyperSeek Search Engine" vendor="CCS Network"><vers num="2000" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1256" published="1999-03-04" seq="1999-1256" severity="Medium" type="CVE"><desc><descript source="cve">Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12744">19990304 Oracle Plaintext Password</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92056752115116&amp;w=2">19990304 Oracle Plaintext Password</ref><ref adv="1" source="XF" url="http://xforce.iss.net/static/1902.php">oracle-passwords(1902)</ref></refs><vuln_soft><prod name="Database Assistant" vendor="Oracle"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-1257" published="1997-11-26" seq="1999-1257" severity="High" type="CVE"><desc><descript source="cve">Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character, or (2) a ? (question mark).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/8134">Xyplex terminal server bug</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1825.php">xyplex-controlz-login (1825</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1826.php">xyplex-question-login (1826)</ref></refs><vuln_soft><prod name="Xyplex Terminal Server" vendor="Xyplex"><vers num="6.0.1 S1"/><vers num="6.0.2 S4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1258" published="1991-01-15" seq="1999-1258" severity="Medium" type="CVE"><desc><descript source="cve">rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/102"> rpc.pwdauthd can be used to gain remote system knowledge</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1782.php">sun-pwdauthd (1782)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.1" prev="1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-20" name="CVE-1999-1259" published="1999-12-31" seq="1999-1259" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q189/5/29.asp"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1780.php">office-extraneous-data(1780)</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers edition="Mac" num="98"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-1260" published="1999-02-15" seq="1999-1260" severity="High" type="CVE"><desc><descript source="cve">mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91910115718150&amp;w=2">19990215 KSR[T] Advisory #10: mSQL ServerStats</ref><ref source="XF" url="http://xforce.iss.net/static/1777.php">msql-serverstats(1777)</ref></refs><vuln_soft><prod name="mSQL" vendor="Hughes"><vers num="2.0.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-1261" published="1997-10-24" seq="1999-1261" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87773365324657&amp;w=2">Vulnerability in metamail</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1677.php">metamail-file-creation (1677</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12433">19990211 Rainbow Six Buffer Overflow.....</ref><ref source="XF" url="http://xforce.iss.net/static/1772.php">rainbowsix-nick-bo(1772)</ref></refs><vuln_soft><prod name="Metamail" vendor="Metamail Corporation"><vers num="7.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-11" name="CVE-1999-1262" published="1997-08-01" seq="1999-1262" severity="Medium" type="CVE"><desc><descript source="cve">Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/1998/11/msg00309.html">Java Redirect Bug - Netscpape 4.0[678] and 4.5</ref><ref source="Ben Mesanders web page" url="http://neurosis.hungry.com/~ben/msie_bug/">Demo of Browser Security Hole</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12231">19990202 Unsecured server in applets under Netscape</ref><ref source="XF" url="http://xforce.iss.net/static/1727.php">java-socket-open(1727)</ref></refs><vuln_soft><prod name="Netscape Communicator" vendor="Netscape"><vers num="4.01"/><vers num="4.06"/><vers num="4.07"/><vers num="4.08"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-23" name="CVE-1999-1263" published="2003-08-15" seq="1999-1263" severity="Low" type="CVE"><desc><descript source="cve">Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/caldera/2003-q3/0004.html">SCO Security Advisory </ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87773365324657&amp;w=2">19971024 Vulnerability in metamail</ref><ref source="XF" url="http://xforce.iss.net/static/1677.php">metamail-file-creation(1677)</ref></refs><vuln_soft><prod name="Metamail" vendor="Metamail Corporation"><vers num="2.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1264" published="1999-01-21" seq="1999-1264" severity="High" type="CVE"><desc><descript source="cve">WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been expliticly disabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12048">19990121 WebRamp M3 remote network access bug</ref><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91815321510224&amp;w=2">19990203 WebRamp M3 Perceived Bug</ref><ref source="XF" url="http://xforce.iss.net/static/1670.php">webramp-remote-access(1670)</ref></refs><vuln_soft><prod name="WebRamp" vendor="Ramp Networks"><vers num="M3"/><vers num="M3t"/><vers num="M3i"/><vers num="300"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1265" published="1998-09-22" seq="1999-1265" severity="Medium" type="CVE"><desc><descript source="cve">SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a &quot;(&quot; (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90649892424117&amp;w=2">Re: WARNING! SMTP Denial of Service in SLmail ver 3.1</ref><ref adv="1" source="NT Bugtraq" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90650438826447&amp;w=2">WARNING! SMTP Denial of Service in SLmail ver 3.1</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1664.php">slmail-parens-overload(1664)</ref></refs><vuln_soft><prod name="Slmail" vendor="Seatle Lab Software"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-1266" published="1997-06-13" seq="1999-1266" severity="Medium" type="CVE"><desc><descript source="cve">rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/6978">                  rshd gives away usernames</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1660.php">rsh-username-leaks (1660)</ref></refs><vuln_soft><prod name="Metamail" vendor="Metamail Corporation"><vers num="7.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1267" published="1997-05-05" seq="1999-1267" severity="Medium" type="CVE"><desc><descript source="cve">KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420906&amp;w=2">Hole in the KDE desktop</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1646.php">kde-flawed-ipc (1646)</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-1268" published="1999-01-06" seq="1999-1268" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="MISC" url="http://lists.kde.org/?l=kde-devel&amp;m=91560433413263&amp;w=2">http://lists.kde.org/?l=kde-devel&amp;m=91560433413263&amp;w=2</ref><ref adv="1" source="XF" url="http://xforce.iss.net/static/1645.php">kde-konsole-hijack(1645)</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1269" published="1998-02-06" seq="1999-1269" severity="Low" type="CVE"><desc><descript source="cve">Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/8506"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1641.php">kde-kss-file-clobber(1641)</ref></refs><vuln_soft><prod name="KDE beta 3" vendor="KDE"><vers num="Initial"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1270" published="1998-07-11" seq="1999-1270" severity="Medium" type="CVE"><desc><descript source="cve">KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="" url="http://lists.kde.org/?l=kde-devel&amp;m=90221974029738&amp;w=2">KMail/PGP security bug</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1639.php">kde-kmail-passphrase-leak(1639)</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1271" published="1998-06-11" seq="1999-1271" severity="Low" type="CVE"><desc><descript source="cve">Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/9511"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1636.php">dreamweaver-weak-passwords(1636)</ref></refs><vuln_soft><prod name="Dreamweaver" vendor="Macromedia"><vers num="Initial"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1272" published="1998-03-01" seq="1999-1272" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX">19980301-01-PX</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1635.php">irix-cdrom-confidence (1635)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1273" published="1998-02-20" seq="1999-1273" severity="High" type="CVE"><desc><descript source="cve">Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/8551"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1627.php">squid-regexp-acl(1627)</ref></refs><vuln_soft><prod name="Squid Web Proxy" vendor="National Science Foundation"><vers num="1.1.20"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1274" published="1997-12-29" seq="1999-1274" severity="Medium" type="CVE"><desc><descript source="cve">iPass RoamServer 3.1 creates temporary files with world-writable permissions.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/8307">iPass RoamServer 3.1</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1625.php">ipass-temporary-files (1625)</ref></refs><vuln_soft><prod name="RoamServer" vendor="iPass"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1275" published="1997-09-08" seq="1999-1275" severity="Medium" type="CVE"><desc><descript source="cve">Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/9478">Password unsecurity in cc:Mail release 8</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1619.php">lotus-ccmail-passwords (1619</ref></refs><vuln_soft><prod name="Lotus cc:Mail" vendor="IBM"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1276" published="1998-12-07" seq="1999-1276" severity="High" type="CVE"><desc><descript source="cve">fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/1998/19981207">fte-console: does not drop its root priviliges</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1609.php">fte-console-privileges (1609</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1277" published="1998-12-24" seq="1999-1277" severity="Medium" type="CVE"><desc><descript source="cve">BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="NT Bugtraq" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91487886514546&amp;w=2">BackWeb - Password issue (used by NAI for Corporate customer notification)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1565.php">backweb-cleartext-passwords(1565)</ref></refs><vuln_soft><prod name="BackWeb Client" vendor="BackWeb Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1278" published="1998-12-25" seq="1999-1278" severity="High" type="CVE"><desc><descript source="cve">nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1550.php">http-cgi-nlog-netbios(1550)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91470326629357&amp;w=2">19981225 Re: Nlog v1.0 Released - Nmap 2.x log management / analyzing tool</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91471400632145&amp;w=2">19981226 Nlog 1.1b released - security holes fixed</ref></refs><vuln_soft><prod name="nlog" vendor="nlog"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1279" published="1999-12-31" seq="1999-1279" severity="Medium" type="CVE"><desc><descript source="cve">An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other&apos;s folders when the users share the same Local APPC LU.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q138/0/01.asp"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1548.php">snaserver-shared-folders(1548)</ref></refs><vuln_soft><prod name="SNA Server" vendor="Microsoft"><vers num="2.11"/><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1280" published="1998-12-03" seq="1999-1280" severity="High" type="CVE"><desc><descript source="cve">Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/11512">Remote Tools w/Exceed v.6.0.1.0 fer 95</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1547.php">exceed-cleartext-passwords(1547)</ref></refs><vuln_soft><prod name="Exceed" vendor="Hummingbird"><vers num="6.0.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1281" published="1998-12-26" seq="1999-1281" severity="Medium" type="CVE"><desc><descript source="cve">Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/11720">Breeze Network Server remote reboot and other bogosity</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1544.php">breeze-remote-reboot(1544)</ref></refs><vuln_soft><prod name="Breeze Network Server" vendor="WindDance Networks Corporation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-1999-1282" published="1998-12-10" seq="1999-1282" severity="Medium" type="CVE"><desc><descript source="cve">RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/11543">RealSystem passwords</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1542.php">realsystem-readable-conf-file(1542)</ref></refs><vuln_soft><prod name="RealSystem G2 Server" vendor="RealNetworks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1283" published="1998-08-14" seq="1999-1283" severity="Medium" type="CVE"><desc><descript source="cve">Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10320">URL exploit to crash Opera Browser</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1541.php">opera-slash-crash(1541)</ref></refs><vuln_soft><prod name="Opera Web Browser" vendor="Opera Software"><vers num="3.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1284" published="1998-11-05" seq="1999-1284" severity="Medium" type="CVE"><desc><descript source="cve">NukeNabber allows remote attackers to cause a denial of service by connecting to the NukeNabber port (1080) without sending any data, which causes the CPU usage to rise to 100% from the report.exe program that is executed upon the connection.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/11131">various *lame* DoS attacks</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1540.php">nukenabber-timeout-dos(1540)</ref><ref source="MISC" url="http://www.dynamsol.com/puppet/text/new.txt">http://www.dynamsol.com/puppet/text/new.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91063407332594&amp;w=2">19981107 Re: various *lame* DoS attacks</ref></refs><vuln_soft><prod name="NukeNabber" vendor="Puppets Place"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1285" published="1998-12-27" seq="1999-1285" severity="Low" type="CVE"><desc><descript source="cve">Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91495921611500&amp;w=2">[patch] fix for urandom read(2) not interruptible</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1472.php">linux-random-read-dos(1472)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.1.132" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1286" published="1997-05-09" seq="1999-1286" severity="High" type="CVE"><desc><descript source="cve">addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420927&amp;w=2">Irix: misc</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1433.php">irix-addnetpr (1433)</ref><ref source="" url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX"></ref><ref source="BID" url="http://www.securityfocus.com/bid/330">330</ref><ref source="OSVDB" url="http://www.osvdb.org/8560">8560</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2" prev="1"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-1999-1287" published="1999-12-31" seq="1999-1287" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Statslab" url="http://www.statslab.cam.ac.uk/~sret1/analog/security.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1410.php">analog-remote-file(1410)</ref></refs><vuln_soft><prod name="Analog" vendor="Stephen Turner"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-1288" published="1998-11-19" seq="1999-1288" severity="Medium" type="CVE"><desc><descript source="cve">Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Caldera" url="http://www.caldera.com/support/security/advisories/SA-1998.35.txt">Suid problem in samba</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1406.php">samba-wsmbconf (1406)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/11397">19981119 Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num=""/></prod><prod name="Samba" vendor="Samba"><vers num="1.9.18"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num=""/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1289" published="1998-11-11" seq="1999-1289" severity="High" type="CVE"><desc><descript source="cve">ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/11233">WARNING: Another ICQ IP address vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1398.php">icq-ip-info(1398)</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="98 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1290" published="1999-12-31" seq="1999-1290" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91127951426494&amp;w=2"></ref><ref adv="1" patch="1" source="Ayukov" url="http://www.ayukov.com/nftp/history.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1397.php">nftp-bo(1397)</ref></refs><vuln_soft><prod name="nFTP" vendor="Chris Matthee"><vers num="1.40"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1291" published="1998-10-05" seq="1999-1291" severity="Medium" type="CVE"><desc><descript source="cve">TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target&apos;s last sequence number from the resulting packet, then spoofing a reset to the target.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10789">New Windows Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1383.php">nt-brkill(1383)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1292" published="1998-09-01" seq="1999-1292" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise7.php">Remote Buffer Overflow in the Kolban Webcam32 Program</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1366.php">webcam32-buffer-overflow(1366)</ref></refs><vuln_soft><prod name="Webcam32" vendor="Kolban"><vers num="4.8.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-1293" published="1999-12-31" seq="1999-1293" severity="High" type="CVE"><desc><descript source="cve">mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88413292830649&amp;w=2"></ref><ref adv="1" patch="1" source="Apache" url="http://www.apache.org/info/security_bulletin_1.2.5.html"></ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.2.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-20" name="CVE-1999-1294" published="1999-12-31" seq="1999-1294" severity="Low" type="CVE"><desc><descript source="cve">Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q146/6/04.asp"></ref><ref source="XF" url="http://xforce.iss.net/static/562.php">nt-filemgr(562)</ref></refs><vuln_soft><prod name="Windows 3.51" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1295" published="1996-09-17" seq="1999-1295" severity="Medium" type="CVE"><desc><descript source="cve">Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.16.transarc"></ref><ref source="CERT" url="http://www.cert.org/vendor_bulletins/VB-96.16.transarc">VB-96.16</ref><ref source="XF" url="http://xforce.iss.net/static/7154.php">dfs-login-groups(7154)</ref></refs><vuln_soft><prod name="DCE Distributed File System" vendor="Transarc"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1296" published="1997-04-29" seq="1999-1296" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420878&amp;w=2">vulnerabilities in kerberos</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1297" published="1998-07-15" seq="1999-1297" severity="Low" type="CVE"><desc><descript source="cve">cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100452&amp;zone_32=10045%2A%20">100452-74</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7482.php">sun-cmdtool-echo (7482)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.1"/><vers edition="A" num="1.1.1a"/><vers num="1.1.2"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1298" published="1997-04-07" seq="1999-1298" severity="High" type="CVE"><desc><descript source="cve">Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-97:03.sysinstall.asc">FreeBSD-SA-97:03</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7537.php">freebsd-sysinstall-ftp-password (7537)</ref><ref source="XF" url="http://www.iss.net/security_center/static/7537.php">freebsd-sysinstall-ftp-password(7537)</ref><ref source="OSVDB" url="http://www.osvdb.org/6087">6087</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2.1" prev="1"/><vers num="2.1.0"/><vers num="2.1.5"/><vers num="2.1.6"/><vers num="2.1.7"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1299" published="1997-02-03" seq="1999-1299" severity="High" type="CVE"><desc><descript source="cve">rcp on various Linux systems including Red Hat 4.0 allows a &quot;nobody&quot; user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420509&amp;w=2">Linux rcp bug</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1300" published="1999-12-31" seq="1999-1300" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-31.shtml"></ref></refs><vuln_soft><prod name="UNICOS" vendor="Cray"><vers num="6.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1301" published="1996-07-16" seq="1999-1301" severity="High" type="CVE"><desc><descript source="cve">A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-31.shtml">G-31: FreeBSD Security Vulnerabilities (ppp, rdist, rz)</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc">FreeBSD-SA-96:17</ref><ref source="XF" url="http://www.iss.net/security_center/static/7540.php">rzsz-command-execution(7540)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-10" name="CVE-1999-1302" published="1994-11-30" seq="1999-1302" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05: SCO Unix at, login, prwarn, sadc, and pt_chmod Patches Available</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7586.php">sco-pt_chmod (7586</ref><ref source="CERT" url="http://ftp.cerias.purdue.edu/pub/advisories/cert/cert_bulletins/VB-94:01.sco">VB-94:01</ref><ref source="OSVDB" url="http://www.osvdb.org/8797">8797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7586">sco-pt_chmod(7586)</ref></refs><vuln_soft><prod name="OpenServer Network System" vendor="SCO"><vers num="3.0"/></prod><prod name="Open Desktop Lite" vendor="SCO"><vers num="3.0"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/><vers num="2.0"/></prod><prod name="OpenServer Enterprise System" vendor="SCO"><vers num="3.0"/></prod><prod name="Unix" vendor="SCO"><vers num="4.2" prev="1"/><vers num="3.2"/><vers num="4.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1303" published="1994-11-30" seq="1999-1303" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05: SCO Unix at, login, prwarn, sadc, and pt_chmod Patches Available</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7587.php">sco-prwarn (7587)</ref></refs><vuln_soft><prod name="Open Desktop Lite" vendor="SCO"><vers num="3.0"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="2.0"/><vers num="3.0"/></prod><prod name="OpenServer Network System" vendor="SCO"><vers num="3.0"/></prod><prod name="OpenServer Enterprise System" vendor="SCO"><vers num="3.0"/></prod><prod name="Unix" vendor="SCO"><vers num="4.2" prev="1"/><vers num="3.2"/><vers num="4.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1304" published="1994-11-30" seq="1999-1304" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05: SCO Unix at, login, prwarn, sadc, and pt_chmod Patches Available</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7588.php">sco-login (7588)</ref></refs><vuln_soft><prod name="Open Desktop Lite" vendor="SCO"><vers num="3.0"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="2.0"/><vers num="3.0"/></prod><prod name="OpenServer Network System" vendor="SCO"><vers num="3.0"/></prod><prod name="OpenServer Enterprise System" vendor="SCO"><vers num="3.0"/></prod><prod name="Unix" vendor="SCO"><vers num="4.2" prev="1"/><vers num="3.2"/><vers num="4.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1305" published="1994-11-30" seq="1999-1305" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in &quot;at&quot; program in SCO UNIX 4.2 and earlier allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-05.shtml">F-05: SCO Unix at, login, prwarn, sadc, and pt_chmod Patches Available</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7589.php">sco-at (7589)</ref></refs><vuln_soft><prod name="Open Desktop Lite" vendor="SCO"><vers num="3.0"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="2.0"/><vers num="3.0"/></prod><prod name="OpenServer Network System" vendor="SCO"><vers num="3.0"/></prod><prod name="OpenServer Enterprise System" vendor="SCO"><vers num="3.0"/></prod><prod name="Unix" vendor="SCO"><vers num="4.2" prev="1"/><vers num="3.2"/><vers num="4.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1306" published="1992-12-10" seq="1999-1306" severity="High" type="CVE"><desc><descript source="cve">Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the &quot;established&quot; keyword is set, which could allow attackers to bypass filters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-20.html">CA-1992-20</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1307" published="1999-12-31" seq="1999-1307" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Dataguard" url="http://www.dataguard.no/bugtraq/1994_4/0676.html"></ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-06.shtml"></ref></refs><vuln_soft><prod name="UnixWare" vendor="Novell"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1308" published="1997-07-31" seq="1999-1308" severity="Medium" type="CVE"><desc><descript source="cve">Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-91.shtml">H-91: HP-UX Large UID&apos;s and GID&apos;s Vulnerability</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-09.shtml">H-09</ref><ref source="XF" url="http://www.iss.net/security_center/static/7594.php">hp-large-uid-gid(7594)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1309" published="1996-08-30" seq="1999-1309" severity="High" type="CVE"><desc><descript source="cve">Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Dataguard" url="http://www.dataguard.no/bugtraq/1994_1/0040.html"></ref><ref adv="1" source="Dataguard" url="http://www.dataguard.no/bugtraq/1994_1/0042.html"></ref><ref adv="1" source="Dataguard" url="http://www.dataguard.no/bugtraq/1994_1/0048.html"></ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.12.sendmail.vulnerabilities">CA-94:12</ref><ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0043.html">19940315 so...</ref><ref source="BUGTRAQ" url="http://www.dataguard.no/bugtraq/1994_1/0078.html">19940327 sendmail exploit script - resend</ref><ref source="XF" url="http://xforce.iss.net/static/7155.php">sendmail-debug-gain-root(7155)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="8.6.7" prev="1"/></prod></vuln_soft></entry><entry modified="2005-10-31" name="CVE-1999-1310" published="1994-11-04" reject="1" seq="1999-1310" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1022.  Reason: This candidate is a duplicate of CVE-1999-1022.  Notes: All CVE users should reference CVE-1999-1022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1311" published="1997-01-07" seq="1999-1311" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-21.shtml">H-21: HP Security Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7668.php">hp-dt-bypass-auth (7668</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1312" published="1993-02-24" seq="1999-1312" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1993-05.html">CA-1993-05</ref><ref source="XF" url="http://xforce.iss.net/static/7142.php">openvms-local-privilege-elevation(7142)</ref></refs><vuln_soft><prod name="DEC OpenVMS VAX" vendor="DEC"><vers num="5.5.2" prev="1"/></prod><prod name="DEC OpenVMS AXP" vendor="DEC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1313" published="1996-05-23" seq="1999-1313" severity="Medium" type="CVE"><desc><descript source="cve">Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml">G-24: FreeBSD Security Vulnerabilities</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:11.man.asc">FreeBSD-SA-96:11</ref><ref source="XF" url="http://xforce.iss.net/static/7348.php">bsd-man-command-sequence(7348)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2" prev="1"/><vers num="2.0"/><vers num="2.0.5"/><vers num="2.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1314" published="1996-05-17" seq="1999-1314" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7429.php">unionfs-mount-ordering (7429)</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:10.mount_union.asc">FreeBSD-SA-96:10</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/g-24.shtml">G-24</ref><ref source="XF" url="http://www.iss.net/security_center/static/7429.php">unionfs-mount-ordering(7429)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2" prev="1"/><vers num="2.0"/><vers num="2.0.5"/><vers num="2.1.0"/><vers num="2.1 Stable"/><vers num="2.2 Current"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1315" published="1999-12-31" seq="1999-1315" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/f-04.shtml">F-04: Security Vulnerabilities in DECnet/OSI for OpenVMS</ref></refs><vuln_soft><prod name="DEC OpenVMS" vendor="DEC"><vers num="5.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-1316" published="1999-12-31" seq="1999-1316" severity="High" type="CVE"><desc><descript source="cve">Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user&apos;s name, which could make it easier for an attacker to guess.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q247/9/75.asp"></ref><ref source="XF" url="http://xforce.iss.net/static/7391.php">passfilt-fullname(7391)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Server 4.0 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1317" published="1999-12-31" seq="1999-1317" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 SP4 and earlier allows local users to gain privileges by modifying the symbolic link table in the \?? object folder using a different case letter (upper or lower) to point to a different device.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92127046701349&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92162979530341&amp;w=2"></ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q222/1/59.asp"></ref><ref source="XF" url="http://xforce.iss.net/static/7398.php">nt-symlink-case(7398)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1318" published="1993-09-17" seq="1999-1318" severity="High" type="CVE"><desc><descript source="cve">/usr/5bin/su in SunOS 4.1.3 and earlier uses a search path that includes the current working directory (.), which allows local users to gain privileges via Trojan horse programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches%2F100630&amp;zone_32=112193%2A%20">100630-02</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7480.php">sun-su-path (7480)</ref><ref source="XF" url="http://www.iss.net/security_center/static/7480.php">sun-su-path(7480)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="1.0"/><vers num="1.0.1"/><vers num="1.1"/><vers num="1.1c"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3" prev="1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3c"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1319" published="1996-01-03" seq="1999-1319" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19960101-01-PX">19960101-01-PX</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7430.php">irix-object-server (7430)</ref><ref source="XF" url="http://www.iss.net/security_center/static/7430.php">irix-object-server(7430)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.2"/><vers num="5"/><vers num="6.0"/><vers num="6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1320" published="1999-12-31" seq="1999-1320" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-01.shtml">D-01: Novell NetWare Access Rights Vulnerability</ref><ref source="XF" url="http://www.iss.net/security_center/static/7213.php">netware-packet-spoofing-privileges(7213)</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="3.x" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1321" published="1998-11-05" seq="1999-1321" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ssh 1.2.26 client with Kerberos V enabled could allow remote attackers to cause a denial of service or execute arbitrary commands via a long DNS hostname that is not properly handled during TGT ticket passing.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Bugtraq" url="http://lists.netspace.org/cgi-bin/wa?A2=ind9811A&amp;L=bugtraq&amp;P=R4814">security patch for ssh-1.2.26 kerberos code</ref><ref source="OSVDB" url="http://www.osvdb.org/4883">4883</ref></refs><vuln_soft><prod name="Kerberos" vendor="MIT"><vers num="V"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-1999-1322" published="1998-11-12" seq="1999-1322" severity="Medium" type="CVE"><desc><descript source="cve">The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91096758513985&amp;w=2">19981112 exchverify.log</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91133714919229&amp;w=2">19981117 Re: exchverify.log - update #1</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num=""/></prod><prod name="Inoculan AV client" vendor="Computer Associates"><vers num=""/></prod><prod name="1ArcServe Backup" vendor="Computer Associates"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1323" published="1999-04-09" seq="1999-1323" severity="Medium" type="CVE"><desc><descript source="cve">Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92370067416739&amp;w=2">19990409 NAV for MS Exchange &amp; Internet Email Gateways</ref></refs><vuln_soft><prod name="Norton AntiVirus for Internet Email Gateways" vendor="Symantec"><vers num="1.0.1.7" prev="1"/></prod><prod name="Norton AntiVirus MS Exchange" vendor="Symantec"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1324" published="1999-12-31" seq="1999-1324" severity="High" type="CVE"><desc><descript source="cve">VAXstations running Open VMS 5.3 through 5.5-2 with VMS DECwindows or MOTIF do not properly disable access to user accounts that exceed the break-in limit threshold for failed login attempts, which makes it easier for attackers to conduct brute force password guessing.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/d-06.shtml"></ref><ref source="XF" url="http://xforce.iss.net/static/7225.php">openvms-sysgen-enabled(7225)</ref></refs><vuln_soft><prod name="DEC OpenVMS VAX" vendor="DEC"><vers num="5.3"/><vers num="5.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1325" published="1999-12-31" seq="1999-1325" severity="High" type="CVE"><desc><descript source="cve">SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/c-19.shtml"></ref><ref source="XF" url="http://xforce.iss.net/static/7261.php">vaxvms-sas-gain-privileges(7261)</ref></refs><vuln_soft><prod name="SAS System" vendor="VAX VMS"><vers num="5.18"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-1326" published="1997-07-04" seq="1999-1326" severity="Medium" type="CVE"><desc><descript source="cve">wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420401&amp;w=2">serious security bug in wu-ftpd v2.4</ref><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420408&amp;w=2">serious security bug in wu-ftpd v2.4 -- PATCH</ref><ref source="XF" url="http://xforce.iss.net/static/7169.php">wuftpd-abor-gain-privileges(7169)</ref></refs><vuln_soft><prod name="Wu-ftpd" vendor="Washington University"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1327" published="1999-12-31" seq="1999-1327" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125826&amp;w=2"></ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/rh51-errata-general.html"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref><ref source="XF" url="http://www.iss.net/security_center/static/7239.php">linuxconf-lang-bo(7239)</ref><ref source="OSVDB" url="http://www.osvdb.org/6065">6065</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1328" published="1999-12-31" seq="1999-1328" severity="High" type="CVE"><desc><descript source="cve">linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90383955231511&amp;w=2"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf">http://www.redhat.com/support/errata/rh51-errata-general.html#linuxconf</ref><ref source="XF" url="http://www.iss.net/security_center/static/7232.php">linuxconf-symlink-gain-privileges(7232)</ref><ref source="OSVDB" url="http://www.osvdb.org/6068">6068</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1329" published="1999-12-31" seq="1999-1329" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/rh50-errata-general.html"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit">http://www.redhat.com/support/errata/rh50-errata-general.html#SysVinit</ref><ref source="XF" url="http://www.iss.net/security_center/static/7250.php">sysvinit-root-bo(7250)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1330" published="1999-12-31" seq="1999-1330" severity="Medium" type="CVE"><desc><descript source="cve">The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602661419259&amp;w=2"></ref><ref source="Debian" url="http://lists.openresources.com/Debian/debian-bugs-closed/msg00581.html">Bug#11120</ref><ref source="RedHat" url="http://www.redhat.com/support/errata/rh42-errata-general.html"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#db">http://www.redhat.com/support/errata/rh42-errata-general.html#db</ref><ref source="XF" url="http://www.iss.net/security_center/static/7244.php">linux-libdb-snprintf-bo(7244)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1331" published="1999-12-31" seq="1999-1331" severity="Low" type="CVE"><desc><descript source="cve">netcfg 2.16-1 in Red Hat Linux 4.2 allows the Ethernet interface to be controlled by users on reboot when an option is set, which allows local users to cause a denial of service by shutting down the interface.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/rh42-errata-general.html"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg">http://www.redhat.com/support/errata/rh42-errata-general.html#netcfg</ref><ref source="XF" url="http://www.iss.net/security_center/static/7245.php">netcfg-ethernet-dos(7245)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1332" published="1999-12-31" seq="1999-1332" severity="Low" type="CVE"><desc><descript source="cve">gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88603844115233&amp;w=2"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#gzip">http://www.redhat.com/support/errata/rh50-errata-general.html#gzip</ref><ref source="DEBIAN" url="http://www.debian.org/security/2003/dsa-308">DSA-308</ref><ref source="BID" url="http://www.securityfocus.com/bid/7845">7845</ref><ref source="OSVDB" url="http://www.osvdb.org/3812">3812</ref><ref source="XF" url="http://www.iss.net/security_center/static/7241.php">gzip-gzexe-tmp-symlink(7241)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1333" published="1999-12-31" seq="1999-1333" severity="High" type="CVE"><desc><descript source="cve">automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89042322924057&amp;w=2"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp">http://www.redhat.com/support/errata/rh50-errata-general.html#ncftp</ref><ref source="XF" url="http://www.iss.net/security_center/static/7240.php">ncftp-autodownload-command-execution(7240)</ref><ref source="OSVDB" url="http://www.osvdb.org/6111">6111</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1334" published="1999-12-31" seq="1999-1334" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88609666024181&amp;w=2">ID #:   filt-bof-007</ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#elm">http://www.redhat.com/support/errata/rh50-errata-general.html#elm</ref></refs><vuln_soft><prod name="Elm" vendor="Elm Development Group"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1335" published="1999-12-31" seq="1999-1335" severity="Medium" type="CVE"><desc><descript source="cve">snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="RedHat" url="http://www.redhat.com/support/errata/rh40-errata-general.htmlcmu-snmp"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp">http://www.redhat.com/support/errata/rh40-errata-general.html#cmu-snmp</ref><ref source="XF" url="http://xforce.iss.net/static/7251.php">cmusnmp-read-write(7251)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1336" published="1999-08-12" seq="1999-1336" severity="Medium" type="CVE"><desc><descript source="cve">3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93458364903256&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93492615408725&amp;w=2"></ref><ref source="OSVDB" url="http://www.osvdb.org/6057">6057</ref></refs><vuln_soft><prod name="Hiper ARC" vendor="3Com"><vers num="4.2.29" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-1337" published="1999-08-01" seq="1999-1337" severity="Medium" type="CVE"><desc><descript source="cve">FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93370073207984&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/archive/1/24704"></ref><ref source="XF" url="http://www.iss.net/security_center/static/9873.php">midnight-commander-data-disclosure(9873)</ref><ref source="OSVDB" url="http://www.osvdb.org/5921">5921</ref></refs><vuln_soft><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1338" published="1999-07-21" seq="1999-1338" severity="Medium" type="CVE"><desc><descript source="cve">Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93259112204664&amp;w=2">19990721 Delegate creates directories writable for anyone</ref></refs><vuln_soft><prod name="DeleGate" vendor="DeleGate"><vers num="5.9.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1339" published="1999-12-31" seq="1999-1339" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic) via a ping -R (record route) command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277766505061&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93277426802802&amp;w=2"></ref><ref source="" url="http://www.kernel.org/pub/linux/kernel/v2.2/patch-2.2.11.gz"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7257.php">ipchains-ping-route-dos(7257)</ref><ref source="OSVDB" url="http://www.osvdb.org/6105">6105</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.2"/></prod><prod name="Linux" vendor="Linux"><vers num="2.2.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1340" published="1999-11-04" seq="1999-1340" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94173799532589&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/765">bid765</ref></refs><vuln_soft><prod name="Hylafax" vendor="Hylafax"><vers num="4.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1341" published="1999-10-22" seq="1999-1341" severity="Medium" type="CVE"><desc><descript source="cve">Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94061108411308&amp;w=2"></ref><ref source="XF" url="http://xforce.iss.net/static/7858.php">linux-tiocsetd-forge-packets(7858)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.3.18" prev="1"/><vers num="2.2.13 pre15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1342" published="1999-10-17" seq="1999-1342" severity="Medium" type="CVE"><desc><descript source="cve">ICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server&apos;s UDP port.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94042342010662&amp;w=2"></ref></refs><vuln_soft><prod name="ActiveList Server" vendor="ICQ"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1343" published="1999-10-13" seq="1999-1343" severity="Medium" type="CVE"><desc><descript source="cve">HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93986405412867&amp;w=2"></ref></refs><vuln_soft><prod name="DocuColor" vendor="Xerox"><vers num="4 LP"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1344" published="1999-10-05" seq="1999-1344" severity="High" type="CVE"><desc><descript source="cve">Auto_FTP.pl script in Auto_FTP 0.2 stores usernames and passwords in plaintext in the auto_ftp.conf configuration file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923873006014&amp;w=2">19991005 Auto_FTP v0.02 Advisory</ref></refs><vuln_soft><prod name="Auto_FTP" vendor="Auto_FTP"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1345" published="1999-10-05" seq="1999-1345" severity="Medium" type="CVE"><desc><descript source="cve">Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923873006014&amp;w=2">19991005 Auto_FTP v0.02 Advisory</ref></refs><vuln_soft><prod name="Auto_FTP" vendor="Auto_FTP"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1346" published="1999-10-07" seq="1999-1346" severity="High" type="CVE"><desc><descript source="cve">PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93942774609925&amp;w=2"></ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1347" published="1999-10-07" seq="1999-1347" severity="Medium" type="CVE"><desc><descript source="cve">Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93942774609925&amp;w=2"></ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1348" published="1999-06-30" seq="1999-1348" severity="Low" type="CVE"><desc><descript source="cve">Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93220073515880&amp;w=2"></ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1349" published="1999-10-06" seq="1999-1349" severity="Medium" type="CVE"><desc><descript source="cve">NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923679004325&amp;w=2"></ref></refs><vuln_soft><prod name="Omni-NFS X Enterprise" vendor="XLink Technology"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1350" published="1999-09-29" seq="1999-1350" severity="Medium" type="CVE"><desc><descript source="cve">ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93871933521519&amp;w=2"></ref></refs><vuln_soft><prod name="ARCAD" vendor="ARCAD Systemhaus"><vers num="0.078_5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-1999-1351" published="1999-09-24" seq="1999-1351" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the &quot;Listen to !nick &lt;soundname&gt; requests&quot; option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/archive/1/28909"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93845560631314&amp;w=2">19990924 Kvirc bug</ref><ref source="XF" url="http://www.iss.net/security_center/static/7761.php">kvirc-dot-directory-traversal(7761)</ref></refs><vuln_soft><prod name="IRC client" vendor="KVIrc"><vers num="0.9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1352" published="1999-09-28" seq="1999-1352" severity="Medium" type="CVE"><desc><descript source="cve">mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93855134409747&amp;w=2"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1353" published="1999-09-07" seq="1999-1353" severity="Medium" type="CVE"><desc><descript source="cve">Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2) user passwords in the Userbase.dbf data file, which could allow local users to gain privielges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93698162708211&amp;w=2"></ref></refs><vuln_soft><prod name="MsgCore" vendor="Nosque"><vers num="2.14"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1354" published="1999-08-30" seq="1999-1354" severity="Medium" type="CVE"><desc><descript source="cve">E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93637687305327&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93698283309513&amp;w=2"></ref></refs><vuln_soft><prod name="FirstClass Internet Server" vendor="Softarc"><vers num="5.506" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1355" published="1999-12-31" seq="1999-1355" severity="High" type="CVE"><desc><descript source="cve">BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93542118727732&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93654336516711&amp;w=2"></ref><ref adv="1" source="Compaq" url="http://www.compaq.com/products/servers/management/advisory.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3231.php">management-pfcuser(3231)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93759822430801&amp;w=2">19990915 (I) UPDATE - PFCUser Account,</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94183795025294&amp;w=2">19991105 UPDATE: SSRT0620 Compaq Foundation Agents v4.40B  PFCUser issues</ref></refs><vuln_soft><prod name="Management Agents" vendor="Compaq"><vers num="4.20" prev="1"/></prod><prod name="Management Agents for Servers" vendor="Compaq"><vers num="4.40" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1356" published="1999-09-02" seq="1999-1356" severity="Medium" type="CVE"><desc><descript source="cve">Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93646669500991&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93759822830815&amp;w=2"></ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93637792706047&amp;w=2">19990902 Compaq CIM UG Overwrites Legal Notice</ref><ref source="XF" url="http://www.iss.net/security_center/static/7763.php">compaq-smartstart-legal-notice(7763)</ref></refs><vuln_soft><prod name="SmartStart" vendor="Compaq"><vers num="4.50" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-1999-1357" published="1999-10-05" seq="1999-1357" severity="High" type="CVE"><desc><descript source="cve">Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a &quot;&lt;&quot; sign, and the 0x9b character to a &quot;&gt;&quot; sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915331626185&amp;w=2"></ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.04"/><vers num="4.7" prev="1"/><vers num="4.51"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1358" published="1999-12-31" seq="1999-1358" severity="Medium" type="CVE"><desc><descript source="cve">When an administrator in Windows NT or Windows 2000 changes a user policy, the policy is not properly updated if the local ntconfig.pol is not writable by the user, which could allow local users to bypass restrictions that would otherwise be enforced by the policy, possibly by changing the policy file to be read-only.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q157/6/73.asp"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7400.php">nt-user-policy-update(7400)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1359" published="1999-12-31" seq="1999-1359" severity="High" type="CVE"><desc><descript source="cve">When the Ntconfig.pol file is used on a server whose name is longer than 13 characters, Windows NT does not properly enforce policies for global groups, which could allow users to bypass restrictions that were intended by those policies.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q163/8/75.asp"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7401.php">nt-group-policy-longname(7401)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1360" published="1999-12-31" seq="1999-1360" severity="Low" type="CVE"><desc><descript source="cve">Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q160/6/50.asp"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7402.php">nt-kernel-handle-dos(7402)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-1361" published="1998-05-09" seq="1999-1361" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925891&amp;w=2"></ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="3.5.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1362" published="1999-12-31" seq="1999-1362" severity="Low" type="CVE"><desc><descript source="cve">Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q160/6/01.asp"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7403.php">nt-win32k-dos(7403)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers edition="SP2" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-1363" published="1999-12-31" seq="1999-1363" severity="Low" type="CVE"><desc><descript source="cve">Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q163/1/43.asp"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7405.php">nt-nonpagedpool-dos(7405)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="3.5.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1364" published="1999-12-31" seq="1999-1364" severity="Low" type="CVE"><desc><descript source="cve">Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q142/6/53.asp"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7421.php">nt-threadcontext-dos(7421)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-1999-1365" published="1999-06-28" seq="1999-1365" severity="High" type="CVE"><desc><descript source="cve">Windows NT searches a user&apos;s home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93069418400856&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93127894731200&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/0515">NT Login Default Folder Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/2336">Windows NT login default folder allows a user to bypass policies</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1366" published="1999-05-15" seq="1999-1366" severity="Low" type="CVE"><desc><descript source="cve">Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92714118829880&amp;w=2">19990515 Pegasus Mail weak encryption</ref></refs><vuln_soft><prod name="Pegasus Mail" vendor="David Harris"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1367" published="1999-05-06" seq="1999-1367" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="PCWorld" url="http://www.pcworld.com/news/article/0,aid,10842,00.asp"></ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1368" published="1999-05-12" seq="1999-1368" severity="High" type="CVE"><desc><descript source="cve">AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user&apos;s rules cause the message to be moved to a different mailbox.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92652152723629&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=97439568517355&amp;w=2"></ref></refs><vuln_soft><prod name="InoculateIT" vendor="Computer Associates"><vers num="4.53"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-1999-1369" published="1999-04-14" seq="1999-1369" severity="Medium" type="CVE"><desc><descript source="cve">Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="XFORCE" url="http://xforce.iss.net/xforce/xfdb/7544">RealServer stores password insecurely during installation</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92411181619110&amp;w=2">19990414 Real Media Server stores passwords in plain text</ref></refs><vuln_soft><prod name="RealServer" vendor="RealNetworks"><vers num="6.0.3.353"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1370" published="1999-03-23" seq="1999-1370" severity="High" type="CVE"><desc><descript source="cve">The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92220197414799&amp;w=2">19990323 MSIE 5 installer disables screen saver</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1371" published="1999-03-08" seq="1999-1371" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100752221493&amp;w=2">19990308 Solaris </ref><ref source="MISC" url="http://www.securiteam.com/exploits/5ZP0O1P35O.html">http://www.securiteam.com/exploits/5ZP0O1P35O.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7546">solaris-write-bo(7546)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1372" published="1999-02-19" seq="1999-1372" severity="Medium" type="CVE"><desc><descript source="cve">Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91966339502073&amp;w=2">19990219 Plaintext Password in Tractives Remote Manager Software</ref><ref patch="1" source="XFORCE" url="http://xforce.iss.net/xforce/xfdb/7548">TriActive Remote Management stores plaintext usernames and passwords in the registry</ref></refs><vuln_soft><prod name="Remote Management" vendor="Triactive"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1373" published="2005-01-05" seq="1999-1373" severity="Medium" type="CVE"><desc><descript source="cve">FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91651770130771&amp;w=2">19990105 Re: Network Scan Vulnerability [SUMMARY]</ref></refs><vuln_soft><prod name="Powerhub Software" vendor="FORE"><vers num="5.0.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1374" published="2005-05-02" seq="1999-1374" severity="Medium" type="CVE"><desc><descript source="cve">perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92523159819402&amp;w=2">19990427 Re: Shopping Carts exposing CC data</ref><ref source="XFORCE" url="http://xforce.iss.net/xforce/xfdb/7557">perlshop.cgi could allow an attacker to obtain sensitive customer information</ref></refs><vuln_soft><prod name="PerlShop" vendor="ARPAnet"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1375" published="1999-02-11" seq="1999-1375" severity="Medium" type="CVE"><desc><descript source="cve">FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91877455626320&amp;w=2">19990211 Using FSO in ASP to view just about anything</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/230">230</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1376" published="1999-01-14" seq="1999-1376" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91632724913080&amp;w=2">MS IIS 4.0 Security Advisory</ref><ref adv="1" source="Security Focus" url="http://online.securityfocus.com/bid/2252">bid 2252</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91638375309890&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1377" published="1999-09-09" seq="1999-1377" severity="Medium" type="CVE"><desc><descript source="cve">Matt Wright&apos;s download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Phrack" url="http://pulhas.org/phrack/55/P55-07.html"></ref></refs><vuln_soft><prod name="download.cgi" vendor="Matt Wright"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1378" published="1999-07-19" seq="1999-1378" severity="Medium" type="CVE"><desc><descript source="cve">dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93250710625956&amp;w=2">19990917 improper chroot in dbmlparser.exe</ref></refs><vuln_soft><prod name="dbmlparser.exe" vendor="dbmlparser.exe"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1379" published="1999-12-31" seq="1999-1379" severity="Medium" type="CVE"><desc><descript source="cve">DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93348057829957&amp;w=2">SPJ-002-000</ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93433758607623&amp;w=2"></ref><ref adv="1" patch="1" source="Auscert" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AL-1999.004.dns_dos">AL-1999.004</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-063.shtml">J-063: Domain Name System (DNS) Denial of Service (DoS) Attacks</ref><ref source="XF" url="http://www.iss.net/security_center/static/7238.php">dns-udp-query-dos(7238)</ref></refs><vuln_soft><prod name="DNSTools" vendor="DNSTools Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1380" published="1997-05-04" seq="1999-1380" severity="Medium" type="CVE"><desc><descript source="cve">Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="IMA" url="http://mlarchive.ima.com/win95/1997/May/0342.html"></ref><ref adv="1" source="ZDNet UK" url="http://news.zdnet.co.uk/story/0,,s2065518,00.html"></ref><ref source="MISC" url="http://www.net-security.sk/bugs/NT/nu20.html">http://www.net-security.sk/bugs/NT/nu20.html</ref><ref source="XF" url="http://www.iss.net/security_center/static/7188.php">nu-tuneocx-activex-control(7188)</ref></refs><vuln_soft><prod name="Norton Utilities" vendor="Symantec"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1381" published="1998-10-08" seq="1999-1381" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90786656409618&amp;w=2">19981008 buffer overflow in dbadmin</ref></refs><vuln_soft><prod name="dbadmin" vendor="dbadmin"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1382" published="1999-12-31" seq="1999-1382" severity="High" type="CVE"><desc><descript source="cve">NetWare NFS mode 1 and 2 implements the &quot;Read Only&quot; flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to &quot;Read Only,&quot; which NetWare-NFS changes to a setuid root program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88427711321769&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90295697702474&amp;w=2"></ref><ref adv="1" patch="1" source="Novell" url="http://support.novell.com/cgi-bin/search/tidfinder.cgi?2940551"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7246.php">netware-nfs-file-ownership(7246)</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1383" published="1996-09-13" seq="1999-1383" severity="Medium" type="CVE"><desc><descript source="cve">(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Dataguard" url="http://www.dataguard.no/bugtraq/1996_3/0503.html">Vulnerability in expansion of PS1 in bash &amp; tcsh</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419868&amp;w=2">19960913 tee see shell problems</ref></refs><vuln_soft><prod name="tcsh" vendor="tcsh"><vers num="6.05"/></prod><prod name="bash" vendor="bash"><vers num="1.14.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1384" published="1996-10-30" seq="1999-1384" severity="High" type="CVE"><desc><descript source="cve">Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420095&amp;w=2">vulnerability in new SGIs</ref><ref adv="1" patch="1" source="Auscert" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul">AA-96.08</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I">19961101-01-I</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/470">bid470</ref><ref source="XF" url="http://www.iss.net/security_center/static/7456.php">irix-systour(7456)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5"/><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1385" published="1996-12-19" seq="1999-1385" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7465.php">ppp-bo (7465)</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:20.stack-overflow.asc">FreeBSD-SA-96:20</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420332&amp;w=2">19961219 Exploit for ppp bug (FreeBSD 2.1.0).</ref><ref source="XF" url="http://www.iss.net/security_center/static/7465.php">ppp-bo(7465)</ref><ref source="OSVDB" url="http://www.osvdb.org/6085">6085</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0" prev="1"/><vers num="1.0"/><vers num="1.1"/><vers num="2.1.5"/><vers num="2.1.6"/><vers num="2.1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-1386" published="1999-12-31" seq="1999-1386" severity="Low" type="CVE"><desc><descript source="cve">Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88932165406213&amp;w=2"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#perl">http://www.redhat.com/support/errata/rh50-errata-general.html#perl</ref><ref source="XF" url="http://www.iss.net/security_center/static/7243.php">perl-e-tmp-symlink(7243)</ref></refs><vuln_soft><prod name="Perl" vendor="Larry Wall"><vers num="5.4.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1387" published="1997-04-02" seq="1999-1387" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.</descript></desc><loss_types><avail/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420731&amp;w=2">Fatal bug in NT 4.0 server</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420732&amp;w=2">Fatal bug in NT 4.0 server (more comments)</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420741&amp;w=2">DUMP of NT system crash</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1388" published="1994-05-13" seq="1999-1388" severity="Medium" type="CVE"><desc><descript source="cve">passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Dataguard" url="http://www2.dataguard.no/bugtraq/1994_2/0197.html">UNIX.passwd.11-May-1994</ref><ref patch="1" source="Dataguard" url="http://www2.dataguard.no/bugtraq/1994_2/0207.html">UNIX.passwd.11-May-1994.NEWFIX</ref><ref adv="1" patch="1" source="Dataguard" url="http://www.dataguard.no/bugtraq/1994_4/0755.html">Sun Patch Id #102060-01</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1389" published="1998-05-11" seq="1999-1389" severity="High" type="CVE"><desc><descript source="cve">US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the &quot;set host prompt&quot; setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the &quot;host: &quot; prompt.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925916&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/99">bid99</ref></refs><vuln_soft><prod name="Total Control NETServer Card" vendor="3Com"><vers num="3.7.24" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1390" published="1998-04-28" seq="1999-1390" severity="High" type="CVE"><desc><descript source="cve">suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Darwin" url="http://darwin.bio.uci.edu/~mcoogan/bugtraq/msg00890.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/94">94</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1391" published="1990-10-03" seq="1999-1391" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml"></ref><ref source="BID" url="http://www.securityfocus.com/bid/10">10</ref><ref source="XF" url="http://www.iss.net/security_center/static/7143.php">nextstep-npd-root-access(7143)</ref></refs><vuln_soft><prod name="NeXT" vendor="NeXT"><vers num="1.0a"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1392" published="1990-10-03" seq="1999-1392" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1990-06.html">CA-1990-06</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/b-01.shtml"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/9">bid9</ref><ref source="XF" url="http://www.iss.net/security_center/static/7144.php">nextstep-restore09-root-access(7144)</ref></refs><vuln_soft><prod name="NeXT" vendor="NeXT"><vers num="1.0"/></prod><prod name="NeX" vendor="NeXT"><vers num="1.0a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1393" published="1999-05-21" seq="1999-1393" severity="Medium" type="CVE"><desc><descript source="cve">Control Panel &quot;Password Security&quot; option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Apple" url="http://freaky.staticusers.net/macsec/data/powerbooksecurity-data.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/532">bid532</ref></refs><vuln_soft><prod name="Mac OS" vendor="Apple"><vers num="8.5"/><vers num="8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1394" published="1999-07-02" seq="1999-1394" severity="Low" type="CVE"><desc><descript source="cve">BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a device.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93094058620450&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/510">510</ref></refs><vuln_soft><prod name="BSD" vendor="BSD"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1395" published="1992-11-17" seq="1999-1395" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-18.html">CA-1992-18</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability">CA-92:16</ref><ref source="BID" url="http://www.securityfocus.com/bid/51">51</ref><ref source="XF" url="http://www.iss.net/security_center/static/7136.php">vms-monitor-gain-privileges(7136)</ref></refs><vuln_soft><prod name="DEC OpenVMS" vendor="DEC"><vers num="5.0"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.1"/><vers num="5.1b"/><vers num="5.1.1"/><vers num="5.1.2"/><vers num="5.2"/><vers num="5.2.1"/><vers num="5.3"/><vers num="5.3.1"/><vers num="5.3.2"/><vers num="5.4"/><vers num="5.4.1"/><vers num="5.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1396" published="1992-07-21" seq="1999-1396" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-15.html">CA-1992-15</ref><ref source="BID" url="http://www.securityfocus.com/bid/49">49</ref><ref source="XF" url="http://www.iss.net/security_center/static/7150.php">sun-integer-multiplication-access(7150)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-11" name="CVE-1999-1397" published="1999-03-23" seq="1999-1397" severity="High" type="CVE"><desc><descript source="cve">Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92242671024118&amp;w=2">Index Server 2.0 and the Registry</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/476/discussion/">NT Index Server Remote Registry Vulnerability</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92223293409756&amp;w=2">19990323 Index Server 2.0 and the Registry</ref><ref source="BID" url="http://www.securityfocus.com/bid/476">476</ref><ref source="XF" url="http://www.iss.net/security_center/static/7559.php">iis-indexserver-reveal-path(7559)</ref></refs><vuln_soft><prod name="Index Server" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1398" published="1997-05-07" seq="1999-1398" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420921&amp;w=2">Irix: misc</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/472">bid472</ref><ref source="MISC" url="http://www.insecure.org/sploits/irix.xfsdump.html">http://www.insecure.org/sploits/irix.xfsdump.html</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1399" published="1997-08-20" seq="1999-1399" severity="High" type="CVE"><desc><descript source="cve">spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602746719552&amp;w=2">SpaceWare 7.3 v1.0</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/471">bid471</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1400" published="1999-06-03" seq="1999-1400" severity="Low" type="CVE"><desc><descript source="cve">The Economist screen saver 1999 with the &quot;Password Protected&quot; option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Indenial" url="http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0007.html"></ref><ref adv="1" source="Indenial" url="http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0009.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/466">466</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92851653600852&amp;w=2">19990604 Official response from The Economist re: 1999 Screen Saver</ref></refs><vuln_soft><prod name="The Economist 1999 Screen Saver" vendor="The Economist"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1401" published="1996-12-05" seq="1999-1401" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961201-01-PX">19961201-01-PX</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/463">bid463</ref><ref source="XF" url="http://www.iss.net/security_center/static/7575.php">irix-searchbook-permissions(7575)</ref><ref source="OSVDB" url="http://www.osvdb.org/8563">8563</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="6.0"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1402" published="1997-05-17" seq="1999-1402" severity="Low" type="CVE"><desc><descript source="cve">The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418317&amp;w=2">UNIX domain socket (Solarisx86 2.5)</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602248718482&amp;w=2">Solaris 2.6 and sockets</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/456">bid456</ref><ref source="XF" url="http://www.iss.net/security_center/static/7172.php">sun-domain-socket-permissions(7172)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.8"/><vers num="3.0"/><vers num="3.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.0"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1403" published="1998-10-02" seq="1999-1403" severity="High" type="CVE"><desc><descript source="cve">IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10771">Several potential security problems in IBM/Tivoli OPC Tracker Age nt</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=382">bid 382</ref><ref source="BID" url="http://www.securityfocus.com/bid/382">382</ref></refs><vuln_soft><prod name="Tivoli OPC Tracker Agent" vendor="IBM"><vers num="1.0X"/><vers num="2.0X"/><vers num="3.0X"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1404" published="1998-10-02" seq="1999-1404" severity="Medium" type="CVE"><desc><descript source="cve">IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10771">Several potential security problems in IBM/Tivoli OPC Tracker Age nt</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=382">bid 382</ref><ref source="BID" url="http://www.securityfocus.com/bid/382">382</ref></refs><vuln_soft><prod name="Tivoli OPC Tracker Agent" vendor="IBM"><vers num="1.0X"/><vers num="2.0X"/><vers num="3.0X"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1405" published="1999-02-17" seq="1999-1405" severity="High" type="CVE"><desc><descript source="cve">snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.</descript></desc><sols><sol source="nvd">Fixed in AIX 4.3 and 4.3.2
AIX 4.3.x APAR: IX88263
AIX 4.2.x APAR: IX88261</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="XFORCE" url="http://www.securityfocus.com/bid/375">AIX snap Insecure Temporary File Creation Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91936783009385&amp;w=2">19990217 snap utility for AIX.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91954824614013&amp;w=2">19990220 Re: snap utility for AIX.</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="4.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/><vers num="4.2"/><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1406" published="1998-07-29" seq="1999-1406" severity="Low" type="CVE"><desc><descript source="cve">dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526185&amp;w=2">Crash a redhat 5.1 linux box</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526192&amp;w=2">FD&apos;s 0..2 and suid/sgid procs (Was: Crash a redhat 5.1 linux box)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=372">bid 372</ref><ref source="BID" url="http://www.securityfocus.com/bid/372">372</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1407" published="1998-03-09" seq="1999-1407" severity="Low" type="CVE"><desc><descript source="cve">ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88950856416985&amp;w=2"></ref><ref source="CONFIRM" url="http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts">http://www.redhat.com/support/errata/rh50-errata-general.html#initscripts</ref><ref source="BID" url="http://www.securityfocus.com/bid/368">368</ref><ref source="XF" url="http://www.iss.net/security_center/static/7294.php">initscripts-ifdhcpdone-dhcplog-symlink(7294)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1408" published="1997-03-05" seq="1999-1408" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420641&amp;w=2">Bug in connect() for aix 4.1.4</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/352">bid352</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/></prod><prod name="HP-UX" vendor="HP"><vers num="9.05"/><vers num="9.5"/><vers num="10.1"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1409" published="1998-07-03" seq="1999-1409" severity="Low" type="CVE"><desc><descript source="cve">The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Shmoo" url="http://www.shmoo.com/mail/bugtraq/jul98/msg00064.html">more about &apos;at&apos;</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7577.php">at-f-read-files (7577)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/331">bid331</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90233906612929&amp;w=2">19980805 irix-6.2 &quot;at -f&quot; vulnerability</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/security/advisories/NetBSD-SA1998-004.txt.asc">NetBSD-SA1998-004</ref><ref source="XF" url="http://www.iss.net/security_center/static/7577.php">at-f-read-files(7577)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.2.1"/><vers num="1.3"/><vers num="1.3.1"/><vers num="1.3.2" prev="1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.2"/><vers num="6.4"/><vers num="6.5"/><vers num="6.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1410" published="1997-05-09" seq="1999-1410" severity="Medium" type="CVE"><desc><descript source="cve">addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Silicon Graphics, Inc." url="ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX">19961203-02-PX</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/330">bid330</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420927&amp;w=2">19970509 Re: Irix: misc</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.0"/><vers num="5.0.1"/><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="5.3"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-1411" published="1998-11-26" seq="1999-1411" severity="High" type="CVE"><desc><descript source="cve">The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91228908407679&amp;w=2">Security flaw in FSP</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/316">bid316</ref><ref source="DEBIAN" url="http://lists.debian.org/debian-security-announce/debian-security-announce-1998/msg00033.html">19981126 new version of fsp fixes security flaw</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91244712808780&amp;w=2">19981130 Debian: Security flaw in FSP</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91936850009861&amp;w=2">19990217 Debian GNU/Linux 2.0r5 released (fwd)</ref><ref source="XF" url="http://www.iss.net/security_center/static/7574.php">fsp-anon-ftp-access(7574)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-1412" published="1999-06-03" seq="1999-1412" severity="High" type="CVE"><desc><descript source="cve">A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/14215"></ref><ref source="BID" url="http://www.securityfocus.com/bid/306">306</ref></refs><vuln_soft><prod name="Mac OS X" vendor="Apple"><vers num="10.0"/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1413" published="1996-08-03" seq="1999-1413" severity="Medium" type="CVE"><desc><descript source="cve">Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419549&amp;w=2">Exploiting Zolaris 2.4 ??</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/296">bid296</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers edition="x86" num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1414" published="1999-05-25" seq="1999-1414" severity="High" type="CVE"><desc><descript source="cve">IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92765856706547&amp;w=2"></ref><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92902484317769&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/284">284</ref></refs><vuln_soft><prod name="Netfinity Remote Control" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1415" published="1991-08-23" seq="1999-1415" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-91.13.Ultrix.mail.vulnerability">CA-91:13</ref><ref source="BID" url="http://www.securityfocus.com/bid/27">27</ref></refs><vuln_soft><prod name="Ultrix" vendor="Digital"><vers num="4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-1999-1416" published="1998-08-23" seq="1999-1416" severity="Medium" type="CVE"><desc><descript source="cve">AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10383">Solaris ab2 web server is junk</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=253">bid 253</ref><ref source="BID" url="http://www.securityfocus.com/bid/253">253</ref></refs><vuln_soft><prod name="dwhttpd" vendor="Inso"><vers num="3.1a4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1417" published="1998-08-23" seq="1999-1417" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10383">19980823 Solaris ab2 web server is junk</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=253">bid 253</ref><ref source="BID" url="http://www.securityfocus.com/bid/253">253</ref></refs><vuln_soft><prod name="AnswerBook2" vendor="Inso"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1418" published="1999-05-01" seq="1999-1418" severity="Medium" type="CVE"><desc><descript source="cve">ICQ99 ICQ web server build 1701 with &quot;Active Homepage&quot; enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists (&quot;404 Forbidden&quot;) versus when a file does not exist (&quot;404 not found&quot;).</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/13508"></ref><ref source="BID" url="http://www.securityfocus.com/bid/246">246</ref></refs><vuln_soft><prod name="ICQ Web Front" vendor="Mirabilis"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1419" published="1997-07-30" seq="1999-1419" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/148">#00148</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/219">bid219</ref><ref source="XF" url="http://www.iss.net/security_center/static/7535.php">sun-nisplus-bo(7535)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers edition="x86" num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1420" published="1998-07-20" seq="1999-1420" severity="High" type="CVE"><desc><descript source="cve">NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch&apos;s configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526016&amp;w=2">N-Base Vulnerability Advisory</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526065&amp;w=2">N-Base Vulnerability Advisory Followup</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=212">bid 212</ref><ref source="BID" url="http://www.securityfocus.com/bid/212">212</ref></refs><vuln_soft><prod name="NH2012" vendor="N-Base"><vers num="2.53"/></prod><prod name="NH3012" vendor="N-Base"><vers num="2.1"/></prod><prod name="NH2015" vendor="N-Base"><vers num="2.51"/></prod><prod name="NH2048" vendor="N-Base"><vers num="1.33"/></prod><prod name="NH2012R" vendor="N-Base"><vers num="2.53"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1421" published="1998-07-20" seq="1999-1421" severity="Medium" type="CVE"><desc><descript source="cve">NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526016&amp;w=2">N-Base Vulnerability Advisory</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526065&amp;w=2">N-Base Vulnerability Advisory Followup</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=212">bid 212</ref><ref source="BID" url="http://www.securityfocus.com/bid/212">212</ref></refs><vuln_soft><prod name="NH208" vendor="N-Base"><vers num=""/></prod><prod name="NH215" vendor="N-Base"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1422" published="1999-01-02" seq="1999-1422" severity="High" type="CVE"><desc><descript source="cve">The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91540043023167&amp;w=2">19990102 PATH variable in zip-slackware 2.0.35</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.4"/><vers num="2.0.35"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1423" published="1997-06-26" seq="1999-1423" severity="Low" type="CVE"><desc><descript source="cve">ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319160&amp;w=2">Solaris Ping bug (DoS)</ref><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319171&amp;w=2">SUMMARY: Solaris Ping bug (DoS)</ref><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/146">#00146</ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319180&amp;w=2">Solaris Ping Bug and other [bc] oddities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/209">bid209</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319181&amp;w=2">19970627 Solaris Ping bug(inetsvc)</ref><ref source="XF" url="http://www.iss.net/security_center/static/7492.php">ping-multicast-loopback-dos(7492)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers num="2.3"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1424" published="1997-11-10" seq="1999-1424" severity="Medium" type="CVE"><desc><descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">#00145</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/208">bid208</ref></refs><vuln_soft><prod name="Solstice AdminSuite" vendor="Sun"><vers edition="x86" num="2.1"/><vers num="2.1"/><vers edition="x86" num="2.2"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1425" published="1997-11-10" seq="1999-1425" severity="Medium" type="CVE"><desc><descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">#00145</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/208">bid208</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">00145</ref></refs><vuln_soft><prod name="Solstice AdminSuite" vendor="Sun"><vers edition="x86" num="2.1"/><vers num="2.1"/><vers edition="x86" num="2.2"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1426" published="1997-11-10" seq="1999-1426" severity="Medium" type="CVE"><desc><descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">#00145</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/208">bid208</ref></refs><vuln_soft><prod name="Solstice AdminSuite" vendor="Sun"><vers edition="x86" num="2.1"/><vers num="2.1"/><vers edition="x86" num="2.2"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1427" published="1997-11-10" seq="1999-1427" severity="Medium" type="CVE"><desc><descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">#00145</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/208">bid208</ref></refs><vuln_soft><prod name="Solstice AdminSuite" vendor="Sun"><vers edition="x86" num="2.1"/><vers num="2.1"/><vers edition="x86" num="2.2"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1428" published="1997-11-10" seq="1999-1428" severity="Medium" type="CVE"><desc><descript source="cve">Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/145">#00145</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/208">bid208</ref></refs><vuln_soft><prod name="Solstice AdminSuite" vendor="Sun"><vers edition="x86" num="2.1"/><vers num="2.1"/><vers edition="x86" num="2.2"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1429" published="1998-01-05" seq="1999-1429" severity="Low" type="CVE"><desc><descript source="cve">DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88419633507543&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/204">204</ref></refs><vuln_soft><prod name="TransferPro" vendor="DIT"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1430" published="1999-01-01" seq="1999-1430" severity="Low" type="CVE"><desc><descript source="cve">PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91540043723185&amp;w=2">19990102 security problem with Royal daVinci</ref><ref source="XFORCE" url="http://www.securityfocus.com/bid/185">Da Vinci database access Vulnerability</ref></refs><vuln_soft><prod name="daVinci" vendor="Royal"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1431" published="2005-01-07" seq="1999-1431" severity="Medium" type="CVE"><desc><descript source="cve">ZAK in Appstation mode allows users to bypass the &quot;Run only allowed apps&quot; policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91576100022688&amp;w=2">19990107 WinNT, ZAK and Office 97</ref><ref adv="1" source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91606260910008&amp;w=2">19990109 WinNT, ZAK and Office 97</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/181">181</ref></refs><vuln_soft><prod name="Zero Administration Kit" vendor="Microsoft"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1432" published="1998-07-16" seq="1999-1432" severity="High" type="CVE"><desc><descript source="cve">Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525997&amp;w=2">Security risk with powermanagemnet on Solaris 2.6</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=160">bid 160</ref><ref source="BID" url="http://www.securityfocus.com/bid/160">160</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.4"/><vers num="2.4"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1433" published="1998-07-15" seq="1999-1433" severity="High" type="CVE"><desc><descript source="cve">HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525988&amp;w=2">JetAdmin software</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526067&amp;w=2">Re: JetAdmin software</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=157">bid 157</ref><ref source="BID" url="http://www.securityfocus.com/bid/157">157</ref></refs><vuln_soft><prod name="JetAdmin" vendor="HP"><vers num="Rev. D.01.09"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1434" published="1998-07-13" seq="1999-1434" severity="High" type="CVE"><desc><descript source="cve">login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525951&amp;w=2">Slackware Shadow Insecurity</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=155">bid 155</ref><ref source="BID" url="http://www.securityfocus.com/bid/155">155</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.1"/><vers num="3.2"/><vers num="3.3"/><vers num="3.4"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1435" published="1998-07-10" seq="1999-1435" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525933&amp;w=2">socks5 1.0r5 buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=154">bid 154</ref><ref source="BID" url="http://www.securityfocus.com/bid/154">154</ref></refs><vuln_soft><prod name="Socks 5" vendor="NEC"><vers num="1.0r5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1436" published="1998-07-08" seq="1999-1436" severity="High" type="CVE"><desc><descript source="cve">Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the &quot;user&quot; parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525905&amp;w=2">WWW Authorization Gateway</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=152">bid 152</ref><ref source="BID" url="http://www.securityfocus.com/bid/152">152</ref></refs><vuln_soft><prod name="WWW Authorization Gateway" vendor="Ray Chan"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1437" published="1998-07-07" seq="1999-1437" severity="High" type="CVE"><desc><descript source="cve">ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525890&amp;w=2">ePerl: bad handling of ISINDEX queries</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104525927&amp;w=2">ePerl Security Update Available</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=151">bid 151</ref><ref source="BID" url="http://www.securityfocus.com/bid/151">151</ref></refs><vuln_soft><prod name="ePerl" vendor="Ralf S. Engelschall"><vers num="2.2.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1438" published="1991-02-22" seq="1999-1438" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-91.01a.SunOS.mail.vulnerability">CA-91:01a</ref><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/105">#00105</ref><ref source="BID" url="http://www.securityfocus.com/bid/15">15</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.0.3"/><vers num="4.1"/><vers num="4.1.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1439" published="1998-01-02" seq="1999-1439" severity="Low" type="CVE"><desc><descript source="cve">gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88419592307388&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88524071002939&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88492937727193&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/146">146</ref></refs><vuln_soft><prod name="GCC" vendor="GCC"><vers num="2.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1440" published="1999-01-01" seq="1999-1440" severity="Medium" type="CVE"><desc><descript source="cve">Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/><design/><exception/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91522424302962&amp;w=2">19990101 Win32 ICQ 98a flaw</ref><ref source="XFORCE" url="http://www.securityfocus.com/bid/132">Mirabilis ICQ 98a Vulnerability</ref></refs><vuln_soft><prod name="ICQ 98a" vendor="Mirabilis"><vers num="1.30" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1441" published="1998-06-30" seq="1999-1441" severity="Low" type="CVE"><desc><descript source="cve">Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103126047&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/111">111</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0.34"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-1999-1442" published="1998-06-22" seq="1999-1442" severity="High" type="CVE"><desc><descript source="cve">Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CS.Helsinki" url="http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html"></ref><ref adv="1" source="UWSG" url="http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/105">105</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0.39" prev="1"/><vers num="2.1.132" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-1999-1443" published="1998-06-02" seq="1999-1443" severity="Medium" type="CVE"><desc><descript source="cve">Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using &lt;CTRL&gt;&lt;ALT&gt;&lt;DEL&gt; and kill the process using the task manager, (2) booting the system from a separate disk, or (3) interrupting certain processes that execute while the system is booting.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125889&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221103125869&amp;w=2"></ref><ref source="BID" url="http://www.securityfocus.com/bid/103">103</ref></refs><vuln_soft><prod name="Full Armor" vendor="Micah Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1444" published="1999-12-31" seq="1999-1444" severity="Medium" type="CVE"><desc><descript source="cve">genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Risks Digest" url="http://catless.ncl.ac.uk/Risks/20.41.htmlsubj4"></ref><ref source="MISC" url="http://catless.ncl.ac.uk/Risks/20.41.html#subj4">http://catless.ncl.ac.uk/Risks/20.41.html#subj4</ref></refs><vuln_soft><prod name="Alibaba" vendor="Computer Software Manufaktur"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1445" published="1998-02-02" seq="1999-1445" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsgroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88637951600184&amp;w=2"></ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.4"/><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1446" published="1997-08-05" seq="1999-1446" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 3 records a history of all URL&apos;s that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the &quot;Clear History&quot; option, and are not visible when the user browses the folders because of tailored displays.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602837719654&amp;w=2">Strange behavior regarding directory</ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=87602837719655&amp;w=2">Strange behavior regarding directory</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1447" published="1998-07-28" seq="1999-1447" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526169&amp;w=2">Object tag crashes Internet Explorer 4.0</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526188&amp;w=2">19980730 Re: Object tag crashes Internet Explorer 4.0</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1448" published="1998-07-29" seq="1999-1448" severity="Medium" type="CVE"><desc><descript source="cve">Eudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user&apos;s mailbox via an e-mail message with certain dates, such as (1) dates before 1970, which cause a Divide By Zero error, or (2) dates that are 100 years after the current date, which causes a segmentation fault.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526168&amp;w=2">Eudora exploit (was Microsoft Security Bulletin (MS98-008))</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num="3.05" prev="1"/></prod><prod name="Eudora Light" vendor="Qualcomm"><vers num="3.05" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1449" published="1997-05-19" seq="1999-1449" severity="Low" type="CVE"><desc><descript source="cve">SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Oamk.fi" url="http://oamk.fi/~jukkao/bugtraq/before-971202/0498.html">/dev/tcx0 crashes SunOS 4.1.4 on Sparc 20&apos;s</ref><ref adv="1" source="Insecure.org" url="http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html">SunOS 4.1.4 crashes when (l)users read /dev/tcx0</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1450" published="1999-01-27" seq="1999-1450" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7466.php">sco-rshd (7466)</ref><ref adv="1" patch="1" source="SSE" url="http://pub.vse.cz/SCO/ftp.sco.com/SSE/sse023.ltr">System Security Enhancement (SSE) 023</ref><ref adv="1" patch="1" source="SSE" url="http://pub.vse.cz/SCO/ftp.sco.com/SSE/sse020.ltr">System Security Enhancement (SSE) 020</ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.03b">SB-99.03b</ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.06b">SB-99.06b</ref><ref source="SCO" url="ftp://ftp.sco.COM/SSE/sse020.ltr">SSE020</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0"/><vers num="5.0.2"/><vers num="5.0.4"/><vers num="5.0.5" prev="1"/></prod><prod name="UnixWare" vendor="SCO"><vers num="2.1.3" prev="1"/><vers num="7.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1451" published="1999-12-31" seq="1999-1451" severity="Medium" type="CVE"><desc><descript source="cve">The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q231/3/68.asp"></ref><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms99-013.asp">MS99-013</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3271.php">iis-samples-winmsdp(3271)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1452" published="1999-12-31" seq="1999-1452" severity="Low" type="CVE"><desc><descript source="cve">GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91822011021558&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91788829326419&amp;w=2"></ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q214/8/02.asp"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/198">bid198</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91764169410814&amp;w=2">19990129 ole objects in a &quot;secured&quot; environment?</ref><ref source="XF" url="http://xforce.iss.net/static/1975.php">nt-gina-clipboard(1975)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1453" published="1999-02-02" seq="1999-1453" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91979439932341&amp;w=2">19990222 New IE4 vulnerability : the clipboard again.</ref><ref source="XFORCE" url="http://www.securityfocus.com/bid/215">Microsoft IE4 Clipboard Paste Vulnerability</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1454" published="1999-10-04" seq="1999-1454" severity="Medium" type="CVE"><desc><descript source="cve">Macromedia &quot;The Matrix&quot; screen saver on Windows 95 with the &quot;Password protected&quot; option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915027622690&amp;w=2"></ref></refs><vuln_soft><prod name="Matrix Screen Saver" vendor="Macromedia"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1455" published="1999-12-31" seq="1999-1455" severity="High" type="CVE"><desc><descript source="cve">RSH service utility RSHSVC in Windows NT 3.5 through 4.0 does not properly restrict access as specified in the .Rhosts file when a user comes from an authorized host, which could allow unauthorized users to access the service by logging in from an authorized host.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q158/3/20.asp"></ref><ref source="XF" url="http://xforce.iss.net/static/7422.php">nt-rshsvc-ale-bypass(7422)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-1999-1456" published="1999-12-31" seq="1999-1456" severity="Medium" type="CVE"><desc><descript source="cve">thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/10368"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1809.php">thttpd-file-read(1809)</ref><ref source="CONFIRM" url="http://www.acme.com/software/thttpd/thttpd.html#releasenotes">http://www.acme.com/software/thttpd/thttpd.html#releasenotes</ref></refs><vuln_soft><prod name="thttpd HTTP server" vendor="thttpd"><vers num="2.03" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-1999-1457" published="1999-11-16" seq="1999-1457" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="S.u.S.E." url="http://www.suse.de/de/support/security/suse_security_announce_30.txt">thttpd 1.90a - 2.04</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4852.php">thttpd-ifmodifiedsince-header (4852)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_30.html">19991116 thttpd</ref></refs><vuln_soft><prod name="thttpd HTTP server" vendor="Thttpd"><vers num="2.04.31" prev="1"/><vers num="1.90a"/><vers num="2.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1458" published="1999-01-25" seq="1999-1458" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/12121">Digital Unix 4.0 exploitable buffer overflows</ref><ref adv="1" patch="1" source="Compaq" url="http://ftp1.support.compaq.com/public/dunix/v4.0d/ssrt0583u.README">SSRT0583U  </ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3138.php">du-at (3138)</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num="4.0"/><vers num="4.0A"/><vers num="4.0B"/><vers num="4.0C"/><vers num="4.0D"/><vers num="4.0E"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1459" published="1998-11-02" seq="1999-1459" severity="High" type="CVE"><desc><descript source="cve">BMC PATROL Agent before 3.2.07 allows local users to gain root privileges via a symlink attack on a temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise10.php">BMC PATROL File Creation Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1388.php">bmc-patrol-file-create(1388)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/534">bid 534</ref></refs><vuln_soft><prod name="Patrol Agent" vendor="BMC Software"><vers num="3.2"/><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1460" published="1999-07-13" seq="1999-1460" severity="High" type="CVE"><desc><descript source="cve">BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93198293132463&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93372579004129&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/525">bid525</ref></refs><vuln_soft><prod name="PATROL Agent" vendor="BMC Software"><vers num="3.2"/><vers num="3.2.3"/><vers num="3.2.5"/><vers num="3.2.07" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1461" published="1997-05-07" seq="1999-1461" severity="High" type="CVE"><desc><descript source="cve">inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/6702">Irix: misc</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I">20001101-01-I</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/381">bid381</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420921&amp;w=2">19970507 Irix: misc</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.10"/><vers num="5.3"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1462" published="1999-12-31" seq="1999-1462" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in bb-hist.sh CGI History module in Big Brother 1.09b and 1.09c allows remote attacker to read portions of arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/13440"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3755.php">http-cgi-bigbrother-bbhist(3755)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/142">bid142</ref><ref source="CONFIRM" url="http://bb4.com/README.CHANGES">http://bb4.com/README.CHANGES</ref></refs><vuln_soft><prod name="Big Brother" vendor="Sean MacGuire"><vers num="1.09c"/><vers num="1.09b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-1463" published="1997-07-10" seq="1999-1463" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/7219">A New Fragmentation Attack</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/528.php">nt-frag (528)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1464" published="1999-12-31" seq="1999-1464" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by Cisco bug CSCdk35564.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml"></ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-016.shtml">J-016: Cisco IOS DFS Access List Leakage Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1401.php">cisco-acl-leakage(1401)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="11.1CC"/><vers num="11.1CT"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1465" published="1999-12-31" seq="1999-1465" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as described by Cisco bug CSCdk43862.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml"></ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-016.shtml">J-016: Cisco IOS DFS Access List Leakage Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1401.php">cisco-acl-leakage(1401)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="11.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1466" published="1992-12-10" seq="1999-1466" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the &quot;established&quot; keyword.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-20.html">CA-1992-20</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/53">bid53</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="8.2"/><vers num="8.3"/><vers num="9.0"/><vers num="9.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-31" name="CVE-1999-1467" published="1989-10-26" seq="1999-1467" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1989-07.html">CA-1989-07</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/5">bid5</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3165.php">sun-rcp(3165)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3c"/><vers num="4.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1468" published="1991-10-22" seq="1999-1468" severity="Medium" type="CVE"><desc><descript source="cve">rdist in various UNIX systems uses popen to execute sendmail, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Unix" url="http://www.unix.geek.org.uk/~arny/www.8lgm.org/1.UNIX.rdist.23-Apr-1991"></ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-91.20.rdist.vulnerability">CA-91:20</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/31">bid31</ref><ref source="MISC" url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-01.html</ref><ref source="XF" url="http://www.iss.net/security_center/static/7160.php">rdist-popen-gain-privileges(7160)</ref><ref source="OSVDB" url="http://www.osvdb.org/8106">8106</ref></refs><vuln_soft><prod name="NeXT" vendor="NeXT"><vers num="2.0"/><vers num="2.1"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.0.3c"/><vers num="4.0.3"/><vers num="4.1PSR_A"/><vers num="4.1"/><vers num="4.1.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="3.3"/><vers num="3.3.1"/><vers num="3.3.2"/><vers num="3.3.3"/><vers num="4.0"/></prod><prod name="UNICOS" vendor="Cray"><vers num="6.0E"/><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1469" published="1999-09-30" seq="1999-1469" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93871926821410&amp;w=2"></ref></refs><vuln_soft><prod name="w3-auth" vendor="Hughes Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1470" published="1999-06-24" seq="1999-1470" severity="Medium" type="CVE"><desc><descript source="cve">Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93034788412494&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2303.php">eastman-cleartext-passwords(2303)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/485">bid485</ref></refs><vuln_soft><prod name="Work Management" vendor="Eastman Software"><vers num="3.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1471" published="1989-01-01" seq="1999-1471" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1989-01.html">CA-1989-01</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/4">bid4</ref><ref source="XF" url="http://www.iss.net/security_center/static/7152.php">bsd-passwd-bo(7152)</ref></refs><vuln_soft><prod name="BSD" vendor="BSD"><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1472" published="1999-12-31" seq="1999-1472" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user&apos;s machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/587.php">http-ie-spy(587)</ref><ref adv="1" patch="1" source="Insecure" url="http://www.insecure.org/sploits/Internet_explorer_4.0.hack.html"></ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q176/7/94.asp"></ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp"></ref><ref source="CONFIRM" url="http://www.microsoft.com/Windows/ie/security/freiburg.asp">http://www.microsoft.com/Windows/ie/security/freiburg.asp</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87710897923098&amp;w=2">19971017 Security Hole in Explorer 4.0</ref><ref source="OSVDB" url="http://www.osvdb.org/7819">7819</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1473" published="1999-12-31" seq="1999-1473" severity="Medium" type="CVE"><desc><descript source="cve">When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the &quot;Page Redirect Issue.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q176/6/97.asp"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7426.php">ie-page-redirect(7426)</ref><ref source="OSVDB" url="http://www.osvdb.org/7818">7818</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0.02"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1474" published="1999-12-31" seq="1999-1474" severity="High" type="CVE"><desc><descript source="cve">PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/179.php">nt-ppt-patch(179)</ref><ref source="CONFIRM" url="http://www.microsoft.com/windows/ie/security/powerpoint.asp">http://www.microsoft.com/windows/ie/security/powerpoint.asp</ref></refs><vuln_soft><prod name="PowerPoint" vendor="Microsoft"><vers num="95"/><vers num="97"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1475" published="1999-11-19" seq="1999-1475" severity="Medium" type="CVE"><desc><descript source="cve">ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/35483"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/812">bid812</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1476" published="1999-12-31" seq="1999-1476" severity="Low" type="CVE"><desc><descript source="cve">A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the &quot;Invalid Operand with Locked CMPXCHG8B Instruction&quot; problem.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q163/8/52.asp"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/704.php">pentium-crash(704)</ref></refs><vuln_soft><prod name="Pentuim" vendor="Intel"><vers num="Overdrive"/></prod><prod name="Pentium" vendor="Intel"><vers num="MMX"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1477" published="1999-09-23" seq="1999-1477" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/28717"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/663">bid663</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3349.php">gnome-espeaker-local-bo(3349)</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="6.0"/></prod><prod name="Gnome Libs" vendor="GNOME"><vers num="1.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1478" published="1999-07-06" seq="1999-1478" severity="Medium" type="CVE"><desc><descript source="cve">The Sun HotSpot Performance Engine VM allows a remote attacker to cause a denial of service on any server running HotSpot via a URL that includes the [ character.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827429589&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93240220324183&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2348.php">sun-hotspot-vm(2348)</ref><ref source="BID" url="http://www.securityfocus.com/bid/522">522</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1479" published="1998-06-24" seq="1999-1479" severity="High" type="CVE"><desc><descript source="cve">The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2052.php">http-cgi-textcounter(2052)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/9609">19980624 textcounter.pl SECURITY HOLE      </ref><ref source="BID" url="http://www.securityfocus.com/bid/2265">2265</ref></refs><vuln_soft><prod name="TextCounter" vendor="Matt Wright"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1480" published="1998-06-11" seq="1999-1480" severity="Low" type="CVE"><desc><descript source="cve">(1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/429">bid429</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1481" published="1999-12-31" seq="1999-1481" severity="Medium" type="CVE"><desc><descript source="cve">Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Squid-Cache" url="http://www.squid-cache.org/Versions/v2/2.2/bugs/"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/741">bid741</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3433.php">squid-proxy-auth-access(3433)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/33295">19991025 [squid] exploit for external authentication problem</ref></refs><vuln_soft><prod name="Squid Web Proxy" vendor="National Science Foundation"><vers num="2.2"/><vers num="2.1"/><vers num="1.1"/><vers num="1.0NOVM"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1482" published="1999-02-19" seq="1999-1482" severity="High" type="CVE"><desc><descript source="cve">SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-02-15&amp;msg=Pine.LNX.3.96.990219175605.9622A-100000@ferret.lmh.ox.ac.uk">19990219 Security hole: </ref></refs><vuln_soft><prod name="zgv" vendor="SVGAlib"><vers num="3.0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1483" published="1997-06-19" seq="1999-1483" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/7041">svgalib/zgv</ref></refs><vuln_soft><prod name="SVGAlib" vendor="SVGAlib"><vers num="1.2.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1484" published="1999-09-24" seq="1999-1484" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/28719"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3310.php">msn-setup-bbs-activex-bo(3310)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/668">bid668</ref></refs><vuln_soft><prod name="MSN Setup BBS" vendor="Microsoft"><vers num="4.71.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1485" published="1999-05-31" seq="1999-1485" severity="Medium" type="CVE"><desc><descript source="cve">nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/13999"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2246.php">sgi-nsd-view(2246)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2247.php">sgi-nsd-create(2247)</ref><ref source="BID" url="http://www.securityfocus.com/bid/412">412</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92818552106912&amp;w=2">19990531 IRIX 6.5 nsd virtual filesystem vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/8564">8564</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-1999-1486" published="1998-02-25" seq="1999-1486" severity="Low" type="CVE"><desc><descript source="cve">sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref source="CONFIRM" url="http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info">http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/408">bid408</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7675.php">aix-sadc-timex (7675)</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX75554&amp;apar=only">IX75554</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76853&amp;apar=only">IX76853</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX76330&amp;apar=only">IX76330</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7675">aix-sadc-timex(7675)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/><vers num="4.2"/><vers num="4.2.1"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1487" published="1998-01-21" seq="1999-1487" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="IBM" url="http://www-1.ibm.com/servlet/support/manager?rt=0&amp;rs=0&amp;org=apars&amp;doc=41D8B61D1E1C4FAB852567C9002C546C">IX74599</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/405">bid405</ref><ref source="XF" url="http://www.iss.net/security_center/static/7477.php">aix-digest(7477)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.4"/><vers num="4.1.5"/><vers num="4.2"/><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1488" published="1999-12-31" seq="1999-1488" severity="Medium" type="CVE"><desc><descript source="cve">sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/371">bid371</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-079a.shtml"></ref><ref source="XF" url="http://www.iss.net/security_center/static/7217.php">ibm-sdr-read-files(7217)</ref></refs><vuln_soft><prod name="System Data Repository" vendor="IBM"><vers num="SP 2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1489" published="1997-03-04" seq="1999-1489" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/6384">Linux SuperProbe exploit</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/364">bid364</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1490" published="1998-05-28" seq="1999-1490" severity="High" type="CVE"><desc><descript source="cve">xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926021&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/362">bid362</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926034&amp;w=2">19980529 Re: Tiresome security hole in &quot;xosview&quot; (xosexp.c)</ref><ref source="XF" url="http://www.iss.net/security_center/static/8787.php">linux-xosview-bo(8787)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1491" published="1996-02-02" seq="1999-1491" severity="High" type="CVE"><desc><descript source="cve">abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418994&amp;w=2">abuse Red Hat 2.1 security hole</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/354">bid354</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1492" published="1998-05-27" seq="1999-1492" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030">19980502-01-P3030</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2104.php">sgi-diskalign(2104)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2103.php">sgi-diskperf (2103)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/348">bid348</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1493" published="1991-12-18" seq="1999-1493" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-23.html">CA-1991-23</ref><ref source="BID" url="http://www.securityfocus.com/bid/34">34</ref><ref source="XF" url="http://xforce.iss.net/static/7158.php">apollo-crp-root-access(7158)</ref></refs><vuln_soft><prod name="Apollo Domain OS" vendor="HP"><vers num="SR10.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1494" published="1994-08-09" seq="1999-1494" severity="Low" type="CVE"><desc><descript source="cve">colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/675">IRIX 5.2 Security Advisory</ref><ref adv="1" patch="1" source="Tryc" url="http://www.tryc.on.ca/archives/bugtraq/1995_1/0614.html">another Irix 5.2 hole</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2112.php">sgi-colorview (2112)</ref><ref adv="1" patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19950209-01-P">19950209-00-P</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/336">bid336</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.1"/><vers num="5.1.1"/><vers num="5.2"/><vers num="6.0"/><vers num="6.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1495" published="1999-02-18" seq="1999-1495" severity="Low" type="CVE"><desc><descript source="cve">xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12580">19990218 xtvscreen and suse 6 </ref><ref source="XF" url="http://xforce.iss.net/static/1792.php">xtvscreen-overwrite(1792)</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/325">325</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1496" published="1999-06-08" seq="1999-1496" severity="Low" type="CVE"><desc><descript source="cve">Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/14665"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/321">bid321</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2277.php">sudo-file-exists(2277)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod><prod name="Sudo" vendor="Todd Miller"><vers num="1.5"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-01-24" name="CVE-1999-1497" published="1999-12-21" seq="1999-1497" severity="High" type="CVE"><desc><descript source="cve">Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/39329"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/880">bid880</ref></refs><vuln_soft><prod name="Imail" vendor="Ipswitch"><vers num="5.0"/><vers num="6.0"/><vers num="5.0.5"/><vers num="5.0.6"/><vers num="5.0.7"/><vers num="5.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1498" published="1998-04-06" seq="1999-1498" severity="Low" type="CVE"><desc><descript source="cve">Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/82">82</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1499" published="1998-04-10" seq="1999-1499" severity="Low" type="CVE"><desc><descript source="cve">named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/8966"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/80">bid80</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="4.9"/><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1500" published="1999-10-01" seq="1999-1500" severity="Medium" type="CVE"><desc><descript source="cve">Internet Anywhere POP3 Mail Server 2.3.1 allows remote attackers to cause a denial of service (crash) via (1) LIST, (2) TOP, or (3) UIDL commands using letters as arguments.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93880357530599&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/733">bid733</ref></refs><vuln_soft><prod name="Internet Anywhere Mail Server" vendor="True North"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1501" published="1998-04-08" seq="1999-1501" severity="Medium" type="CVE"><desc><descript source="cve">(1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/70">bid70</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/71">bid71</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=19980408184855.12506@math.princeton.edu">19980408 SGI O2 ipx security issue</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89217373930054&amp;w=2">19980408 SGI O2 ipx security issue</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1502" published="1998-04-08" seq="1999-1502" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89205623028934&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/68">bid68</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/69">bid69</ref></refs><vuln_soft><prod name="Quake" vendor="Id Software"><vers num="1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1503" published="1998-04-08" seq="1999-1503" severity="Medium" type="CVE"><desc><descript source="cve">Network Flight Recorder (NFR) 1.5 and 1.6 allows remote attackers to cause a denial of service in nfrd (crash) via a TCP packet with a null header and data field.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/63">bid63</ref></refs><vuln_soft><prod name="NFR" vendor="NFR"><vers num="1.5"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1504" published="1998-04-08" seq="1999-1504" severity="Medium" type="CVE"><desc><descript source="cve">Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/8951"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/62">bid62</ref></refs><vuln_soft><prod name="Stalker Internet Mail Server" vendor="Stalker"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1505" published="1998-04-07" seq="1999-1505" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=89200537415923&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/60">bid60</ref></refs><vuln_soft><prod name="QuakeWorld" vendor="Id Software"><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1506" published="1990-01-29" seq="1999-1506" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-90.01.sun.sendmail.vulnerability">CA-90:01</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/6">bid6</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="3.5"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3c"/><vers num="4.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1507" published="1993-02-03" seq="1999-1507" severity="High" type="CVE"><desc><descript source="cve">Sun SunOS 4.1 through 4.1.3 allows local attackers to gain root access via insecure permissions on files and directories such as crash.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1993-03.html">CA-1993-03</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/59">bid59</ref><ref source="XF" url="http://xforce.iss.net/static/521.php">sun-dir(521)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1PSR_A"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3c"/><vers num="4.1.3u1"/><vers num="4.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1508" published="1999-11-16" seq="1999-1508" severity="High" type="CVE"><desc><descript source="cve">Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286041430870&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/806">bid806</ref></refs><vuln_soft><prod name="Phaser Network Printer" vendor="Tektronix"><vers num="930"/><vers num="840"/><vers num="750DP"/><vers num="750"/><vers num="740"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1509" published="1999-11-04" seq="1999-1509" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94183041514522&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/773">bid773</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94177470915423&amp;w=2">19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability</ref></refs><vuln_soft><prod name="Eserv" vendor="Etype"><vers num="2.50"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1510" published="1999-05-17" seq="1999-1510" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsgroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92697301706956&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3234.php">bisonware-command-bo(3234)</ref></refs><vuln_soft><prod name="BisonWare FTP Server" vendor="BisonWare"><vers num="4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1511" published="1999-11-10" seq="1999-1511" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94226003804744&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/791">bid791</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3488.php">xtramail-pass-dos(3488)</ref></refs><vuln_soft><prod name="XtraMail" vendor="Artisoft"><vers num="1.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1512" published="1999-12-31" seq="1999-1512" severity="High" type="CVE"><desc><descript source="cve">The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93219846414732&amp;w=2"></ref><ref adv="1" source="Amavis" url="http://www.amavis.org/ChangeLog.txt"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/527">bid527</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2349.php">amavis-command-execute(2349)</ref></refs><vuln_soft><prod name="Virus Scanner" vendor="AMaViS"><vers num="0.2 pre4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1513" published="1999-08-30" seq="1999-1513" severity="High" type="CVE"><desc><descript source="cve">Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93616983223090&amp;w=2"></ref></refs><vuln_soft><prod name="SuperStack II Hub" vendor="3Com"><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1514" published="2001-11-28" seq="1999-1514" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94121377716133&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/749">bid749</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3401.php">expressfs-command-bo(3401)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94130292519646&amp;w=2">19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability</ref></refs><vuln_soft><prod name="ExpressFS" vendor="Celtech Software"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1515" published="1999-08-31" seq="1999-1515" severity="Medium" type="CVE"><desc><descript source="cve">A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/613">bid613</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3290.php">tfs-gateway-dos(3290)</ref></refs><vuln_soft><prod name="TFS Gateway" vendor="TenFour"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1516" published="1999-09-02" seq="1999-1516" severity="High" type="CVE"><desc><descript source="cve">A buffer overflow in TenFour TFS Gateway SMTP mail server 3.2 allows an attacker to crash the mail server and possibly execute arbitrary code by offering more than 128 bytes in a MAIL FROM string.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93677241318492&amp;w=2"></ref></refs><vuln_soft><prod name="TFS Gateway SMTP" vendor="TenFour"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1517" published="1999-11-01" seq="1999-1517" severity="High" type="CVE"><desc><descript source="cve">runtar in the Amanda backup system used in various UNIX operating systems executes tar with root privileges, which allows a user to overwrite or read arbitrary files by providing the target files to runtar.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94148942818975&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/750">bid750</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1518" published="1999-07-15" seq="1999-1518" severity="Medium" type="CVE"><desc><descript source="cve">Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93207728118694&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/526">bid526</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2351.php">bsd-shared-memory-dos(2351)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="1.1.5.1"/><vers num="2.0"/><vers num="2.0.5"/><vers num="2.1.0"/><vers num="2.1.5"/><vers num="2.1.6"/><vers num="2.1.7.1"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.8"/><vers num="3.0"/><vers num="3.1"/><vers num="3.2"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.4 x86"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1519" published="1999-11-17" seq="1999-1519" severity="Medium" type="CVE"><desc><descript source="cve">Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286244700573&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/805">bid805</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3513.php">g6ftp-username-dos(3513)</ref></refs><vuln_soft><prod name="G6 FTP Server" vendor="Gene6"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-1999-1520" published="1999-05-11" seq="1999-1520" severity="Medium" type="CVE"><desc><descript source="cve">A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92647407227303&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/256">bid256</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2270.php">siteserver-site-csc(2270)</ref></refs><vuln_soft><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1521" published="1999-09-12" seq="1999-1521" severity="High" type="CVE"><desc><descript source="cve">Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93720402717560&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94121824921783&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/633">bid633</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2240.php">cmail-command-bo(2240)</ref></refs><vuln_soft><prod name="CMail" vendor="Computalynx"><vers num="2.3SP2"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-1522" published="1999-10-07" seq="1999-1522" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in htmlparse.pike in Roxen Web Server 1.3.11 and earlier, possibly related to recursive parsing and referer tags in RXML.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93942579008408&amp;w=2"></ref></refs><vuln_soft><prod name="Roxen Web Server" vendor="Roxen"><vers num="1.3.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1523" published="1999-10-04" seq="1999-1523" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Sambar Web Server 4.2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93901161727373&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93941351229256&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1672.php">http://xforce.iss.net/static/1672.php</ref></refs><vuln_soft><prod name="Sambar Server" vendor="Sambar"><vers num="4.2.1"/><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1524" published="1999-08-07" seq="1999-1524" severity="Medium" type="CVE"><desc><descript source="cve">FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93424680430460&amp;w=2"></ref></refs><vuln_soft><prod name="FlowPoint DSL Router" vendor="FlowPoint"><vers num="3.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1525" published="1997-03-14" seq="1999-1525" severity="Medium" type="CVE"><desc><descript source="cve">Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user&apos;s mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167420670&amp;w=2">Shockwave Security Alert</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1585.php">shockwave-internal-access (1585</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1586.php">shockwave-file-read-vuln (1586)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/460.php">http-ns-shockwave (460)</ref></refs><vuln_soft><prod name="Shockwave Flash Plugin" vendor="Macromedia"><vers num="6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1526" published="1999-03-11" seq="1999-1526" severity="Medium" type="CVE"><desc><descript source="cve">Auto-update feature of Macromedia Shockwave 7 transmits a user&apos;s password and hard disk information back to Macromedia.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/12842">Shockwave 7 Security Hole</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1931.php">shockwave-updater (1931)</ref></refs><vuln_soft><prod name="Shockwave Flash Plugin" vendor="Macromedia"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-21" name="CVE-1999-1527" published="1999-11-23" seq="1999-1527" severity="High" type="CVE"><desc><descript source="cve">Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94338883114254&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/816">bid816</ref></refs><vuln_soft><prod name="Forte" vendor="Sun"><vers num="Community 1.0 Beta"/></prod><prod name="Netbeans Developer" vendor="Sun"><vers num="3.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1528" published="1999-11-14" seq="1999-1528" severity="Medium" type="CVE"><desc><descript source="cve">ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94261444428430&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/794">bid794</ref></refs><vuln_soft><prod name="NetWare Client" vendor="Prosoft Engineering"><vers num="5.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1529" published="1999-11-07" seq="1999-1529" severity="High" type="CVE"><desc><descript source="cve">A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94201512111092&amp;w=2"></ref><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94208143007829&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/55551"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/787">bid787</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3465.php">viruswall-helo-bo(3465)</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94199707625818&amp;w=2">19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94210427406568&amp;w=2">19991108 Re: Interscan VirusWall NT 3.23/3.3 buffer overflow.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94204166130782&amp;w=2">19991108 Patch for VirusWall 3.23.</ref></refs><vuln_soft><prod name="Interscan VirusWall" vendor="Trend Micro"><vers num="3.23"/><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-1530" published="1999-11-08" seq="1999-1530" severity="Low" type="CVE"><desc><descript source="cve">cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94209954200450&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225629200045&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/777">bid777</ref><ref source="XF" url="http://www.iss.net/security_center/static/7764.php">cobalt-cgiwrap-incorrect-permissions(7764)</ref><ref source="OSVDB" url="http://www.osvdb.org/35">35</ref></refs><vuln_soft><prod name="Cobalt RaQ" vendor="Sun"><vers num="2.0"/><vers num="3i"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1531" published="1999-11-02" seq="1999-1531" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer&apos;s system via a long IMG_SRC HTML tag.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94157187815629&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/763">bid763</ref><ref source="XF" url="http://www.iss.net/security_center/static/7767.php">ibm-homepageprint-bo(7767)</ref></refs><vuln_soft><prod name="HomePagePrint" vendor="IBM"><vers num="1.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-1999-1532" published="1999-10-29" seq="1999-1532" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94117465014255&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/748">bid748</ref></refs><vuln_soft><prod name="Netscape Messaging Server" vendor="Netscape"><vers num="3.6"/><vers num="3.54"/><vers num="3.55"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1533" published="1999-11-07" seq="1999-1533" severity="High" type="CVE"><desc><descript source="cve">Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94208143007829&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/55551"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/787">bid787</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3465.php">viruswall-helo-bo(3465)</ref><ref source="BID" url="http://www.securityfocus.com/bid/665">665</ref><ref source="XF" url="http://xforce.iss.net/static/3317.php">diva-lan-isdn-dos(3317)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93846522511387&amp;w=2">19990926 DoS Exploit in Eicon Diehl LAN ISDN Modem</ref></refs><vuln_soft><prod name="InterScan VirusWall" vendor="Trend Micro"><vers num="3.2.3"/><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1534" published="1999-09-23" seq="1999-1534" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93837184228248&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/661">bid661</ref></refs><vuln_soft><prod name="Arkeia" vendor="Knox Software"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-1535" published="1999-07-20" seq="1999-1535" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93256878011447&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93501427820328&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/592">bid592</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3291.php">http-aspupload-bo(3291)</ref></refs><vuln_soft><prod name="AspUpload" vendor="Persits Software"><vers num="1.4.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1536" published="1999-07-30" seq="1999-1536" severity="High" type="CVE"><desc><descript source="cve">.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93347785827287&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/560">bid560</ref><ref source="OSVDB" url="http://www.osvdb.org/13557">
13557</ref></refs><vuln_soft><prod name="SalesBuilder" vendor="Acushop"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-1999-1537" published="1999-07-07" seq="1999-1537" severity="Medium" type="CVE"><desc><descript source="cve">IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=93138827329577&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/521">bid521</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2352.php">ssl-iis-dos(2352)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1538" published="1999-01-14" seq="1999-1538" severity="Low" type="CVE"><desc><descript source="cve">When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator&apos;s password.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91638375309890&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref><ref patch="1" source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91632724913080&amp;w=2">19990114 MS IIS 4.0 Security Advisory</ref><ref source="XFORCE" url="http://www.securityfocus.com/bid/189">NT IIS4 Remote Web-Based Administration Vulnerability</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-1999-1539" published="1999-11-10" seq="1999-1539" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FTP server in QPC Software&apos;s QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94223972910670&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/796">bid796</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3491.php">qvtterm-login-dos(3491)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225924803704&amp;w=2">19991110 Remote DoS Attack in QVT/Term &apos;Plus&apos; 4.2d FTP Server Vulnerability</ref></refs><vuln_soft><prod name="QVT Term Plus" vendor="QPC Software"><vers num="4.2d"/><vers num="4.3"/></prod><prod name="QVT Net" vendor="QPC Software"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1540" published="1999-10-04" seq="1999-1540" severity="Low" type="CVE"><desc><descript source="cve">shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.atstake.com/research/advisories/1999/shell-lock.txt"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93916168802365&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3356.php">cactus-shell-lock-retrieve-shell-code(3356)</ref></refs><vuln_soft><prod name="Shell-Lock" vendor="Cactus Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1541" published="1999-10-04" seq="1999-1541" severity="High" type="CVE"><desc><descript source="cve">shell-lock in Cactus Software Shell Lock allows local users to read or modify decoded shell files before they are executed, via a symlink attack on a temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3358.php">cactus-shell-lock-root-privs(3358)</ref><ref source="L0PHT" url="http://www.atstake.com/research/advisories/1999/shell-lock.txt">19991004</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93916168802365&amp;w=2">19991005 Cactus Software&apos;s shell-lock</ref></refs><vuln_soft><prod name="Shell-Lock" vendor="Cactus Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1542" published="1999-10-04" seq="1999-1542" severity="High" type="CVE"><desc><descript source="cve">RPMMail before 1.4 allows remote attackers to execute commands via an e-mail message with shell metacharacters in the &quot;MAIL FROM&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93923853105687&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3353.php">linux-rh-rpmmail(3353)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93915641729415&amp;w=2">19991004 RH6.0 local/remote command execution</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-1999-1543" published="1999-07-10" seq="1999-1543" severity="Medium" type="CVE"><desc><descript source="cve">MacOS uses weak encryption for passwords that are stored in the Users &amp; Groups Data File.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93188174906513&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93736667813924&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/519">bid519</ref></refs><vuln_soft><prod name="Mac OS" vendor="Apple"><vers num="7.5.3"/><vers num="7.6"/><vers num="7.6.1"/><vers num="8.0"/><vers num="8.1"/><vers num="8.5"/><vers num="8.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1544" published="1999-01-24" seq="1999-1544" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91722115016183&amp;w=2">19990124 Advisory: IIS FTP Exploit/DoS Attack</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1545" published="1999-07-14" seq="1999-1545" severity="Low" type="CVE"><desc><descript source="cve">Joe&apos;s Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93226771401036&amp;w=2"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93216103027827&amp;w=2">19990714 </ref></refs><vuln_soft><prod name="Joe" vendor="Joes Own Editor"><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1546" published="1999-01-29" seq="1999-1546" severity="Medium" type="CVE"><desc><descript source="cve">netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12217">19990129 TROJAN: netstation.navio-comm.rte 1.1.0.1</ref><ref source="XF" url="http://xforce.iss.net/static/1724.php">navionc-config-script(1724)</ref></refs><vuln_soft><prod name="Navio NC Browser" vendor="IBM"><vers num="1.1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-04-04" name="CVE-1999-1547" published="1999-11-25" seq="1999-1547" severity="High" type="CVE"><desc><descript source="cve">Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94390053530890&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/841">bid841</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94359982417686&amp;w=2">19991125 Oracle Web Listener</ref></refs><vuln_soft><prod name="Web Listener" vendor="Oracle"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1548" published="1999-11-24" seq="1999-1548" severity="Medium" type="CVE"><desc><descript source="cve">Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Razor" url="http://razor.bindview.com/publish/advisories/adv_Cabletron.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/841">821</ref></refs><vuln_soft><prod name="SmartSwitch Router 8000 firmware" vendor="Cabletron"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1549" published="1999-11-16" seq="1999-1549" severity="Medium" type="CVE"><desc><descript source="cve">Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a &quot;secure&quot; hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user&apos;s configuration file and execute commands.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94286509804526&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/804">bid804</ref></refs><vuln_soft><prod name="Lynx" vendor="University of Kansas"><vers num="2.7"/><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-1550" published="1999-11-08" seq="1999-1550" severity="Medium" type="CVE"><desc><descript source="cve">bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the &quot;file&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217006208374&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94217879020184&amp;w=2"></ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94225879703021&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/778">bid778</ref><ref source="XF" url="http://www.iss.net/security_center/static/7771.php">bigip-bigconf-view-files(7771)</ref></refs><vuln_soft><prod name="BigIP" vendor="F5"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1551" published="1999-03-02" seq="1999-1551" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92038879607336&amp;w=2">19990302 Multiple IMail Vulnerabilites</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/505">505</ref><ref source="XF" url="http://xforce.iss.net/static/1898.php">imail-websvc-overflow(1898)</ref></refs><vuln_soft><prod name="IMail" vendor="Ipswitch"><vers num="6.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1552" published="1994-07-20" seq="1999-1552" severity="High" type="CVE"><desc><descript source="cve">dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/358">bid358</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/7208.php">aix-dpsexec-root (7208)</ref><ref source="BUGTRAQ" url="http://lists.insecure.org/lists/bugtraq/1994/Jul/0038.html">19940720 xnews and XDM</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.5" prev="1"/><vers num="3.1"/><vers num="3.2"/><vers num="3.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1553" published="1999-05-01" seq="1999-1553" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.</descript></desc><sols><sol source="nvd">The authors were notified of this problem and it was fixed in devel-release 0.99.7.</sol></sols><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12730">19990301 [0z0n3] XCmail remotely exploitable vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/311">311</ref><ref source="XF" url="http://xforce.iss.net/static/1859.php">xcmail-reply-overflow(1859)</ref></refs><vuln_soft><prod name="XCmail" vendor="XCmail"><vers num="0.99.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1554" published="1990-10-31" seq="1999-1554" severity="Low" type="CVE"><desc><descript source="cve">/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1990-08.html">CA-1990-08</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/13">bid13</ref><ref source="XF" url="http://www.iss.net/security_center/static/3164.php">sgi-irix-reset(3164)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="3.3"/><vers num="3.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1555" published="1998-06-11" seq="1999-1555" severity="High" type="CVE"><desc><descript source="cve">Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with &quot;EVERYONE FULL CONTROL&quot; permissions, which allows local users to cause Inoculan&apos;s antivirus update feature to install a Trojan horse dll.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/9515"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1536.php">inoculan-bad-permissions(1536)</ref></refs><vuln_soft><prod name="InocuLAN Anti-Virus Server" vendor="Cheyenne"><vers edition="SP 2" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-1999-1556" published="1998-06-29" seq="1999-1556" severity="High" type="CVE"><desc><descript source="cve">Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading and decrypting the CmdExecAccount value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=90222453431645&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/109">bid109</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/7354">Microsoft SQL Server 6.5 stores the SQLExecutiveCmdExec in registry using weak encryption algorithm</ref></refs><vuln_soft><prod name="SQL Server" vendor="Microsoft"><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1557" published="2005-05-02" seq="1999-1557" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92038879607336&amp;w=2">19990301 Multiple IMail Vulnerabilites</ref><ref patch="1" source="XF" url="http://xforce.iss.net/static/1895.php">imail-imap-overflow(1895)</ref></refs><vuln_soft><prod name="IMail" vendor="Ipswitch"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-1558" published="1998-07-16" seq="1999-1558" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-071a.shtml">I-071A</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/161">bid161</ref><ref source="XF" url="http://www.iss.net/security_center/static/7151.php">openvms-loginout-unauth-access(7151)</ref></refs><vuln_soft><prod name="Digital OpenVMS AXP" vendor="Digital"><vers num="7.1"/></prod><prod name="Digital OpenVMS" vendor="Digital"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-1559" published="1999-03-31" seq="1999-1559" severity="Medium" type="CVE"><desc><descript source="cve">Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92299263017061&amp;w=2">19990331 Xylan OmniSwitch </ref><ref adv="1" source="XF" url="http://xforce.iss.net/static/2064.php">xylan-omniswitch-login(2064)</ref></refs><vuln_soft><prod name="OmniSwitch" vendor="Alcatel"><vers num="3.2.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-1999-1560" published="1999-07-20" seq="1999-1560" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in a script in Texas A&amp;M University (TAMU) Tiger allows local users to execute arbitrary commands as the Tiger user, usually root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93252050203589&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2369.php">tiger-script-execute(2369)</ref></refs><vuln_soft><prod name="Tiger" vendor="TAMU"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1561" published="1999-08-20" seq="1999-1561" severity="High" type="CVE"><desc><descript source="cve">Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/24852"></ref></refs><vuln_soft><prod name="SHOUTcast server" vendor="Nullsoft"><vers edition="Win32" num="1.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1562" published="1999-09-05" seq="1999-1562" severity="Medium" type="CVE"><desc><descript source="cve">gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/26915"></ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-084">DSA-084</ref><ref source="BID" url="http://www.securityfocus.com/bid/3446">3446</ref></refs><vuln_soft><prod name="FTP client" vendor="GFTP"><vers num="1.13"/><vers num="2.0.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1563" published="2000-10-14" seq="1999-1563" severity="Medium" type="CVE"><desc><descript source="cve">Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/30849"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/35075"></ref></refs><vuln_soft><prod name="D445" vendor="Nachuatec"><vers num=""/></prod><prod name="D435" vendor="Nachuatec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1564" published="1999-09-02" seq="1999-1564" severity="Low" type="CVE"><desc><descript source="cve">FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/26166"></ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-1999-1565" published="1999-08-20" seq="1999-1565" severity="Medium" type="CVE"><desc><descript source="cve">Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/24784"></ref><ref source="OSVDB" url="http://www.osvdb.org/6291">6291</ref></refs><vuln_soft><prod name="Man2html" vendor="Earl Hood"><vers num="2.1" prev="1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1566" published="1999-05-08" seq="1999-1566" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/13600"></ref></refs><vuln_soft><prod name="iParty" vendor="Intel"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1567" published="1999-03-08" seq="1999-1567" severity="Medium" type="CVE"><desc><descript source="cve">Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconnecting without sending any data.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/static/1948.php">testtrack-dos(1948)</ref></refs><vuln_soft><prod name="TestTrack" vendor="Seapine Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-14" name="CVE-1999-1568" published="1999-01-01" seq="1999-1568" severity="Medium" type="CVE"><desc><descript source="cve">Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="SEIFRIED" url="http://www.seifried.org/security/index.php?title=CVE-1999-1568&amp;printable=yes">CVE-1999-1568</ref><ref source="ColaSoft" url="http://colasoft.com/resources/vulnerability.php?id=CAN-1999-1568">CAN-1999-1568</ref><ref source="" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91981352617720&amp;w=2"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12699">19990223 Comments on NcFTPd &quot;theoretical root compromise&quot;</ref><ref source="XF" url="http://xforce.iss.net/static/1833.php">ncftpd-port-bo(1833)</ref></refs><vuln_soft><prod name="NcFTPd FTP server" vendor="NcFTPd"><vers num="2.4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1569" published="2001-07-17" seq="1999-1569" severity="Medium" type="CVE"><desc><descript source="cve">Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server&apos;s player limit.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6871.php">quake-spoofed-client-dos(6871)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/3051">ID Software Quake Denial of Service Vulnerability</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91012172524181&amp;w=2"></ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/197268">20010716 Quake client and server denial-of-service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925989&amp;w=2">19980502 NetQuake Protocol problem resulting in smurf like effect.</ref></refs><vuln_soft><prod name="Quake" vendor="id Software"><vers num="1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1570" published="2002-05-01" seq="1999-1570" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in sar for OpenServer 5.0.5 allows local users to gain root privileges via a long -o parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/4089">Multiple Vendor SNMP Request Handling Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/8989.php">openserver-sar-bo(8989)</ref><ref adv="1" patch="1" source="Caldera" url="ftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.17/CSSA-2002-SCO.17.txt">CSSA-2002-SCO.17</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/27074">19990909 19 SCO 5.0.5+Skunware98 buffer overflows</ref><ref source="VULN-DEV" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=102098949103708&amp;w=2">20020509 Sar -o exploitation process info.</ref></refs><vuln_soft><prod name="OpenServer" vendor="Caldera"><vers num="5.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-1999-1571" published="1999-11-04" seq="1999-1571" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in sar for SCO OpenServer 5.0.0 through 5.0.5 may allow local users to gain root privileges via a long -f parameter, a different vulnerability than CVE-1999-1570.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93762097815861&amp;w=2"></ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/8989.php">Caldera OpenServer /usr/bin/sar buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/advisories/1843">Multiple vulnerabilities in OpenServer 5.0.0 through 5.0.5</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/27074">19990909 19 SCO 5.0.5+Skunware98 buffer overflows</ref><ref source="SCO" url="ftp://stage.caldera.com/pub/security/sse/security_bulletins/SB-99.17c">SB-99.17c</ref><ref source="CONFIRM" url="ftp://stage.caldera.com/pub/security/sse/sse037c/sse037c.ltr">ftp://stage.caldera.com/pub/security/sse/sse037c/sse037c.ltr</ref><ref source="BID" url="http://online.securityfocus.com/bid/643">643</ref><ref source="BID" url="http://www.securityfocus.com/bid/643">643</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94053017801639&amp;w=2">19991020 Re: recent SCO 5.0.x vulnerabilities</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94183363719024&amp;w=2">19991105 SCO Security Bulletin 99.17</ref><ref source="VULN-DEV" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=102098949103708&amp;w=2">20020509 Sar -o exploitation process info.</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.0"/><vers num="5.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1572" published="1996-07-16" seq="1999-1572" severity="Low" type="CVE"><desc><descript source="cve">cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.</descript></desc><sols><sol source="nvd">Fixed in rev 1.3 of cpio/main.c.</sol></sols><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391">http://www.freebsd.org/cgi/query-pr.cgi?pr=bin/1391</ref><ref source="DEBIAN" url="http://www.debian.org/security/2005/dsa-664">DSA-664</ref><ref source="MANDRAKE" url="http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:032">MDKSA-2005:032</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-073.html">RHSA-2005:073</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-080.html">RHSA-2005:080</ref><ref source="TRUSTIX" url="http://www.trustix.org/errata/2005/0003/">2005-0003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/19167">cpio-o-archive-insecure-permissions(19167)</ref><ref source="" url="http://support.avaya.com/elmodocs2/security/ASA-2005-212.pdf"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2005-806.html">RHSA-2005:806</ref><ref source="SECUNIA" url="http://secunia.com/advisories/14357">14357</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17063">17063</ref><ref source="SECUNIA" url="http://secunia.com/advisories/17532">17532</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=110763404701519&amp;w=2">20050204 [USN-75-1] cpio vulnerability</ref><ref source="MANDRAKE" url="http://www.mandriva.com/security/advisories?name=MDKSA-2005:032">MDKSA-2005:032</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0"/></prod><prod name="Desktop" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Ubuntu Linux" vendor="Ubuntu"><vers num="4.10"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="9.2"/><vers num="10.0"/><vers num="10.1"/><vers num="CS2.1"/><vers num="CS3.0"/></prod><prod name="Enterprise Linux" vendor="Red Hat"><vers edition="Advanced Server" num="4.0"/><vers edition="Enterprise Server" num="4.0"/><vers edition="Workstation" num="4.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1573" published="1999-12-28" seq="1999-1573" severity="High" type="CVE"><desc><descript source="cve">Multiple unknown vulnerabilities in the &quot;r-cmnds&quot; (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="HP" url="http://www.securityfocus.com/advisories/1471">HPSBUX9812-090</ref><ref patch="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=490">ESB-98.186</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/13217">VU#13217</ref><ref patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-022.shtml">J-022</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/7860">hp-rcmnds-gain-privileges(7860)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.00"/><vers num="10.30"/><vers num="10.20"/><vers num="10.10"/><vers num="10.01"/><vers num="10.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1574" published="1998-07-06" seq="1999-1574" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via &quot;long input strings.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX79909&amp;apar=only">IX79909</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/182777">VU#182777</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7867">aix-nslookup-lex-bo(7867)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1575" published="1999-09-10" seq="1999-1575" severity="Medium" type="CVE"><desc><descript source="cve">The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as &quot;Safe for Scripting,&quot; which allows remote attackers to create and modify files and execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719">19990924 Several ActiveX Buffer Overruns</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-037.mspx">MS99-037</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/23412">VU#23412</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/24839">VU#24839</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/26924">VU#26924</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/41408">VU#41408</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/9162">VU#9162</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7097">wang-kodak-activex-control(7097)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.01"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1576" published="1999-09-27" seq="1999-1576" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary code via the pdf.setview method.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719">19990924 Several ActiveX Buffer Overruns</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/25919">VU#25919</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/666">666</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/3318">adobe-acrobat-pdf-bo(3318)</ref></refs><vuln_soft><prod name="Acrobat ActiveX Control" vendor="Adobe"><vers num="1.3.188"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1577" published="1999-10-31" seq="1999-1577" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719">19990924 Several ActiveX Buffer Overruns</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/29795">VU#29795</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/0669">Microsoft hhopen OLE Control Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3314">ie-hhopen-bo(3314)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.01"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1578" published="1999-09-24" seq="1999-1578" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/28719">19990924 Several ActiveX Buffer Overruns</ref><ref adv="1" patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/37556">VU#37556</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/671">671</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3311">ie-registration-wiz-bo(3311)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="4.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1579" published="2000-12-14" seq="1999-1579" severity="Medium" type="CVE"><desc><descript source="cve">The Cenroll ActiveX control (xenroll.dll) for Terminal Server Editions of Windows NT 4.0 and Windows NT Server 4.0 before SP6 allows remote attackers to cause a denial of service (resource consumption) by creating a large number of arbitrary files on the target machine.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;242366">Q242366</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/3062">VU#3062</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/6827">Windows NT Xenroll Library Storage Consumption Vulnerability</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/7107">winnt-xenroll-dos(7107)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1580" published="1995-08-23" seq="1999-1580" severity="High" type="CVE"><desc><descript source="cve">SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html">http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html</ref><ref adv="1" source="AUSCERT" url="http://www.auscert.org.au/render.html?it=1853&amp;cid=1978">AA-95.09</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.11.sun.sendmail-oR.vul">CA-1995-11</ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/3278">VU#3278</ref><ref source="BID" url="http://www.securityfocus.com/bid/7829">7829</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="5.59"/><vers num="5.61"/><vers num="5.65"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3c"/><vers num="4.1.3u1"/><vers num="4.1.3"/><vers num="4.1.4JL"/><vers num="4.1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1581" published="1997-12-23" seq="1999-1581" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a denial of service (memory consumption) via a large number of SNMP packets with Object Identifiers (OIDs) that cannot be decoded.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref source="MSKB" url="http://support.microsoft.com/kb/q178381/">Q178381</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/4923">VU#4923</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/8231">winnt-snmp-oid-memory-leak(8231)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="4.0 SP1"/><vers num="4.0 SP2"/><vers num="4.0 SP3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-03" name="CVE-1999-1582" published="1998-07-15" seq="1999-1582" severity="High" type="CVE"><desc><descript source="cve">By design, the &quot;established&quot; command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="CISCO" url="http://www.cisco.com/warp/public/707/pixest-pub.shtml">19980715 PIX Firewall </ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/6733">VU#6733</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/8052">cisco-pix-established-bypass(8052)</ref></refs><vuln_soft><prod name="PIX Firewall" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1583" published="1999-09-30" seq="1999-1583" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY02120&amp;apar=only">IY02120</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/872443">VU#872443</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/8031">aix-nslookup-hostname-bo(8031)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-1999-1584" published="1999-12-31" seq="1999-1584" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in (1) loadmodule, and (2) modload if modload is installed with setuid/setgid privileges, in SunOS 4.1.1 through 4.1.3c, and Open Windows 3.0, allows local users to gain root privileges via environment variables, a different vulnerability than CVE-1999-1586.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SUN" url="http://sunsolve.sun.com/search/document.do?assetkey=1-22-00124-1">00124</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1993-18.html">CA-93.18</ref></refs><vuln_soft><prod name="OpenWindows" vendor="Sun"><vers num="3.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.3c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-1585" published="1999-12-31" seq="1999-1585" severity="High" type="CVE"><desc><descript source="cve">The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SUN" url="http://sunsolve.sun.com/search/document.do?assetkey=1-22-00124-1">00124</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-1999-1586" published="1999-12-31" seq="1999-1586" severity="High" type="CVE"><desc><descript source="cve">loadmodule in SunOS 4.1.x, as used by xnews, does not properly sanitize its environment, which allows local users to gain privileges, a different vulnerability than CVE-1999-1584.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1995-12.html">CA-95.12</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/g-02.shtml">G-02</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/498">sun-loadmodule(498)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.3c"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="1996-08-30" modified="2006-05-01" name="CVE-1999-1587" published="1999-12-31" seq="1999-1587" severity="Low" type="CVE"><desc><descript source="cve">/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="" url="http://www.sunmanagers.org/archives/1996/1383.html"></ref><ref patch="1" source="SUNALERT" url="http://sunsolve.sun.com/search/document.do?assetkey=1-26-102215-1">102215</ref><ref adv="1" patch="1" source="FRSIRT" url="http://www.frsirt.com/english/advisories/2006/1123">ADV-2006-1123</ref><ref patch="1" source="SECTRACK" url="http://securitytracker.com/id?1015833">1015833</ref><ref adv="1" patch="1" source="SECUNIA" url="http://secunia.com/advisories/19426">19426</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25460">solaris-ps-information-disclosure(25460)</ref><ref source="OSVDB" url="http://www.osvdb.org/24200">24200</ref><ref source="BID" url="http://www.securityfocus.com/bid/19662">19662</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1470">oval:org.mitre.oval:def:1470</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="SPARC" num="9.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-1999-1588" published="1999-12-31" seq="1999-1588" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with &quot;NLPS:002:002:&quot; to the listen (aka System V listener) port, TCP port 2766.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="" url="http://security-protocols.com/sploits/unsorted_exploits/nlps_server.c"></ref><ref source="SECURITY FOCUS" url="http://www.securityfocus.com/data/vulnerabilities/exploits/nlps_server.c"></ref><ref source="" url="http://lsd-pl.net/files/get?SOLARIS/solx86_nlps_server"></ref><ref source="BID" url="http://www.securityfocus.com/bid/2319">2319</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.4"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="1992-05-05" modified="2006-06-15" name="CVE-1999-1589" published="1999-12-31" seq="1999-1589" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1992-10.html">CA-1992-10</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/357">357</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="3.1"/><vers num="2.2.1"/><vers num="1.3"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.5" CVSS_exploit_subscore="6.8" CVSS_impact_subscore="2.9" CVSS_score="3.5" CVSS_vector="(AV:N/AC:M/Au:S/C:P/I:N/A:N)" CVSS_version="2.0" modified="2006-12-06" name="CVE-1999-1590" published="1999-12-31" seq="1999-1590" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Muhammad A. Muquit wwwcount (Count.cgi) 2.3 allows remote attackers to read arbitrary GIF files via &quot;..&quot; sequences in the image parameter, a different vulnerability than CVE-1999-0021.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://seclists.org/bugtraq/1997/Oct/0058.html">19971010 Security flaw in Count.cgi (wwwcount)</ref></refs><vuln_soft><prod name="wwwcount" vendor="wwwcount"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-01" name="CVE-1999-1591" published="1999-12-31" seq="1999-1591" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Information Services (IIS) server 4.0 SP4, without certain hotfixes released for SP4, does not require authentication credentials under certain conditions, which allows remote attackers to bypass authentication requirements, as demonstrated by connecting via Microsoft Visual InterDev 6.0.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00276.html">19990118 IIS4.0 and Visual Interdev</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/1998-1999/msg00277.html">19990119 Re: IIS4.0 and Visual Interdev</ref><ref source="BID" url="http://www.securityfocus.com/bid/190">190</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0 sp4"/></prod><prod name="Visual InterDev" vendor="Microsoft"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-08-01" name="CVE-1999-1592" published="1999-12-31" seq="1999-1592" severity="High" type="CVE"><desc><descript source="cve">Multiple unspecified vulnerabilities in sendmail 5, as installed on Sun SunOS 4.1.3_U1 and 4.1.4, have unspecified attack vectors and impact.  NOTE: this might overlap CVE-1999-0129.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="SUN" url="http://sunsolve.sun.com/search/document.do?assetkey=1-22-00159-1">00159</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/243">243</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail"><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2000-0001" published="1999-12-23" seq="2000-0001" severity="Medium" type="CVE"><desc><descript source="cve">RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/888">BID 888</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4296.php">realserver-ramgen-dos(4296)</ref><ref source="BID" url="http://www.securityfocus.com/bid/888">888</ref></refs><vuln_soft><prod name="RealServer" vendor="RealNetworks"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-2000-0002" published="1999-12-22" seq="2000-0002" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3809.php">zbserver-get-bo(3809)</ref><ref adv="1" source="UssrBack" url="http://www.ussrback.com/labs24.html">Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-22%26msg%3DNCBBKFKDOLAGKIAPMILPOELLCBAA.labs@ussrback.com">Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref><ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94598388530358&amp;w=2">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=36B0596E.8D111D66@teleline.es">20000128 ZBServer 1.50-r1x exploit (WinNT)</ref><ref source="BID" url="http://www.securityfocus.com/bid/889">889</ref></refs><vuln_soft><prod name="ZBServer" vendor="ZBSoft"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0003" published="1999-12-30" seq="2000-0003" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in UnixWare rtpm program allows local users to gain privileges via a long environmental variable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-01-22&amp;msg=Pine.SV4.3.96.000127183714.1040D-100000@ripley.london.sco.com">local-buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94908470928258&amp;w=2">20000127 New SCO patches...</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0004" published="1999-12-01" seq="2000-0004" severity="Medium" type="CVE"><desc><descript source="cve">ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4319.php">zbserver-url-dot(4319)</ref><ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=NTBUGTRAQ&amp;P=R3556">19991223 Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606572912422&amp;w=2">19991223 Re: Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT</ref></refs><vuln_soft><prod name="ZBServer" vendor="ZBSoft"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0005" published="1999-01-02" seq="2000-0005" severity="High" type="CVE"><desc><descript source="cve">HP-UX aserver program allows local users to gain privileges via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-1.php">hp-aserver</ref><ref adv="1" patch="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-014.shtml">K-014: HP-UX Aserver Vulnerability</ref></refs><vuln_soft><prod name="Aserver" vendor="HP"><vers num=""/></prod><prod name="HP9000" vendor="HP"><vers num="7_800"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.34"/><vers num="10.30"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.9"/><vers num="10.8"/><vers num="10.1"/><vers num="10.0.1"/><vers num="10.0"/><vers num="9.10"/><vers num="9.9"/><vers num="9.8"/><vers num="9.7"/><vers num="9.6"/><vers num="9.5"/><vers num="9.4"/><vers num="9.3"/><vers num="9.1"/><vers num="9.0"/><vers num="8.9"/><vers num="8.8"/><vers num="8.7"/><vers num="8.6"/><vers num="8.5"/><vers num="8.4"/><vers num="8.2"/><vers num="8.1"/><vers num="8.0"/><vers num="7.8"/><vers num="7.6"/><vers num="7.4"/><vers num="7.2"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="4.9" CVSS_score="2.6" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-2000-0006" published="1999-12-25" seq="2000-0006" severity="Low" type="CVE"><desc><descript source="cve">strace allows local users to read arbitrary files via memory mapped file names.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4554.php">linux-strace(4554)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-22%26msg%3D19991225230452.C114@bug.ucw.cz">strace can lie</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/39831">19991225 strace can lie</ref></refs><vuln_soft><prod name="Strace" vendor="Paul Kranenburg"><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num="2.3.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0007" published="1999-12-29" seq="2000-0007" severity="Medium" type="CVE"><desc><descript source="cve">Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4491.php">pccillin-proxy-remote-dos(4491)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-29%26msg%3D004401bf52f4%24e185bf80%241ef084ce@karemor.com">PC-Cillin 6.x DoS Attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/1740">1740</ref></refs><vuln_soft><prod name="PC-cillin" vendor="Trend Micro"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0008" published="1999-12-26" seq="2000-0008" severity="Low" type="CVE"><desc><descript source="cve">FTPPro allows local users to read sensitive information, which is stored in plain text.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4490.php">ftppro-plaintext-information(4490)</ref><ref source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-22%26msg%3DPine.LNX.4.10.9912270855530.13115-100000@7of9.neohapsis.com">FTPPro insecuities</ref></refs><vuln_soft><prod name="FTPPro" vendor="1st Choice Software"><vers num="7.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0009" published="1999-12-29" seq="2000-0009" severity="High" type="CVE"><desc><descript source="cve">The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the &quot;rm&quot; program, which allows local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4489.php">netarchitect-path-vulnerability(4489)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D907">Optivity NETarchitect PATH Vulnerability</ref><ref source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19991230224901.2D54E1F388@lists.securityfocus.com">bna,sh</ref><ref source="BID" url="http://www.securityfocus.com/bid/907">907</ref></refs><vuln_soft><prod name="Optivity NETarchitect" vendor="Nortel"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0010" published="1999-12-26" seq="2000-0010" severity="High" type="CVE"><desc><descript source="cve">WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/892">BID 892</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3748.php">http-cgi-webwhoplus(3748)</ref></refs><vuln_soft><prod name="WebWho+" vendor="Tony Greenwood"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2000-0011" published="1999-12-31" seq="2000-0011" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/906">BID 906</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4297.php">simpleserver-get-bo(4297)</ref><ref source="MISC" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/906">906</ref><ref source="OSVDB" url="http://www.osvdb.org/1184">1184</ref></refs><vuln_soft><prod name="SimpleServer" vendor="AnalogX"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0012" published="1999-12-27" seq="2000-0012" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3766.php">w3-msql-scanf-bo(3766)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/898">BID 898</ref><ref source="BID" url="http://www.securityfocus.com/bid/898">898</ref></refs><vuln_soft><prod name="mSQL" vendor="Hughes"><vers num="2.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0013" published="1999-12-31" seq="2000-0013" severity="High" type="CVE"><desc><descript source="cve">IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/909">BID 909</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4298.php">irix-soundplayer-symlink(4298)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-04-15%26msg%3D19991231112220.B283C1FA59@lists.securityfocus.com"> irix-soundplayer.sh</ref><ref source="BID" url="http://www.securityfocus.com/bid/909">909</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0014" published="1999-12-28" seq="2000-0014" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Savant web server via a null character in the requested URL.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/897">BID 897</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3762.php">savant-server-null-dos(3762)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-22%26msg%3DNCBBKFKDOLAGKIAPMILPAENGCBAA.labs@ussrback.com"> Local / Remote D.o.S Attack in Savant Web Server V2.0 WIN9X / NT / 2K</ref><ref source="BID" url="http://www.securityfocus.com/bid/897">897</ref></refs><vuln_soft><prod name="Savant WebServer" vendor="Michael Lamont"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0015" published="1999-12-31" seq="2000-0015" severity="Medium" type="CVE"><desc><descript source="cve">CascadeView TFTP server allows local users to gain privileges via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/910">BID 910</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4388.php">cascadeview-tftp-symlink(4388)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19991231164825.3B3211F5F7@lists.securityfocus.com"> tftpserv.sh</ref><ref source="BID" url="http://www.securityfocus.com/bid/910">910</ref></refs><vuln_soft><prod name="CascadeView_UX" vendor="Ascend"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0016" published="1999-10-01" seq="2000-0016" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-8.phpiams-pop3-command-dos">iams-pop3-command-dos</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9910&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=662">Vulnerabilities in the Internet Anywhere Mail Server</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D730">Internet Anywhere Mail Server Multiple Buffer Overflow Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/730">730</ref></refs><vuln_soft><prod name="Internet Anywhere Mail Server" vendor="True North"><vers num="2.3.1"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0017" published="1999-12-21" seq="2000-0017" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94580196627059&amp;w=2">(Possible) Linuxconf Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="Linux Weekly News" url="http://lwn.net/1999/1223/a/linuxconfresponse.html">(Possible) Linuxconf Remote Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0018" published="1999-12-22" seq="2000-0018" severity="High" type="CVE"><desc><descript source="cve">wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/885">BID 885</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4382.php">freebsd-wmmon-root-exploit(4382)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-15&amp;msg=19991221003643.A7521@grok.localnet"> Wmmon under FreeBSD</ref><ref source="BID" url="http://www.securityfocus.com/bid/885">885</ref><ref source="OSVDB" url="http://www.osvdb.org/1169">1169</ref></refs><vuln_soft><prod name="wmmon" vendor="WindowMaker"><vers num="1.0b2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0019" published="1999-03-04" seq="2000-0019" severity="Low" type="CVE"><desc><descript source="cve">IMail POP3 daemon uses weak encryption, which allows local users to read files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-7.php">imail-passwords</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9903a&amp;L=bugtraq&amp;F=&amp;S=&amp;P=1193">IMAIL password recovery is trivial</ref></refs><vuln_soft><prod name="Imail" vendor="Ipswitch"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0020" published="1999-12-20" seq="2000-0020" severity="Medium" type="CVE"><desc><descript source="cve">DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-15&amp;msg=NCBBKFKDOLAGKIAPMILPCEKKCBAA.labs@ussrback.com">Remote D.o.S Attack in DNS PRO v5.7 WinNT From FBLI Software Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3811.php">dnspro-flood-dos(3811)</ref><ref adv="1" source="USSR" url="http://www.ussrback.com/">USSR Advisory Code:    22</ref></refs><vuln_soft><prod name="DNS PRO" vendor="Man and Mice"><vers num="5.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0021" published="1999-12-01" seq="2000-0021" severity="Medium" type="CVE"><desc><descript source="cve">Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4389.php">http-cgi-lotus-domino(4389)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-22%26msg%3DOF393D9FCA.A3040608-ON85256854.0079C253@lotus.com">Re: Lotus Domino HTTP denial of service attack</ref><ref adv="1" patch="1" source="Lotus Customer Support" url="http://www.support.lotus.com/sims2.nsf/0/6ecb87e6e6820b008525659f0080d40c?OpenDocument">Domino Web Server Crashes When CGI Scripts are Being Accessed</ref><ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref></refs><vuln_soft><prod name="Domino Server" vendor="Lotus"><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0022" published="1999-12-21" seq="2000-0022" severity="Medium" type="CVE"><desc><descript source="cve">Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-15&amp;msg=19991221114213.H54294@yoko.hsc.fr"> serious Lotus Domino HTTP denial of service</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4390.php">lotus-domino-anonymous-access(4390)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/885">BID 885</ref><ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref></refs><vuln_soft><prod name="Domino Server" vendor="Lotus"><vers num="4.6.x"/><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0023" published="1999-12-21" seq="2000-0023" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-15&amp;msg=19991221114213.H54294@yoko.hsc.fr"> serious Lotus Domino HTTP denial of service</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/885">BID 881</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4391.php">lotus-domino-http-dos(4391)</ref><ref source="BID" url="http://www.securityfocus.com/bid/881">881</ref><ref source="OSVDB" url="http://www.osvdb.org/51">51</ref></refs><vuln_soft><prod name="Domino Server" vendor="Lotus"><vers num="4.6.x"/><vers num="4.6"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0024" published="1999-12-21" seq="2000-0024" severity="Medium" type="CVE"><desc><descript source="cve">IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the &quot;Escape Character Parsing&quot; vulnerability.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/886">BID 886</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-061.asp">MS99-061</ref><ref source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9912292138530.17163-100000@eight.wiretrip.net">19991229 More info on MS99-061 (IIS escape character vulnerability)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3731.php">iis-badescapes(3731)</ref><ref source="" url="http://www.acrossecurity.com/aspr/ASPR-1999-11-10-1-PUB.txt"></ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-061.asp">MS99-061</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246401">Q246401</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/><vers num="Commerce 3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0025" published="1999-12-21" seq="2000-0025" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the &quot;Virtual Directory Naming&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-058.asp">MS99-058</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4392.php">iis-virtual-directory-naming(4392)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/885">BID 882</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-058.mspx">MS99-058</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q238606">Q238606</ref><ref source="OSVDB" url="http://www.osvdb.org/8098">8098</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/><vers num="Commerce 3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0026" published="1999-12-21" seq="2000-0026" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-15&amp;msg=19991222064519.11124.qmail@www0q.netaddress.usa.net">UnixWare i2odialogd remote root exploit</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4062.php">sco-i2odialogd-bo(4062)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/885">BID 876</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94606167110764&amp;w=2">19991223 FYI, SCO Security patches available.</ref><ref source="BID" url="http://www.securityfocus.com/bid/876">876</ref><ref source="OSVDB" url="http://www.osvdb.org/6310">6310</ref></refs><vuln_soft><prod name="wmmon" vendor="WindowMaker"><vers num="1.0b2"/></prod><prod name="Unixware" vendor="SCO"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0027" published="1999-12-27" seq="2000-0027" severity="Medium" type="CVE"><desc><descript source="cve">IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=900">IBM Network Station Manager Race Condition Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19991228020929.1780.qmail@nw173.netaddress.usa.net">IBM NetStation/UnixWare local root exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/39962">19991227 IBM NetStation/UnixWare local root exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/900">900</ref><ref source="XF" url="http://www.iss.net/security_center/static/5381.php">ibm-netstat-race-condition(5381)</ref></refs><vuln_soft><prod name="Network Station Manager" vendor="IBM"><vers num="2.0R1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0028" published="1999-12-23" seq="2000-0028" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4456.php">ie-navigateandfind(4456)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-22%26msg%3D19991223162007.LENT16253.mta04.onebox.com@onebox.com">Re: IE 5.01 vulnerabilities in external.NavigateAndFind()</ref><ref adv="1" source="ISS X-Force" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-22%26msg%3D3860D6F8.CFEF6D9C@nat.bg">IE 5.01 vulnerabilities in external.NavigateAndFind()</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.1"/><vers num="5.0"/><vers num="4.5"/><vers num="4.1"/><vers edition="SP2" num="4.0.1"/><vers edition="a Mac OS" num="4.0"/><vers num="4.0"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0.2"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0029" published="1999-12-27" seq="2000-0029" severity="Medium" type="CVE"><desc><descript source="cve">UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/901">BID 901</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-22&amp;msg=19991228033701.14290.qmail@nwcst091.netaddress.usa.net">19991227 UnixWare local pis exploit</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4393.php">sco-pis-symlink(4393)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref><ref source="BID" url="http://www.securityfocus.com/bid/901">901</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0030" published="1999-12-22" seq="2000-0030" severity="Medium" type="CVE"><desc><descript source="cve">Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/878">BID 878</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4394.php">sol-dmispd-fill-disk(4394)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-15%26msg%3D19991222170733.24846.qmail@nwcst313.netaddress.usa.net"> Solaris 2.7 dmispd local/remote problems</ref><ref source="BID" url="http://www.securityfocus.com/bid/878">878</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0031" published="2000-10-20" seq="2000-0031" severity="Medium" type="CVE"><desc><descript source="cve">The initscripts package in Red Hat Linux allows local users to gain privileges via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4159.php">linux-initscripts-race(4159)</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA1999052-04.html">initscripts</ref><ref adv="1" patch="1" source="L0pht Security Advisory" url="http://www.l0pht.com/advisories/init_advisory.txt">Advisory Released 12.27.1999</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0032" published="1999-12-22" seq="2000-0032" severity="High" type="CVE"><desc><descript source="cve">Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/878">BID 878</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4395.php">sol-dmispd-dos(4395)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-15%26msg%3D19991222170733.24846.qmail@nwcst313.netaddress.usa.net"> Solaris 2.7 dmispd local/remote problems</ref><ref source="BID" url="http://www.securityfocus.com/bid/878">878</ref><ref source="OSVDB" url="http://www.osvdb.org/7582">7582</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0033" published="1999-12-27" seq="2000-0033" severity="Medium" type="CVE"><desc><descript source="cve">InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/899">BID 899</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3767.php">interscan-viruswall-bypass(3767)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D3867EFD2.887D0023@usa.alcatel.com">Trend Micro InterScan VirusWall SMTP bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/899">899</ref></refs><vuln_soft><prod name="InterScan VirusWall" vendor="Trend Micro"><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0034" published="1999-12-22" seq="2000-0034" severity="Medium" type="CVE"><desc><descript source="cve">Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled &quot;remember passwords.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4492.php">netscape-password-preferences(4492)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-22%26msg%3D38604C7C.75E16D88@cwo.com.au">More Netscape Passwords availiable</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0035" published="1999-12-28" seq="2000-0035" severity="Medium" type="CVE"><desc><descript source="cve">resend command in Majordomo allows local users to gain privileges via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3764.php">majordomo-local-resend(3764)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19991229024744.23364.qmail@nwcst292.netaddress.usa.net">majordomo local exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/902">902</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref></refs><vuln_soft><prod name="Majordomo" vendor="Great Circle Associates"><vers num="1.94.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0036" published="1999-12-22" seq="2000-0036" severity="Medium" type="CVE"><desc><descript source="cve">Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the &quot;HTML Mail Attachment&quot; vulnerability.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-060.asp">MS99-060</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3551.php">macos-outlook-file-download(3551)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/901">BID 883</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q249082">Q249082</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Macintosh" num="4.5"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers edition="MacOS" num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0037" published="1999-12-28" seq="2000-0037" severity="Medium" type="CVE"><desc><descript source="cve">Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-22&amp;msg=19991229024744.23364.qmail@nwcst292.netaddress.usa.net"></ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/903">BID 903</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3761.php">majordomo-local-c-parameter(3761)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780294009285&amp;w=2">20000113 Info on some security holes reported against SCO Unixware.</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-005.html">RHSA-2000:005</ref><ref source="BID" url="http://www.securityfocus.com/bid/903">903</ref></refs><vuln_soft><prod name="Majordomo" vendor="Great Circle Associates"><vers num="1.94.5"/><vers num="1.94.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0038" published="1999-12-23" seq="2000-0038" severity="High" type="CVE"><desc><descript source="cve">glFtpD includes a default glftpd user account with a default password and a UID of 0.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4457.php">glftpd-default-account(4457)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-22%26msg%3DPine.LNX.4.20.9912231131330.22882-100000@jawa.chilli.net.au">Multiple vulnerabilites in glFtpD (current versions)</ref><ref source="suid.kg" url="http://www.suid.kg/advisories/003_wp.txt">Example attack</ref><ref patch="1" source="glFtpD" url="http://www.glftpd.org/glftpd.html">glFtpD home page</ref></refs><vuln_soft><prod name="GlFtpd" vendor="GlFtpd"><vers num="1.17.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0039" published="1999-12-29" seq="2000-0039" severity="Medium" type="CVE"><desc><descript source="cve">AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/896">BID 896</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-29&amp;msg=Pine.BSF.4.21.9912292256090.46516-100000@key-largo.cl.msu.edu">Traversal Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3754.php">http-cgi-avsearch(3754)</ref><ref source="BID" url="http://www.securityfocus.com/bid/896">896</ref><ref source="OSVDB" url="http://www.osvdb.org/15">15</ref></refs><vuln_soft><prod name="Search Intranet" vendor="AltaVista"><vers num="2.3A"/><vers num="2.0b"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0040" published="1999-12-23" seq="2000-0040" severity="High" type="CVE"><desc><descript source="cve">glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-22&amp;msg=Pine.LNX.4.20.9912231131330.22882-100000@jawa.chilli.net.au">Multiple vulnerabilites in glFtpD</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4458.php">glftpd-site-zipchk(4458)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/896">BID 891</ref></refs><vuln_soft><prod name="GlFtpd" vendor="GlFtpd"><vers num="1.17.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0041" published="1999-12-28" seq="2000-0041" severity="Medium" type="CVE"><desc><descript source="cve">Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-12-29&amp;msg=v04210105b491674f0c6a@%5B10.0.0.13%5D">19991229 The &quot;Mac DoS Attack,&quot; a Scheme for Blocking Internet Connections</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/890">BID 890</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/advisory.html?id=2006">Asymmetric traffic from MacOS 9</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3752.php">macos-opentransport-dos(3752)</ref><ref source="BID" url="http://www.securityfocus.com/bid/890">890</ref></refs><vuln_soft><prod name="Mac OS" vendor="Apple"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0042" published="1999-12-29" seq="2000-0042" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/895">BID 895</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3760.php">csm-server-bo(3760)</ref><ref adv="1" source="USSRBACK" url="http://www.ussrback.com/labs27.html">USSR-99027</ref><ref source="BID" url="http://www.securityfocus.com/bid/895">895</ref></refs><vuln_soft><prod name="Mail Server" vendor="CSM"><vers num="1999-07b"/><vers num="1999-07F"/><vers num="1999-07G"/><vers num="1999-07H"/><vers num="1999-07I"/><vers num="1999-07M"/><vers num="2000-01A"/><vers num="2000.8.A"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0043" published="1999-12-30" seq="2000-0043" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/905">BID 905</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/advisory.html?id=2015">Remote GET Buffer Overflow Vulnerability in CamShot WebCam</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3806.php">camshot-http-get-overflow(3806)</ref><ref source="BID" url="http://www.securityfocus.com/bid/905">905</ref></refs><vuln_soft><prod name="WebCam HTTP Server" vendor="CamShot"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0044" published="2000-01-06" seq="2000-0044" severity="High" type="CVE"><desc><descript source="cve">Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/919">BID 919</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3871.php">warftp-macro-access-files(3871)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000106054840.5523.qmail@securityfocus.com"> Re: SECURITY ALERT - WAR FTP DAEMON ALL VERSIONS</ref><ref source="BID" url="http://www.securityfocus.com/bid/919">919</ref></refs><vuln_soft><prod name="WarFTPd" vendor="Jgaa"><vers num="1.70b"/><vers num="1.67b2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-0045" published="2000-01-11" seq="2000-0045" severity="Medium" type="CVE"><desc><descript source="cve">MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/926">BID 926</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3848.php">mysql-pwd-grant(3848)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.GSO.4.10.10001111730040.11035-100000@palver.dtek.chalmers.se">Serious bug in MySQL password handling</ref><ref source="BID" url="http://www.securityfocus.com/bid/926">926</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.23.8"/><vers num="3.22.29"/><vers num="3.22.27"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0046" published="2000-01-10" seq="2000-0046" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D929">ICQ URL Remote Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-1.php-icq-url-bo">icq-url-bo</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-8%26msg%3D20000111183043.8950.qmail@web2001.mail.yahoo.com">ICQ Buffer Overflow Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/929">929</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="0.99b 1.1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0047" published="1999-10-01" seq="2000-0047" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-8.phpyahoo-messenger-dos">yahoo-messenger-dos</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-10-01%26thread%3D00cf01bf0c74%2460be7f20%24488a163f@default">Team Asylum: Yahoo! Messenger DoS</ref></refs><vuln_soft><prod name="Yahoo Pager" vendor="Yahoo"><vers num="733"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0048" published="2000-01-12" seq="2000-0048" severity="High" type="CVE"><desc><descript source="cve">get_it program in Corel Linux Update allows local users to gain root access by specifying an alternate PATH for the cp program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=928">Corel Linux get_it PATH Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-1.php-linux-corel-update">linux-corel-update</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-8%26msg%3DPine.LNX.4.10.10001120924350.5629-100000@enete.gui.uva.es">Serious Bug in Corel Linux.(Local root exploit)</ref><ref source="CONFIRM" url="http://linux.corel.com/support/clos_patch1.htm">http://linux.corel.com/support/clos_patch1.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/928">928</ref></refs><vuln_soft><prod name="Linux" vendor="Corel"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0049" published="2000-01-04" seq="2000-0049" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-1.php">winamp-playlist-bo</ref><ref adv="1" source="Bugtraq" url="http://www.shmoo.com/mail/bugtraq/may99/msg00085.html">Winamp buffer overflow</ref><ref adv="1" source="Bugtraq" url="http://www2.merton.ox.ac.uk/~security/bugtraq-200001/0121.html">Buffer overflow with WinAmp 2.10</ref><ref source="BID" url="http://www.securityfocus.com/bid/925">925</ref><ref source="OSVDB" url="http://www.osvdb.org/12022">12022</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="2.10"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0050" published="2000-01-04" seq="2000-0050" severity="Medium" type="CVE"><desc><descript source="cve">The Allaire Spectra Webtop allows authenticated users to access other Webtop sections by specifying explicit URLs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/915">BID 915</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3897.php">allaire-webtop-access(3897)</ref><ref adv="1" patch="1" source="Allaire Security Bulletin" url="http://www.allaire.com/handlers/index.cfm?ID=13976&amp;Method=Full">Allaire Security Bulletin (ASB00-01)</ref><ref source="BID" url="http://www.securityfocus.com/bid/915">915</ref></refs><vuln_soft><prod name="Spectra" vendor="Allaire"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0051" published="2000-01-04" seq="2000-0051" severity="Medium" type="CVE"><desc><descript source="cve">The Allaire Spectra Configuration Wizard allows remote attackers to cause a denial of service by repeatedly resubmitting data collections for indexing via a URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/916">BID 916</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3898.php">allaire-spectra-config-dos(3898)</ref><ref adv="1" patch="1" source="Allaire Security bulletin" url="http://www.allaire.com/handlers/index.cfm?ID=13977&amp;Method=Full">Addressing Potential Denial Of Service Problem With Installation Files In Allaire Spectra 1.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/916">916</ref></refs><vuln_soft><prod name="Spectra" vendor="Allaire"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0052" published="2000-01-04" seq="2000-0052" severity="High" type="CVE"><desc><descript source="cve">Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/913">BID 913</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3886.php">linux-pam-userhelper(3886)</ref><ref adv="1" patch="1" source="Red Hat Security Advisory" url="http://www.redhat.com/support/errata/RHSA2000001-03.html">RHSA-2000:001-03</ref><ref source="L0PHT" url="http://www.l0pht.com/advisories/pam_advisory">20000104 PamSlam</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-001.html">RHSA-2000:001</ref><ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=linux-pam-userhelper">linux-pam-userhelper</ref><ref source="BID" url="http://www.securityfocus.com/bid/913">913</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.1"/><vers edition="i386" num="6.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="6.1"/><vers num="6.0"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num="6.0.2"/><vers num="4.4"/><vers num="4.2"/><vers num="3.5b2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0053" published="2000-01-04" seq="2000-0053" severity="High" type="CVE"><desc><descript source="cve">Microsoft Commercial Internet System (MCIS) IMAP server allows remote attackers to cause a denial of service via a malformed IMAP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/912">BID 912</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-001.asp">MS00-001</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1895.php">imail-imap-overflow(1895)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q246731">Q246731</ref><ref source="BID" url="http://www.securityfocus.com/bid/912">912</ref></refs><vuln_soft><prod name="Commercial Internet System" vendor="Microsoft"><vers num="2.5"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0054" published="1999-01-03" seq="2000-0054" severity="Medium" type="CVE"><desc><descript source="cve">search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D921">SolutionScripts Home Free search.cgi Directory Traversal Vulnerability</ref><ref source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000104025223.21126.qmail@hotmail.com">Another search.cgi vulnerability</ref><ref patch="1" source="Solution Scripts" url="http://solutionscripts.com/vault/homefree/index.shtml">Home Page</ref><ref source="BID" url="http://www.securityfocus.com/bid/921">921</ref></refs><vuln_soft><prod name="Home Free" vendor="Solution Scripts"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0055" published="2000-01-06" seq="2000-0055" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3870.php">sol-chkperm-bo(3870)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D918">Solaris chkperm Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200001051936.EAA18559@ce.hannam.ac.kr">[Hackerslab bug_paper] Solaris chkperm buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/918">918</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86HW5" num="2.6"/><vers edition="x86HW3" num="2.6"/><vers edition="x86" num="2.6"/><vers edition="HW5" num="2.6"/><vers edition="HW3" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0056" published="2000-01-05" seq="2000-0056" severity="Medium" type="CVE"><desc><descript source="cve">IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D914">IMail IMonitor status.cgi DoS Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-7.phpimail-imonitor-overflow">imail-imonitor-overflow</ref><ref source="eEye Digital Security" url="http://www.eeye.com/database/advisories/ad03011999/ad03011999.html">Multiple IMail Vulnerabilites</ref><ref source="BID" url="http://www.securityfocus.com/bid/914">914</ref></refs><vuln_soft><prod name="Imail" vendor="Ipswitch"><vers num="6.1"/><vers num="6.0"/><vers num="5.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0057" published="2000-01-04" seq="2000-0057" severity="High" type="CVE"><desc><descript source="cve">Cold Fusion CFCACHE tag places temporary cache files within the web document root, allowing remote attackers to obtain sensitive system information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/917">BID 917</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3862.php">coldfusion-cfcache(3862)</ref><ref adv="1" patch="1" source="Allaire security bulletin" url="http://www.allaire.com/handlers/index.cfm?ID=13978&amp;Method=Full">Allaire Security Bulletin (ASB00-03)</ref><ref source="BID" url="http://www.securityfocus.com/bid/917">917</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.0.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0058" published="2000-01-05" seq="2000-0058" severity="Medium" type="CVE"><desc><descript source="cve">Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D920">Handspring Visor Network HotSync Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3873.php">handspring-visor-auth(3873)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D6C09D9B03136D31183980090276269659C1769@EXCHANGE1">Handspring Visor Network HotSync Security Hole</ref><ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/2000-01/0085.html">20000105 Handspring Visor Network HotSync Security Hole</ref><ref source="BID" url="http://www.securityfocus.com/bid/920">920</ref></refs><vuln_soft><prod name="Visor Network HotSync" vendor="Handspring"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0059" published="2000-01-04" seq="2000-0059" severity="High" type="CVE"><desc><descript source="cve">PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=911">PHP3 &apos;safe_mode&apos; Failure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3900.php">php3-popen-execute(3900)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000103224740.16223@white.koehntopp.de">PHP3 safe_mode and popen()</ref><ref source="BID" url="http://www.securityfocus.com/bid/911">911</ref></refs><vuln_soft><prod name="PHP_FI" vendor="PHP"><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0060" published="1999-12-27" seq="2000-0060" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D894">aVirt Rover POP3 Server Buffer Overflow DoS Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DNCBBKFKDOLAGKIAPMILPEEMNCBAA.labs@ussrback.com">Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref><ref adv="1" patch="1" source="USSR Advisory" url="http://www.securityfocus.com/frames/?content=/templates/advisory.html%3Fid%3D2003">Rover POP3 Server V1.1 NT From aVirt and possibly others versions.</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=94647711311057&amp;w=2">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94633851427858&amp;w=2">19991227 Local / Remote Remote DoS Attack in Rover POP3 Server V1.1 NT From aVirt</ref><ref source="BID" url="http://www.securityfocus.com/bid/894">894</ref><ref source="XF" url="http://www.iss.net/security_center/static/3765.php">avirt-rover-pop3-dos(3765)</ref></refs><vuln_soft><prod name="Rover" vendor="Avirt"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0061" published="2000-01-07" seq="2000-0061" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3668.php">ie-crossframe-file-read(3668)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D923">BID 923</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.securityfocus.com/frames/?content=/templates/advisory.html%3Fid%3D2089">MS00-009: Patch Available for &quot;Image Source Redirect&quot; Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/923">923</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5 preview"/><vers num="5.01"/><vers num="5.0"/><vers num="4.0.0.1"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0062" published="2000-01-04" seq="2000-0062" severity="High" type="CVE"><desc><descript source="cve">The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/922">BID 922</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3902.php">zope-dtml(3902)</ref><ref adv="1" patch="1" source="Zope.org" url="http://www.zope.org/Products/Zope/2.1.2/Zope_212_release">SECURITY ALERT</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000104222219.B41650@schvin.net">20000104 [petrilli@digicool.com: [Zope] SECURITY ALERT]</ref><ref source="BID" url="http://www.securityfocus.com/bid/922">922</ref></refs><vuln_soft><prod name="Zope" vendor="Zope"><vers num="2.1.1"/><vers num="1.10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2000-0063" published="2000-01-17" seq="2000-0063" severity="Medium" type="CVE"><desc><descript source="cve">cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to read arbitrary files by specifying the filename in a parameter to the script.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D938">Nortel Contivity Denial of Service and File Viewing Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4316.php">http-cgi-cgiproc-file-read(4316)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-04-15%26msg%3DPine.BSF.4.10.10001172335290.44367-100000@blacklisted.intranova.net">Nortel Contivity Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/938">938</ref></refs><vuln_soft><prod name="Contivity" vendor="Nortel Networks"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2000-0064" published="2000-01-17" seq="2000-0064" severity="Medium" type="CVE"><desc><descript source="cve">cgiproc CGI script in Nortel Contivity HTTP server allows remote attackers to cause a denial of service via a malformed URL that includes shell metacharacters.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=938">Nortel Contivity Denial of Service and File Viewing Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4317.php">http-cgi-cgiproc-dos(4317)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-04-15%26thread%3D20000118170408.E23093@jade.chc-chimes.com">Nortel Contivity Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/938">938</ref><ref source="OSVDB" url="http://www.osvdb.org/7583">7583</ref></refs><vuln_soft><prod name="Contivity" vendor="Nortel Networks"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0065" published="2000-01-17" seq="2000-0065" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4318.php">inetserv-get-bo(4318)</ref><ref patch="1" source="InetServe" url="http://www.escape.ca/~avtronic/inetserv/download.html">InetServ</ref><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0001&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=4592">Remote Buffer Exploit - InetServ 3.0</ref></refs><vuln_soft><prod name="InetServ" vendor="avtronics"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0066" published="2000-01-13" seq="2000-0066" severity="Medium" type="CVE"><desc><descript source="cve">WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3839.php">website-pro-dir-path(3839)</ref><ref source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D00f001bf5e58%24112c1d60%24beffcd98@u1u7p1">Re: WebSitePro/2.3.18 + 2.4.9 is revealing Webdirectories</ref></refs><vuln_soft><prod name="Website Professional" vendor="OReilly"><vers num="2.3.18"/><vers num="2.4.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0067" published="2000-01-11" seq="2000-0067" severity="Low" type="CVE"><desc><descript source="cve">CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3823.php">cybercash-mck-tmp(3823)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-8%26msg%3D20000112180038.15138.qmail@web112.yahoomail.com">CyberCash MCK 3.2.0.4: Large /tmp hole</ref></refs><vuln_soft><prod name="Merchant Connection Kit" vendor="CyberCash"><vers num="3.2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-09" name="CVE-2000-0068" published="1999-12-14" seq="2000-0068" severity="High" type="CVE"><desc><descript source="cve">daynad program in Intel InBusiness E-mail Station does not require authentication, which allows remote attackers to modify its configuration, delete files, or read mail.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3903.php">intel-email-unauthenticate-users</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-01-01&amp;msg=Pine.LNX.4.10.10001041514050.31424-100000@owned.connectnet.com">[rootshell] Security Bulletin #27</ref><ref patch="1" source="Intel" url="http://support.intel.com/support/inbusiness/emailstation/index.htm">InBusiness E-mail Station</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94704437920965&amp;w=2">20000104 [rootshell] Security Bulletin #27</ref></refs><vuln_soft><prod name="InBusiness eMail Station" vendor="Intel"><vers num="1.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0069" published="2000-01-01" seq="2000-0069" severity="Low" type="CVE"><desc><descript source="cve">The recover program in Solstice Backup allows local users to restore sensitive files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3904.php">solstice-backup-restore-files(3904)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-01-01&amp;msg=00Jan4.173712edt.62249@pinkwind.utcs.toronto.edu">Security problem with Solstice Backup/Legato Networker recover command</ref></refs><vuln_soft><prod name="Solstice Backup" vendor="Sun"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2000-0070" published="2000-01-12" seq="2000-0070" severity="High" type="CVE"><desc><descript source="cve">NtImpersonateClientOfPort local procedure call in Windows NT 4.0 allows local users to gain privileges, aka &quot;Spoofed LPC Port Request.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/934">BID 934</ref><ref adv="1" patch="1" source="BindView" url="http://www.bindview.com/security/advisory/adv_NtImpersonate.html">20000113 Local Promotion Vulnerability in Windows NT 4</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/fq00-003.asp">MS00-003</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3821.php">nt-spoofed-lpc-port(3821)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-003.asp">MS00-003</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q247869">Q247869</ref><ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=nt-spoofed-lpc-port">nt-spoofed-lpc-port</ref><ref source="BID" url="http://www.securityfocus.com/bid/934">934</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0071" published="2000-01-11" seq="2000-0071" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4346.php">iis-ida-idq-paths(4346)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-01-08&amp;msg=387A3627.269DB1D4@relaygroup.com">Security problem with Solstice Backup/Legato Networker recover command</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94770020309953&amp;w=2">20000111 IIS still revealing paths for web directories</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94780058006791&amp;w=2">20000113 SV: IIS still revealing paths for web directories</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0072" published="2000-01-17" seq="2000-0072" severity="Medium" type="CVE"><desc><descript source="cve">Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D937">VCasel Filename Trusting Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3867.php">vcasel-filename-trusting</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000118144510.3288.qmail@web3202.mail.yahoo.com">Warning: VCasel security hole</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94823061421676&amp;w=2">20000118 Warning: VCasel security hole.</ref><ref source="BID" url="http://www.securityfocus.com/bid/937">937</ref><ref source="XF" url="http://www.iss.net/security_center/static/3867.php">vcasel-filename-trusting(3867)</ref></refs><vuln_soft><prod name="Visual CASEL" vendor="Computer Power Solutions"><vers num="3.5"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0073" published="1999-11-17" seq="2000-0073" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/42384">Re: Microsoft Security Bulletin (MS00-005)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3868.php">win-malformed-rtf-control-word(3868)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-005.asp">MS00-005</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q249973">Q249973</ref><ref source="XF" url="http://xforce.iss.net/search.php3?type=2&amp;pattern=win-malformed-rtf-control-word">win-malformed-rtf-control-word</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0074" published="2000-01-11" seq="2000-0074" severity="High" type="CVE"><desc><descript source="cve">PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4396.php">plusmail-password-permissions</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-8%26msg%3D20000111214313.24266.qmail@securityfocus.com">PowerScripts PlusMail Vulnerablity</ref><ref adv="1" patch="1" source="SecuriTeam" url="http://www.securiteam.com/exploits/PowerScripts_PlusMail_password_vulnerability__password_change_.html">PowerScripts PlusMail password vulnerability (password change)</ref></refs><vuln_soft><prod name="PlusMail" vendor="PowerScripts"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-0075" published="2000-01-13" seq="2000-0075" severity="Medium" type="CVE"><desc><descript source="cve">Super Mail Transfer Package (SMTP), later called MsgCore, has a memory leak which allows remote attackers to cause a denial of service by repeating multiple HELO, MAIL FROM, RCPT TO, and DATA commands in the same session.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3822.php">supermail-memleak-dos</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-8%26msg%3DNCBBKFKDOLAGKIAPMILPEEDBCCAA.labs@ussrback.com">Local / Remote D.o.S Attack in Super Mail Transfer Package (SMTP) Server for WinNT Version 1.9x</ref><ref adv="1" source="USSR" url="http://www.ussrback.com/labs31.html">USSR-2000031</ref><ref source="BID" url="http://www.securityfocus.com/bid/930">930</ref></refs><vuln_soft><prod name="MsgCore" vendor="Nosque"><vers num="1.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2000-0076" published="1999-12-30" seq="2000-0076" severity="Low" type="CVE"><desc><descript source="cve">nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D1439">Multiple Vendor nvi Root Directory File Removal Vulnerability</ref><ref adv="1" source="Debian" url="http://www.debian.org/security/2000/20000108">nvi: incorrect file removal in boot script</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4321.php">nvi-delete-files</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94709988232618&amp;w=2">19991230 vibackup.sh</ref><ref source="BID" url="http://www.securityfocus.com/bid/1439">1439</ref></refs><vuln_soft><prod name="nvi" vendor="Berkeley"><vers num="1.7x"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0077" published="2000-01-02" seq="2000-0077" severity="High" type="CVE"><desc><descript source="cve">The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3881.php">hp-aserver</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-29%26msg%3DPine.HPX.4.10.10001021257160.3248-100000@zap.ee.byu.edu">HPUX Aserver revisited.</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-014.shtml">K-014K-014: HP-UX Aserver Vulnerability</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.x"/><vers num="11.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0078" published="2000-01-02" seq="2000-0078" severity="High" type="CVE"><desc><descript source="cve">The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3881.php">hp-aserver</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-29%26msg%3DPine.HPX.4.10.10001021257160.3248-100000@zap.ee.byu.edu">HPUX Aserver revisited.</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-014.shtml">K-014</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.x"/><vers num="11.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2000-0079" published="2000-01-18" seq="2000-0079" severity="High" type="CVE"><desc><descript source="cve">The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4384.php">w3c-httpd-reveal-paths</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=936">W3C httpd (Formerly &apos;CERN httpd&apos;) Path Revealing Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-22&amp;msg=38846E63.8E800666@nightlabs.de">Re: IIS still revealing paths for web directories</ref><ref source="BID" url="http://www.securityfocus.com/bid/936">936</ref></refs><vuln_soft><prod name="CERN httpd" vendor="W3C"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0080" published="2000-01-10" seq="2000-0080" severity="Low" type="CVE"><desc><descript source="cve">AIX techlibss allows local users to overwrite files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3850.php">aix-techlibss-symbolic-link</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D931">AIX techlibss Symbolic Link Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=B7DF252F2093D111982F40003881990401F0A8EB@ntli01-004.ooe.gv.at">2nd attempt: AIX techlibss follows links</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94757136413681&amp;w=2">20000110 2nd attempt: AIX techlibss follows links</ref><ref source="BID" url="http://www.securityfocus.com/bid/931">931</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2000-0081" published="2000-01-10" seq="2000-0081" severity="High" type="CVE"><desc><descript source="cve">Hotmail does not properly filter JavaScript code from a user&apos;s mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. j&amp;#x41;vascript.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Hotmail" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0082" published="2000-01-02" seq="2000-0082" severity="Medium" type="CVE"><desc><descript source="cve">WebTV email client allows remote attackers to force the client to send email without the user&apos;s knowledge via HTML.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Net4TV Voice" url="http://net4tv.com/voice/story.cfm?StoryID=1823"></ref><ref adv="1" source="Wired" url="http://www.wired.com/news/technology/0,1282,33420,00.html"></ref></refs><vuln_soft><prod name="WebTV" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0083" published="2000-04-18" seq="2000-0083" severity="Medium" type="CVE"><desc><descript source="cve">HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/40860">Security Bulletins Digest</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/advisories/2031">HP Security Advisory</ref><ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=2031">HPSBUX0001-109</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.X"/><vers num="11.X"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0084" published="2000-01-06" seq="2000-0084" severity="Medium" type="CVE"><desc><descript source="cve">CuteFTP uses weak encryption to store password information in its tree.dat file.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3910.php">cuteftp-weak-encrypt</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-01-1&amp;msg=200001050839.VAA05944@fep4-orange.clear.net.nz">CuteFTP saved password &apos;encryption&apos; weakness</ref></refs><vuln_soft><prod name="CuteFTP" vendor="GlobalSCAPE"><vers num="2.x" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0085" published="2000-01-04" seq="2000-0085" severity="High" type="CVE"><desc><descript source="cve">Hotmail does not properly filter JavaScript code from a user&apos;s mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3911.php">hotmail-java-execute</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-01%26msg%3D3872022D.88D2BB0E%40nat.bg">Yet another Hotmail security hole - injecting JavaScript in IE</ref></refs><vuln_soft><prod name="Hotmail" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0086" published="2000-01-18" seq="2000-0086" severity="Medium" type="CVE"><desc><descript source="cve">Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4322.php">timbuktu-password-cleartext</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D935">Netopia Timbuktu Cleartext Username/Password Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D019501bf6067%2401a1eb70%240400a8c0@davepiii.cyber-pete.com">TB2 Pro sending NT passwords cleartext</ref><ref source="BID" url="http://www.securityfocus.com/bid/935">935</ref></refs><vuln_soft><prod name="Timbuktu Pro" vendor="Netopia"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0087" published="2000-01-12" seq="2000-0087" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4385.php">netscape-mail-notify-plaintext</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-15%26msg%3D387E245C.F279E367%40digsigtrust.com">Misleading sense of security in Netscape</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94790377622943&amp;w=2">20000113 Misleading sense of security in Netscape</ref><ref source="XF" url="http://www.iss.net/security_center/static/4385.php">netscape-mail-notify-plaintext(4385)</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.7"/></prod><prod name="Navigator" vendor="Netscape"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0088" published="2000-01-20" seq="2000-0088" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the &quot;Malformed Conversion Data&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-002.asp">MS00-002</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3876.php">office-malformed-convert(946)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/946">BID 946</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-002.mspx">MS00-002</ref><ref source="BID" url="http://www.securityfocus.com/bid/946">946</ref></refs><vuln_soft><prod name="PowerPoint" vendor="Microsoft"><vers edition="Korean" num="97"/><vers edition="Japanese" num="97"/><vers edition="Chinese" num="97"/><vers edition="Korean" num="2000"/><vers edition="Japanese" num="2000"/><vers edition="Chinese" num="2000"/></prod><prod name="Office" vendor="Microsoft"><vers edition="Korean" num="97"/><vers edition="Japanese" num="97"/><vers edition="Chinese" num="97"/><vers edition="Korean" num="2000"/><vers edition="Japanese" num="2000"/><vers edition="Chinese" num="2000"/></prod><prod name="Word" vendor="Microsoft"><vers edition="Korean" num="98"/><vers edition="Japanese" num="98"/><vers edition="Chinese" num="98"/><vers edition="Korean" num="97"/><vers edition="Japanese" num="97"/><vers edition="Chinese" num="97"/><vers edition="Korean" num="2000"/><vers edition="Japanese" num="2000"/><vers edition="Chinese" num="2000"/></prod><prod name="Converter Pack" vendor="Microsoft"><vers num="2000.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2000-0089" published="2000-02-04" seq="2000-0089" severity="Low" type="CVE"><desc><descript source="cve">The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the &quot;RDISK Registry Enumeration File&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://xforce.iss.net/static/3877.php">MS00-004</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq00-004.asp">MS00-004</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/947">BID 947</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-004.mspx">MS00-004</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q249108">Q249108</ref><ref source="BID" url="http://www.securityfocus.com/bid/947">947</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="Server 4.0"/><vers num="Enterprise 4.0"/><vers num="Terminal Server 4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0090" published="2000-01-17" seq="2000-0090" severity="Low" type="CVE"><desc><descript source="cve">VMWare 1.1.2 allows local users to cause a denial of service via a symlink attack.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3878.php">linux-vmware-symlink</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D943">VMware Symlink Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-01-22&amp;msg=Pine.BSO.4.10.10001240842210.19617-100000@shaolin.fcbl.net">VMware 1.1.2 Symlink Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/943">943</ref><ref source="OSVDB" url="http://www.osvdb.org/1205">1205</ref></refs><vuln_soft><prod name="VMWare" vendor="VMWare"><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.2"/><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0091" published="2000-01-21" seq="2000-0091" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/942">BID 942</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4572.php">inter7-vpopmail-bo(4572)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-05-22%26msg%3D388A45A2.B3798973@ktwo.ca">remote root qmail-pop with vpopmail advisory and exploit with patch</ref><ref source="MISC" url="http://www.inter7.com/vpopmail/ChangeLog">http://www.inter7.com/vpopmail/ChangeLog</ref><ref source="MISC" url="http://www.inter7.com/vpopmail/">http://www.inter7.com/vpopmail/</ref><ref source="BID" url="http://www.securityfocus.com/bid/942">942</ref></refs><vuln_soft><prod name="vpopmail" vendor="Inter7"><vers num="vchkpw 3.4.9"/><vers num="vchkpw 3.4.8"/><vers num="vchkpw 3.4.7"/><vers num="vchkpw 3.4.6"/><vers num="vchkpw 3.4.5"/><vers num="vchkpw 3.4.4"/><vers num="vchkpw 3.4.3"/><vers num="vchkpw 3.4.2"/><vers num="vchkpw 3.4.11"/><vers num="vchkpw 3.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0092" published="2000-01-19" seq="2000-0092" severity="Medium" type="CVE"><desc><descript source="cve">The BSD make program allows local users to modify files via a symlink attack when the -j option is being used.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/939">BID 939</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3985.php">gnu-makefile-tmp-root(3985)</ref><ref adv="1" patch="1" source="FreeBSD Advisory" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:01.make.asc">Insecure temporary file handling in make(1)</ref><ref source="BID" url="http://www.securityfocus.com/bid/939">939</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.6"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.1_x86"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0093" published="2000-01-21" seq="2000-0093" severity="High" type="CVE"><desc><descript source="cve">An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4578.php">linux-initial-password-encryption(4578)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-15%26msg%3D20000122011507.A30744@asit.ro">NIS security advisory : password method downgrade</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-15%26msg%3D3887A0F9.7A53C698@optusnet.com.au">Rh 6.1 initial root password encryption</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0094" published="2000-02-16" seq="2000-0094" severity="High" type="CVE"><desc><descript source="cve">procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-2.php-netbsd-procfs">netbsd-procfs</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-15%26msg%3D14505.23693.773699.404104@passion.geek.com.au">NetBSD Security Advisory 2000-001</ref><ref patch="1" source="NetBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/patches/20000130-procfs">procfs Patch</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-001.txt.asc">NetBSD-SA2000-001</ref><ref source="BID" url="http://www.securityfocus.com/bid/940">940</ref><ref source="OSVDB" url="http://www.osvdb.org/20760">20760</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3995">netbsd-procfs(3995)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0095" published="2000-01-24" seq="2000-0095" severity="Medium" type="CVE"><desc><descript source="cve">The PMTU discovery procedure used by HP-UX 10.30 and 11.00 for determining the optimum MTU generates large amounts of traffic in response to small packets, allowing remote attackers to cause the system to be used as a packet amplifier.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/944">BID 944</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/advisory.html?id=2041">HPSBUX0001-110</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4581.php">hp-packet-amplifier-dos(4581)</ref><ref source="HP" url="http://www.securityfocus.com/templates/advisory.html?id=2041">HPSBUX0001-110</ref><ref source="BID" url="http://www.securityfocus.com/bid/944">944</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.30"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0096" published="2000-01-26" seq="2000-0096" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D948">Qualcomm qpopper &apos;LIST&apos; Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4573.php">qpopper-list-bo(4573)</ref><ref patch="1" source="Qualcom" url="ftp://ftp.qualcomm.com/eudora/servers/unix/popper/">Qpopper download</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.10001261454390.7596-100000@piscis.zhodiac.net">Qpopper security bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/948">948</ref></refs><vuln_soft><prod name="qpopper" vendor="Qualcomm"><vers num="3.0beta9"/><vers num="3.0beta8"/><vers num="3.0beta7"/><vers num="3.0beta6"/><vers num="3.0beta5"/><vers num="3.0beta4"/><vers num="3.0beta3"/><vers num="3.0beta29"/><vers num="3.0beta28"/><vers num="3.0beta27"/><vers num="3.0beta26"/><vers num="3.0beta25"/><vers num="3.0beta24"/><vers num="3.0beta23"/><vers num="3.0beta22"/><vers num="3.0beta21"/><vers num="3.0beta20"/><vers num="3.0beta2"/><vers num="3.0beta19"/><vers num="3.0beta18"/><vers num="3.0beta17"/><vers num="3.0beta16"/><vers num="3.0beta15"/><vers num="3.0beta14"/><vers num="3.0beta13"/><vers num="3.0beta12"/><vers num="3.0beta11"/><vers num="3.0beta10"/><vers num="3.0beta1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0097" published="2000-01-26" seq="2000-0097" severity="Medium" type="CVE"><desc><descript source="cve">The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the &quot;Malformed Hit-Highlighting Argument&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-006.asp">MS00-006</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4227.php">http-indexserver-asp-source(4227)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/950">BID 950</ref><ref source="BID" url="http://www.securityfocus.com/bid/950">950</ref><ref source="OSVDB" url="http://www.osvdb.org/1210">1210</ref></refs><vuln_soft><prod name="Index Server" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0098" published="2000-01-26" seq="2000-0098" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Index Server allows remote attackers to determine the real path for a web directory via a request to an Internet Data Query file that does not exist.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4232.php">http-indexserver-view-files(4232)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq00-006.asp">MS00-006</ref><ref adv="1" patch="1" source="Cerberus Security Advisory" url="http://www.cerberus-infosec.co.uk/adviisidq.html">Cerberus Information Security Advisory (CISADV000202)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp">MS00-006</ref></refs><vuln_soft><prod name="Index Server" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-21" name="CVE-2000-0099" published="2000-01-18" seq="2000-0099" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in UnixWare ppptalk command allows local users to gain privileges via a long prompt argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=2000-01-15&amp;msg=Pine.LNX.4.05.10001191552540.30714-200000@varmint-ent.com">Unixware ppptalk</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4594.php">sco-ppptalk-bo(4594)</ref><ref adv="1" source="CA" url="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=2324">Unixware ppptalk overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94848865112897&amp;w=2">20000119 Unixware ppptalk</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.0.0"/><vers num="7.0.1"/><vers num="7.1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0100" published="1999-12-29" seq="2000-0100" severity="High" type="CVE"><desc><descript source="cve">The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/945">BID 945</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-012.asp">MS00-012</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4196.php">sms-remote-control-permissions(4196)</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/current/0045.html">20000115 Security Vulnerability with SMS 2.0 Remote Control</ref></refs><vuln_soft><prod name="Systems Management Server" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0101" published="2000-02-01" seq="2000-0101" severity="High" type="CVE"><desc><descript source="cve">The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-12-8%26thread%3DPine.LNX.3.96.990420132956.13470B-100000@gonzo.blarg.net">Shopping Carts exposing CC data</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="OrderPage" vendor="Make-a-Store"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0102" published="2000-02-01" seq="2000-0102" severity="High" type="CVE"><desc><descript source="cve">The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="SalesCart" vendor="SalesCart"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0103" published="2000-02-01" seq="2000-0103" severity="High" type="CVE"><desc><descript source="cve">The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="SmartCart" vendor="NetSmart"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0104" published="2000-02-01" seq="2000-0104" severity="High" type="CVE"><desc><descript source="cve">The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="ShopTron" vendor="Web Express"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0105" published="2000-02-01" seq="2000-0105" severity="Medium" type="CVE"><desc><descript source="cve">Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user&apos;s email messages via a script that accesses a variable that references subsequent email messages that are read by the client.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=962">MS Outlook Express 5 Javascript Email Access Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4018.php">email-active-script-html(4018)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D3896E440.553BD289@nat.bg">Outlook Express 5 vulnerability - Active Scripting may read email messages</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-045.asp">Microsoft Security Bulletin (MS00-045)</ref><ref source="BID" url="http://www.securityfocus.com/bid/962">962</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0106" published="2000-02-01" seq="2000-0106" severity="High" type="CVE"><desc><descript source="cve">The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="EasyCart" vendor="EasyCart"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0107" published="2000-02-01" seq="2000-0107" severity="High" type="CVE"><desc><descript source="cve">Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/958">BID 958</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/Lists-Archives/debian-security-announce-00/msg00002.html">20000201</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4017.php">debian-apcd-symlink-root(4017)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20000201">20000201</ref><ref source="BID" url="http://www.securityfocus.com/bid/958">958</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0108" published="2000-02-01" seq="2000-0108" severity="High" type="CVE"><desc><descript source="cve">The Intellivend shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="Intellivend" vendor="Intelligent Vending Systems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0109" published="2000-01-31" seq="2000-0109" severity="High" type="CVE"><desc><descript source="cve">The mcsp Client Site Processor system (MultiCSP) in Standard and Poor&apos;s ComStock is installed with several accounts that have no passwords or easily guessable default passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4639.php">comstock-multicsp-passwords(4639)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-29%26msg%3D20000201152730.0C2BF1EEB4@lists.securityfocus.com">Security issues with S&amp;P ComStock multiCSP (Linux)</ref></refs><vuln_soft><prod name="MultiCSP" vendor="ComStock"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0110" published="2000-02-01" seq="2000-0110" severity="High" type="CVE"><desc><descript source="cve">The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="WebSiteTool" vendor="Baron Consulting Group"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0111" published="2000-01-29" seq="2000-0111" severity="High" type="CVE"><desc><descript source="cve">The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=953">BID 953</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.SUN.3.96.1000129193017.11412A-100000@grex.cyberspace.org">BUGTRAQ:20000129 [LoWNOISE] Rightfax web client 5.2</ref><ref source="BID" url="http://www.securityfocus.com/bid/953">953</ref></refs><vuln_soft><prod name="Rightfax" vendor="AVT"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-2000-0112" published="2000-02-02" seq="2000-0112" severity="High" type="CVE"><desc><descript source="cve">The default installation of Debian GNU/Linux uses an insecure Master Boot Record (MBR) which allows a local user to boot from a floppy disk during the installation.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/960">BID 960</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4013.php">debian-mbr-bypass-security(4013)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000203145216.W50448@enst.fr">Re: vulnerability in Linux Debian default boot configuration</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94973075614088&amp;w=2">20000202 vulnerability in Linux Debian default boot configuration</ref><ref source="BID" url="http://www.securityfocus.com/bid/960">960</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2 pre potato"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0r5"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0113" published="2000-01-27" seq="2000-0113" severity="High" type="CVE"><desc><descript source="cve">The SyGate Remote Management program does not properly restrict access to its administration service, which allows remote attackers to cause a denial of service, or access network traffic statistics.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/952">BID 952</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3963.php">sygate-remote-admin(3963)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DNDBBKKFPELKEPAPKJFAPAEIDCAAA.rhillery@tec.nh.us">Undocumented back door</ref><ref source="CONFIRM" url="http://www.sybergen.com/support/fix.htm">http://www.sybergen.com/support/fix.htm</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94934808714972&amp;w=2">20000128 SyGate 3.11 Port 7323 / Remote Admin hole</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94952641025328&amp;w=2">20000202 SV: SyGate 3.11 Port 7323 / Remote Admin hole</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94973281714994&amp;w=2">20000203 UPDATE: Sygate 3.11 Port 7323 Telnet Hole</ref><ref source="BID" url="http://www.securityfocus.com/bid/952">952</ref></refs><vuln_soft><prod name="SyGate" vendor="Sybergen"><vers num="3.11"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2008-01-24" name="CVE-2000-0114" published="2000-02-02" seq="2000-0114" severity="Medium" type="CVE"><desc><descript source="cve">Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-2.php-iis-frontpage-info">iis-frontpage-info</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-29%26msg%3D038201bf6dd8%24249e2250%245802020a@cerberusinfosec.co.uk">Alert: IIS 4 / IS 2 IDQ Cerberus Information Security Advisory (CISADV000202)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp">Microsoft Security Bulletin (MS00-006)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0115" published="2000-01-21" seq="2000-0115" severity="Medium" type="CVE"><desc><descript source="cve">IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="NT Bugtraq" url="http://ntbugtraq.ntadvice.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0001&amp;L=NTBUGTRAQ&amp;P=R3598">Strange behaviour IIS and RegExp</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2000-0116" published="2000-01-29" seq="2000-0116" severity="High" type="CVE"><desc><descript source="cve">Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the &quot;Strip Script Tags&quot; restriction by including an extra &lt; in front of the SCRIPT tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3905.php">http-script-bypass(3905)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-29%26msg%3DJKEHIOKGPMHGBMCCADAIMEMHCAAA.arne.vidstrom@ntsecurity.nu">&quot;Strip Script Tags&quot; in FW-1 can be circumvented</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-28%26msg%3D50325BA28B01D211A57F00805FB7FC250272F8D6@mail">Re: &quot;Strip Script Tags&quot; in FW-1 can be circumvented</ref><ref source="BID" url="http://www.securityfocus.com/bid/954">954</ref><ref source="OSVDB" url="http://www.osvdb.org/1212">1212</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2000-0117" published="2000-01-30" seq="2000-0117" severity="High" type="CVE"><desc><descript source="cve">The siteUserMod.cgi program in Cobalt RaQ2 servers allows any Site Administrator to modify passwords for other users, site administrators, and possibly admin (root).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4595.php">http-cgi-cobalt-passwords(4595)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-29%26msg%3D3895C9A8.5EFF43B0@cobaltnet.com">[ Cobalt ] Security Advisory -- 01.31.2000</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-22%26msg%3DPine.BSF.4.10.10001271725040.97978-100000@cerebus.oanet.com">Cobalt RaQ2 - a user of mine changed my admin password</ref><ref source="BID" url="http://www.securityfocus.com/bid/951">951</ref></refs><vuln_soft><prod name="Cobalt RaQ" vendor="Sun"><vers num="2.0"/><vers num="3.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2000-0118" published="1999-06-09" seq="2000-0118" severity="High" type="CVE"><desc><descript source="cve">The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2278.php">su-brute(2278)</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9906b&amp;L=bugtraq&amp;F=&amp;S=&amp;P=6051">Solaris 2.5 /bin/su [was: vulnerability in su/PAM in redhat]</ref><ref adv="1" source="Bugtraq" url="http://www.netspace.org/cgi-bin/wa?A2=ind9906b&amp;L=bugtraq&amp;F=&amp;S=&amp;P=5356">vulnerability in su/PAM in redhat</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94935300520617&amp;w=2">20000130 RedHat 6.1 /and others/ PAM</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Alpha" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Sparc" num="6.1"/><vers edition="Sparc" num="6.0"/><vers edition="Alpha" num="6.0"/><vers edition="i386" num="6.0"/><vers edition="Sparc" num="5.2"/><vers edition="Alpha" num="5.2"/><vers edition="i386" num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/><vers num="3.0.3"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers edition="JL" num="1.1.4"/><vers num="1.1.4"/><vers edition="U1" num="1.1.3"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1a"/><vers num="1.1"/><vers edition="x86" num="Any"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0119" published="1999-12-22" seq="2000-0119" severity="High" type="CVE"><desc><descript source="cve">The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3810.php">win-trojan-detection-bypass(3810)</ref><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9912&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=6030">Bypass Virus Checking under 95/98/NT</ref><ref adv="1" source="Bugtraq" url="http://www2.merton.ox.ac.uk/~security/bugtraq-200002/0003.html">Re: Bypass Virus Checking</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94936267131123&amp;w=2">20000130 Bypass Virus Checking</ref></refs><vuln_soft><prod name="VirusScan" vendor="McAfee"><vers num=""/></prod><prod name="Norton AntiVirus" vendor="Symantec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0120" published="2000-01-01" seq="2000-0120" severity="High" type="CVE"><desc><descript source="cve">The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=955">Allaire Spectra 1.0 invoke.cfm Unauthenticated RAS Access Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4025.php">allaire-spectra-ras-access(4025)</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=14300&amp;Method=Full">Patch Available for Allaire Spectra 1.0 Security Authentication System</ref><ref source="BID" url="http://www.securityfocus.com/bid/955">955</ref></refs><vuln_soft><prod name="Spectra" vendor="Allaire"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2000-0121" published="2000-02-01" seq="2000-0121" severity="Low" type="CVE"><desc><descript source="cve">The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim&apos;s SID in the recycler directory, aka the &quot;Recycle Bin Creation&quot; vulnerability.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-007.asp">MS00-007</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/963">BID 963</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4016.php">nt-recycle-bin-access(4016)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-007.mspx">MS00-007</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q248399">Q248399</ref><ref source="BID" url="http://www.securityfocus.com/bid/963">963</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0122" published="2000-02-03" seq="2000-0122" severity="Medium" type="CVE"><desc><descript source="cve">Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4008.php">ms-frontpage-get-htimage(4008)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D039d01bf6ddd%248f529fe0%245802020a@cerberusinfosec.co.uk">2 MS Frontpage issues Cerberus Information Security Advisory (CISADV000203)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D964">MS Frontpage htimage.exe Path Leak Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/964">964</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470458/100/0/threaded">20070603 CERN &amp;#304;mage Map Dispatcher</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34719">frontpage-cern-information-disclosure(34719)</ref></refs><vuln_soft><prod name="FrontPage" vendor="Microsoft"><vers num="98"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0123" published="2000-02-01" seq="2000-0123" severity="High" type="CVE"><desc><descript source="cve">The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="FileMaker Pro" vendor="FileMaker"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0124" published="2000-02-03" seq="2000-0124" severity="Low" type="CVE"><desc><descript source="cve">surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=965">surfCONTROL SuperScout Content Filtering Bypass Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4009.php">surfcontrol-superscout-bypass-filter(4009)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000203052832.10544.qmail@securityfocus.com">surfCONTROL SuperScout v2.6.1.6 flaw</ref><ref source="BID" url="http://www.securityfocus.com/bid/965">965</ref></refs><vuln_soft><prod name="SuperScout" vendor="SurfControl"><vers num="2.6.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-07" name="CVE-2000-0125" published="2000-02-03" seq="2000-0125" severity="High" type="CVE"><desc><descript source="cve">wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4011.php">wwwthreads-sql-command-privs(4011)</ref><ref patch="1" source="WWWThreads" url="http://www.wwwthreads.com/perl/showflat.pl?Cat=&amp;Board=info&amp;Number=9932&amp;page=1&amp;view=collapsed&amp;sb=5">Urgent update</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.10002031027120.15921-100000@eight.wiretrip.net">RFP2K01 - </ref><ref source="BID" url="http://www.securityfocus.com/bid/967">967</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10002031027120.15921-100000@eight.wiretrip.net">20000203 RFP2K01 - </ref></refs><vuln_soft><prod name="WWWThreads" vendor="Wired Community Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0126" published="2000-01-26" seq="2000-0126" severity="Medium" type="CVE"><desc><descript source="cve">Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94972759912790&amp;w=2">Alert: IIS 4 / IS 2 IDQ Cerberus Information Security Advisory</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4014.php">iis-dir-traversal-read(4014)</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://packetderm.cotse.com/mailing-lists/ntbugtraq/2000/Jan/0067.html">Webhits.dll buffer truncation</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-2000-0127" published="2000-02-03" seq="2000-0127" severity="High" type="CVE"><desc><descript source="cve">The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=969">Progress WebSpeed Administration Utility Configuration Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4012.php">webspeed-adminutil-auth(4012)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D003a01bf6ebf%2425e867a0%240a1a90d8@eniac">Webspeed security issue</ref><ref source="" url="http://www.progress.com/services/support/cgi-bin/techweb-kbase.cgi/webkb.html?kbid=19412&amp;keywords=security%20Webspeed"></ref><ref source="BID" url="http://www.securityfocus.com/bid/969">969</ref></refs><vuln_soft><prod name="WebSpeed" vendor="Progress Software Corp"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0128" published="2000-02-04" seq="2000-0128" severity="High" type="CVE"><desc><descript source="cve">The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4006.php">finger-server-input(4006)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D389AB9D7.4E043518@optusnet.com.au">&quot;The Finger Server&quot;</ref><ref patch="1" source="Finger Server" url="http://www.glazed.org/finger/">Home page</ref><ref source="CONFIRM" url="http://www.glazed.org/finger/changelog.txt">http://www.glazed.org/finger/changelog.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/7610">7610</ref></refs><vuln_soft><prod name="The Finger Server" vendor="Daniel Beckham"><vers num="0.80 Beta"/><vers num="0.81 Beta"/><vers num="0.82 Beta"/><vers num="0.83 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0129" published="2000-02-04" seq="2000-0129" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4049.php">win-shortcut-api-bo(4049)</ref><ref adv="1" source="USSR Labs" url="http://www.ussrback.com/labs32.html">Local / Remote D.o.S Attack in Serv-U FTP-Server v2.5b for Win9x/WinNT Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DNCBBKFKDOLAGKIAPMILPAEGNCCAA.labs@ussrback.com">Windows Api SHGetPathFromIDList Buffer Overflow</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0130" published="2000-01-27" seq="2000-0130" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SCO scohelp program allows remote attackers to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4272.php">sco-help-bo(4272)</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94908470928258&amp;w=2">New SCO patches</ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.02a">SB-00.02a</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.0"/><vers num="7.0.1"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0131" published="2000-02-01" seq="2000-0131" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/966">BID 966</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=38969236225.C3BFCRC@mail.sft.sega.co.jp">war-ftpd 1.6x DoS</ref><ref adv="1" patch="1" source="Jgaa" url="http://war.jgaa.com/alert/">Buffer overflow problem in 1.6*</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=94960703721503&amp;w=2">20000201 war-ftpd 1.6x DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/966">966</ref><ref source="OSVDB" url="http://www.osvdb.org/4677">4677</ref></refs><vuln_soft><prod name="WarFTPd" vendor="Jgaa"><vers num="1.67.3"/><vers num="1.66x4s"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-11-09" name="CVE-2000-0132" published="2000-01-31" seq="2000-0132" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4577.php">virtual-machine-file-read(4577)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D957">Microsoft Java Virtual Machine getSystemResource Vulnerability</ref><ref adv="1" source="JavaHouse-Brewer" url="http://java-house.etl.go.jp/ml/archive/j-h-b/030411.html">[JavaHouse-Brewers:30411] Re: Warning: Yet Another Security Hole of `Microsoft VM for Java&apos;</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-011.asp">Patch Available for </ref><ref source="BID" url="http://www.securityfocus.com/bid/957">957</ref></refs><vuln_soft><prod name="Virtual Machine" vendor="Microsoft"><vers num="3000"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0133" published="2000-02-01" seq="2000-0133" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D961">Tiny FTPd Multiple Buffer Overflow Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4000.php">tinyftp-command-overflow(4000)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-01-29%26msg%3D200002012024.CCF54899.XJONB-@lac.co.jp">Tiny FTPd 0.52 beta3 Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/961">961</ref></refs><vuln_soft><prod name="Tiny FTPDaemon" vendor="H. Nomura"><vers num="0.52" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0134" published="2000-02-01" seq="2000-0134" severity="High" type="CVE"><desc><descript source="cve">The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="Check It Out" vendor="Adgrafix Corporation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0135" published="2000-02-01" seq="2000-0135" severity="High" type="CVE"><desc><descript source="cve">The @Retail shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="AtRetail" vendor="AtRetail"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0136" published="2000-02-01" seq="2000-0136" severity="High" type="CVE"><desc><descript source="cve">The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="Cart32" vendor="McMurtrey Whitaker and Associates"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0137" published="2000-02-01" seq="2000-0137" severity="High" type="CVE"><desc><descript source="cve">The CartIt shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">ISS E-Security Alert</ref></refs><vuln_soft><prod name="CartIt" vendor="CartIt"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0138" published="2000-05-02" seq="2000-0138" severity="Medium" type="CVE"><desc><descript source="cve">A system has a distributed denial of service (DDOS) attack master, agent, or zombie installed, such as (1) Trinoo, (2) Tribe Flood Network (TFN), (3) Tribe Flood Network 2000 (TFN2K), (4) stacheldraht, (5) mstream, or (6) shaft.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise48.php"> ISS:20000502 &quot;mstream&quot; Distributed Denial of Service Tool</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-01.html">CERT:CA-2000-01</ref><ref source="ISS" url="http://xforce.iss.net/alerts/advise48.php3">20000502 &quot;mstream&quot; Distributed Denial of Service Tool</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95715370208598&amp;w=2">20000429 Re: Source code to mstream, a DDoS tool</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95722093124322&amp;w=2">20000429 Re: Source code to mstream, a DDoS tool</ref></refs></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0139" published="1999-12-03" seq="2000-0139" severity="Low" type="CVE"><desc><descript source="cve">Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/982">BID 982</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-8&amp;msg=200002101853.JBJ65698.-XBNJO@lac.co.jp">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3988.php">anywhere-mailserver-retr-dos(3988)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95021326417936&amp;w=2">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref><ref source="BID" url="http://www.securityfocus.com/bid/982">982</ref></refs><vuln_soft><prod name="Internet Anywhere Mail Server" vendor="True North"><vers num="3.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0140" published="2000-02-10" seq="2000-0140" severity="Medium" type="CVE"><desc><descript source="cve">Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service via a large number of connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/980">BID 980</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3989.php">anywhere-mailserver-connect-dos(3989)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200002101853.JBJ65698.-XBNJO@lac.co.jp">remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95021326417936&amp;w=2">20000210 remote DoS on Internet Anywhere Mail Server Ver.3.1.3</ref><ref source="BID" url="http://www.securityfocus.com/bid/980">980</ref></refs><vuln_soft><prod name="Internet Anywhere Mail Server" vendor="True North"><vers num="3.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0141" published="2000-02-11" seq="2000-0141" severity="High" type="CVE"><desc><descript source="cve">Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-8%26msg%3D20000211224935.A13236@infomag.ape.relarn.ru">perl-cgi hole in UltimateBB by Infopop Corp.</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3964.php">http-cgi-ultimatebb(3964)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-15%26msg%3D032201bf7805%24dd293c60%240200a8c0@garlic.com">Re: perl-cgi hole in UltimateBB by Infopop Corp.</ref><ref source="MISC" url="http://www.ultimatebb.com/home/versions.shtml">http://www.ultimatebb.com/home/versions.shtml</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-8&amp;msg=20000211224935.A13236@infomag.ape.relarn.ru">20000211 perl-cgi hole in UltimateBB by Infopop Corp.</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=NDBBLKOPOLNKELHPDEFKIEPGCAAA.renzo.toma@veronica.nl">20000225 FW: Important UBB News For Licensed Users</ref><ref source="BID" url="http://www.securityfocus.com/bid/991">991</ref></refs><vuln_soft><prod name="Ultimate Bulletin Board" vendor="InfoPop"><vers num="5.43"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0142" published="2000-02-11" seq="2000-0142" severity="Medium" type="CVE"><desc><descript source="cve">The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3962.php">timbuktu-auth-dos(3962)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D4.2.0.58.20000211204020.00994c00@194.98.103.230">Timbuktu Pro 2.0b650 DoS</ref><ref patch="1" source="Netopia" url="http://www.netopia.com/software/products/tb2/">Timbuktu Pro Remote Control Software</ref></refs><vuln_soft><prod name="Timbuktu Pro" vendor="Netopia"><vers num="2.0"/><vers num="5.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0143" published="2000-02-11" seq="2000-0143" severity="Medium" type="CVE"><desc><descript source="cve">The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4683.php">ssh-redirect-tcp-connection(4683)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-08%26msg%3DPine.LNX.4.10.10002111717370.27486-100000@vulcan.alphanet.ch">20000211 sshd and pop/ftponly users incorrect configuration</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.27"/><vers num="1.2.26"/><vers num="1.2.25"/><vers num="1.2.24"/><vers num="1.2.23"/><vers num="1.2.22"/><vers num="1.2.21"/><vers num="1.2.20"/><vers num="1.2.2"/><vers num="1.2.19"/><vers num="1.2.18"/><vers num="1.2.17"/><vers num="1.2.16"/><vers num="1.2.15"/><vers num="1.2.14"/><vers num="1.2.13"/><vers num="1.2.12"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/></prod><prod name="OpenSSH" vendor="OpenBSD"><vers num="1.2.1" prev="1"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-16" name="CVE-2000-0144" published="2000-02-07" seq="2000-0144" severity="High" type="CVE"><desc><descript source="cve">Axis 700 Network Scanner does not properly restrict access to administrator URLs, which allows users to bypass the password protection via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/971">BID 971</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=4125687E.004790B1.00@mailgw.backupcentralen.se">Infosec.20000207.axis700.a</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4684.php">axis-bypass-authentication(4684)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0034.html">20000207 Infosec.20000207.axis700.a</ref><ref source="BID" url="http://www.securityfocus.com/bid/971">971</ref></refs><vuln_soft><prod name="AXIS 700 Network Document Server" vendor="Axis Communications"><vers num="1.0"/><vers num="1.10"/><vers num="1.11"/><vers num="1.12"/><vers num="1.13"/><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-2000-0145" published="2000-02-05" seq="2000-0145" severity="High" type="CVE"><desc><descript source="cve">The libguile.so library file used by gnucash in Debian GNU/Linux is installed with world-writable permissions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-1&amp;msg=20000205220024.A16073@ghost.nslug.ns.ca">Debian (frozen): Perms on /usr/lib/libguile.so.6.0.0</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4791.php">debian-libguile-world-writable(4791)</ref><ref patch="1" source="Remote Assessment" url="http://remoteassessment.com/?op=varchive&amp;vulnid=6233">debian-libguile-world-writable</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0146" published="2000-02-07" seq="2000-0146" severity="Medium" type="CVE"><desc><descript source="cve">The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service via a long URL to the servlet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/972">Novell GroupWise 5.5 Enhancement Pack DoS Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DCB068FFE4872BE4D81D729A32F20E71E1A1F@GRAYHOME.gray.com">Novell GroupWise 5.5 Enhancement Pack Web Access Denial of Servic e</ref><ref patch="1" source="Novell" url="http://support.novell.com/products/gw55/">GroupWise Support</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0049.html">20000207 Novell GroupWise 5.5 Enhancement Pack Web Access Denial of Servic e</ref></refs><vuln_soft><prod name="GroupWise Enhancement Pack" vendor="Novell"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0147" published="2000-02-08" seq="2000-0147" severity="Low" type="CVE"><desc><descript source="cve">snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host&apos;s configuration.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.04a">SNMPD configuration Vulnerability in  SCO OpenServer</ref><ref adv="1" patch="1" source="NeoHapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0045.html">SCO OpenServer SNMPD vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/973">973</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-0148" published="2000-02-08" seq="2000-0148" severity="High" type="CVE"><desc><descript source="cve">MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4228.php">mysql-remote-access(4228)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/975">BID 975</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/advisory.html?id=2103">mysql322-server</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0053.html">20000208 Remote access vulnerability in all MySQL server versions</ref><ref source="BID" url="http://www.securityfocus.com/bid/975">975</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.23.9"/><vers num="3.23.8"/><vers num="3.23.10"/><vers num="3.22.30"/><vers num="3.22.29"/><vers num="3.22.27"/><vers num="3.22.26"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0149" published="2000-02-08" seq="2000-0149" severity="Medium" type="CVE"><desc><descript source="cve">Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end of a URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-8&amp;msg=38A066C3.BA024C66@relaygroup.com">Zeus Web Server - obtaining source of CGI scripts</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/977">BID 977</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3982.php">zeus-server-null-string(3982)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0057.html">20000208 Zeus Web Server: Null Terminated Strings</ref><ref source="BID" url="http://www.securityfocus.com/bid/977">977</ref><ref source="OSVDB" url="http://www.osvdb.org/254">254</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3982">zeus-server-null-string(3982)</ref></refs><vuln_soft><prod name="Zeus Web Server" vendor="Zeus Technologies"><vers num="3.3.5"/><vers num="3.3.4"/><vers num="3.3.3"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.1.9"/><vers num="3.1.8"/><vers num="3.1.7"/><vers num="3.1.6"/><vers num="3.1.5"/><vers num="3.1.4"/><vers num="3.1.3"/><vers num="3.1.2"/><vers num="3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-2000-0150" published="2000-02-12" seq="2000-0150" severity="High" type="CVE"><desc><descript source="cve">Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client&apos;s PASV attempt.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-8&amp;msg=51A8E31DE32DD211A0590008C71E7E4C59686E@tro-03-msg.merkantildata.no">FireWall-1 FTP Server Vulnerability</ref><ref adv="1" patch="1" source="Check Point" url="http://www.checkpoint.com/techsupport/alerts/pasvftp.html">Passive FTP Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/979">BID 979</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3983.php">checkpoint-pasv-ftp(3983)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/328867">VU#328867</ref><ref source="BID" url="http://www.securityfocus.com/bid/979">979</ref><ref source="OSVDB" url="http://www.osvdb.org/4417">4417</ref></refs><vuln_soft><prod name="PIX Firewall" vendor="Cisco"><vers num="5.0"/><vers num="4.4(4)"/><vers num="4.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.1.6b"/><vers num="4.1.6"/></prod><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0151" published="2000-02-01" seq="2000-0151" severity="Medium" type="CVE"><desc><descript source="cve">GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3985.php">gnu-makefile-tmp-root(3985)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/981">GNU make /tmp Vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20000217">make: symlink attack in make</ref></refs><vuln_soft><prod name="make" vendor="Gnu"><vers num="3.77.44"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0152" published="2000-03-30" seq="2000-0152" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connection to port 2000.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Novell" url="http://support.novell.com/cgi-bin/search/tidfinder.cgi?2955744">BorderManager csatpxy.nlm fix avalable.</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4007.php">novell-audit-trail-dos(4007)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/979">BID 976</ref><ref source="BID" url="http://www.securityfocus.com/bid/976">976</ref><ref source="OSVDB" url="http://www.osvdb.org/7468">7468</ref></refs><vuln_soft><prod name="BorderManager" vendor="Novell"><vers num="3.5"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0153" published="1999-03-26" seq="2000-0153" severity="Medium" type="CVE"><desc><descript source="cve">FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000801bf780a$9ad4b2e0$0100007f@localhost">Doubledot bug in FrontPage FrontPage Personal Web Server.</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-8.phppws-file-access">pws-file-access</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-010.asp">Patch Available for File Access Vulnerability in Personal Web Server</ref><ref source="BID" url="http://www.securityfocus.com/bid/989">989</ref></refs><vuln_soft><prod name="Personal Web Server" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Frontpage" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0154" published="2000-02-16" seq="2000-0154" severity="Low" type="CVE"><desc><descript source="cve">The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/988">SCO Unixware ARCserver /tmp symlink Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-2.php-sco-openserver-arc-symlink">sco-openserver-arc-symlink</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-15%26msg%3D000101bf78af%2494528870%244d2f45a1@jmagdych.na.nai.com">ARCserve symlink vulnerability</ref><ref source="MISC" url="http://www.sco.com/security/">http://www.sco.com/security/</ref><ref source="NAI" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000101bf78af$94528870$4d2f45a1@jmagdych.na.nai.com">20000215 ARCserve symlink vulnerability</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0155" published="2000-02-18" seq="2000-0155" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1274.php">nt-autorun-notdefault(1274)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/993">BID  993</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-15%26msg%3D000701bf79cd%24fdb5a620%244c4342a6@mightye.org">AUTORUN.INF Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q177/8/80.asp">CD-ROM Does Not Run Automatically When Inserted</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000701bf79cd$fdb5a620$4c4342a6@mightye.org">20000218 AUTORUN.INF Vulnerability</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-2000-0156" published="2000-02-16" seq="2000-0156" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the &quot;Image Source Redirect&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-009.asp">MS00-009</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-2.php">ie-source-redirect advisory</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-009.mspx">MS00-009</ref><ref source="OSVDB" url="http://www.osvdb.org/7827">7827</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3996">ie-image-source-redirect(3996)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0"/><vers num="4.0.0.1"/><vers num="5.0"/><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0157" published="2000-02-01" seq="2000-0157" severity="High" type="CVE"><desc><descript source="cve">NetBSD ptrace call on VAX allows local users to gain privileges by modifying the PSL contents in the debugging process.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3994.php">netbsd-ptrace(3994)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/979">BID 992</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-15%26msg%3D14505.23579.967265.266049@passion.geek.com.au">NetBSD Security Advisory 1999-012</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-012.txt.asc">1999-012</ref><ref source="BID" url="http://www.securityfocus.com/bid/992">992</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0158" published="2000-02-16" seq="2000-0158" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in MMDF server allows remote attackers to gain privileges via a long MAIL FROM command to the SMTP daemon.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000001bf78af$6d0d47a0$4d2f45a1@jmagdych.na.nai.com">Remote Vulnerability in the MMDF SMTP Daemon</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4344.php">sco-mmdf-bo(4344)</ref><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.06a">Buffer Overflow Vulnerabilities in OpenServer MMDF subsystem</ref><ref source="BID" url="http://www.securityfocus.com/bid/997">997</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=200002181449.JAA03436@dragonfly.corp.home.net">20000218 MMDF</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.0"/><vers num="5.0.2"/><vers num="5.0.5"/><vers num="5.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0159" published="2000-02-17" seq="2000-0159" severity="High" type="CVE"><desc><descript source="cve">HP Ignite-UX does not save /etc/passwd when it creates an image of a trusted system, which can set the password field to a blank and allow an attacker to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1027">BID 1027</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/advisory.html?id=2091">HPSBUX0002-111</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4782.php">hp-ignite-blank-password(4782)</ref><ref source="HP" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=20000217160216.13708.qmail@underground.org">HPSBUX0002-111</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0160" published="2000-02-21" seq="2000-0160" severity="High" type="CVE"><desc><descript source="cve">The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software&apos;s manufacturer is Microsoft.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-2.php-win-active-setup">win-active-setup</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-15%26msg%3D20000221103938.T21312@securityfocus.com">Microsoft signed software can be install software without prompting users</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=20000221103938.T21312@securityfocus.com">20000221 Microsoft signed software can be install software without prompting users</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5"/><vers num="4.x"/></prod><prod name="Outlook" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0161" published="2000-02-18" seq="2000-0161" severity="High" type="CVE"><desc><descript source="cve">Sample web sites on Microsoft Site Server 3.0 Commerce Edition do not validate an identification number, which allows remote attackers to execute SQL commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3997.php">siteserver-sitebuilder(3997)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq00-010.asp">MS00-010</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/994">bugtraq id 994</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-010.asp">MS00-010</ref><ref source="BID" url="http://www.securityfocus.com/bid/994">994</ref></refs><vuln_soft><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0162" published="2000-02-18" seq="2000-0162" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the &quot;VM File Reading&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-011.asp">MS00-011</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4024.php">msvm-java-file-read(4024)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1027">BID 600</ref></refs><vuln_soft><prod name="Visual Studio" vendor="Microsoft"><vers num="6.0"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows NT 4.0" num="50"/><vers edition="Windows 98" num="5.0"/><vers edition="Windows 95" num="5.0"/><vers edition="Windows NT 4.0" num="4.1"/><vers edition="Windows 95" num="4.1"/><vers edition="Windows NT" num="4.0"/><vers edition="Windows 98" num="4.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0163" published="2000-02-21" seq="2000-0163" severity="Medium" type="CVE"><desc><descript source="cve">asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4182.php">asmon-ascpu-execute-commands(4182)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/advisory.html%3Fid%3D2092">FreeBSD-SA-00:03: Asmon/Ascpu ports fail to drop privileges</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D996">bugtraq id 996</ref><ref source="FREEBSD" url="http://www.securityfocus.com/templates/advisory.html?id=2092">FreeBSD-SA-00:03</ref><ref source="BID" url="http://www.securityfocus.com/bid/996">996</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0164" published="2000-02-20" seq="2000-0164" severity="High" type="CVE"><desc><descript source="cve">The installation of Sun Internet Mail Server (SIMS) creates a world-readable file that allows local users to obtain passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4783.php">sims-temp-world-readable(4783)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-15%26msg%3DPine.SOL.4.21.0002200031320.22675-100000@klayman.hq.formus.pl">Sun Internet Mail Server</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1004">bugtraq id 1004</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.SOL.4.21.0002200031320.22675-100000@klayman.hq.formus.pl">20000220 Sun Internet Mail Server</ref></refs><vuln_soft><prod name="Solaris ISP Server" vendor="Sun"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0165" published="1999-11-13" seq="2000-0165" severity="High" type="CVE"><desc><descript source="cve">The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/808">BID 808</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/templates/advisory.html?id=2093">FreeBSD-SA-00:04</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4195.php">delegate-proxy-bo(4195)</ref><ref source="FREEBSD" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=Pine.BSF.4.21.0002192249290.10784-100000@freefall.freebsd.org">FreeBSD-SA-00:04</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-023.shtml">K-023</ref></refs><vuln_soft><prod name="Delegate" vendor="ETL"><vers num="6.0"/><vers num="5.9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0166" published="2000-02-21" seq="2000-0166" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4032.php">interaccess-telnet-login-bo(4032)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-15%26msg%3DNCBBKFKDOLAGKIAPMILPGEJHCCAA.labs@ussrback.com">Local / Remote Exploiteable Buffer Overflow Vulnerability in InterAccess TelnetD Server 4.0 for Windows NT</ref><ref adv="1" source="USSRLabs" url="http://www.ussrback.com/labs33.html">Local / Remote Exploiteable Buffer Overflow Vulnerability in InterAccess TelnetD Server 4.0 for Windows NT</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPGEJHCCAA.labs@ussrback.com">20000221 Local / Remote Exploiteable Buffer Overflow Vulnerability in InterAccess TelnetD Server 4.0 for Windows NT</ref><ref source="BID" url="http://www.securityfocus.com/bid/995">995</ref></refs><vuln_soft><prod name="InterAccess TelnetD Server" vendor="Interaccess"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0167" published="2000-02-15" seq="2000-0167" severity="Low" type="CVE"><desc><descript source="cve">IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4790.php">iis-pickup-directory-dos(4790)</ref><ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0002&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=8800">20000215 Crashing Inetinfo.exe by using a longfilename in the \mailroot\pickup directory</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0168" published="2000-03-04" seq="2000-0168" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows 9x operating systems allow an attacker to cause a denial of service via a pathname that includes file device names, aka the &quot;DOS Device in Path Name&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1043">BID 1043</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4107.php">win-dos-devicename-dos(4107)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCENECCAA.labs@ussrback.com">20000306 con\con is a old thing (anyway is cool)</ref><ref source="MS" url="http://www.securityfocus.com/templates/advisory.html?id=2126">MS00-017</ref><ref source="BID" url="http://www.securityfocus.com/bid/1043">1043</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2000-0169" published="2000-03-15" seq="2000-0169" severity="High" type="CVE"><desc><descript source="cve">Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes &apos;?&amp;&apos;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4198.php">oracle-weblistener-remote-attack(4198)</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1053">BID 1053</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-03-8%26msg%3D013001bf8e14%245a2a3970%242102020a@ELYSIUM"> Oracle Web Listener 4.0.x</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0211.html">20000314 Oracle Web Listener 4.0.x</ref><ref source="BID" url="http://www.securityfocus.com/bid/1053">1053</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0170" published="2000-02-26" seq="2000-0170" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1011">BID 1011</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/advisory.html?id=2114">man bugs might lead to root compromise</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4043.php">man-bo(4043)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1011">1011</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/><vers num="6.0"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num="4.4"/><vers num="4.2"/><vers num="3.5b2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0171" published="2000-03-11" seq="2000-0171" severity="High" type="CVE"><desc><descript source="cve">atsadc in the atsar package for Linux does not properly check the permissions of an output file, which allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4208.php">atsar-root-access(4208)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1048">BID 1048</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-03-8%26msg%3D20000311143217.E56241EE8B@lists.securityfocus.com">TESO advisory -- atsadc</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0102.html">20000311 TESO advisory -- atsadc</ref><ref source="BID" url="http://www.securityfocus.com/bid/1048">1048</ref></refs><vuln_soft><prod name="atsar_linux" vendor="AT Computing"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0172" published="2000-03-03" seq="2000-0172" severity="High" type="CVE"><desc><descript source="cve">The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1038">BID 1038</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4162.php">mtr-drop-privileges(4162)</ref><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-028.shtml">FreeBSD Port Exploits for mh/nmh, Lynx, and mtr</ref><ref source="BID" url="http://www.securityfocus.com/bid/1038">1038</ref></refs><vuln_soft><prod name="mtr" vendor="Matt Kimball and Roger Wolff"><vers num="0.41"/><vers num="0.28"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num="6.0.2"/><vers num="4.4"/><vers num="4.2"/><vers num="3.5b2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0173" published="2000-03-10" seq="2000-0173" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.08a">EELS security patch</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4341.php">sco-eels-dos(4341)</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.1"/><vers num="7.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0174" published="2000-03-09" seq="2000-0174" severity="Medium" type="CVE"><desc><descript source="cve">StarOffice StarScheduler web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1040">Bugtraq id 1040</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4076.php">staroffice-scheduler-fileread(4076)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D38C68FB8.6F234393@relaygroup.com"> [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/1040">1040</ref></refs><vuln_soft><prod name="StarOffice" vendor="Sun"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0175" published="2000-03-09" seq="2000-0175" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in StarOffice StarScheduler web server allows remote attackers to gain root access via a long GET command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1039">BID 1039</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4075.php">staroffice-scheduler-bo(4075)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D38C68FB8.6F234393@relaygroup.com">[SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0063.html">20000308 [SAFER 000309.EXP.1.4] StarScheduler (StarOffice) vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/1039">1039</ref></refs><vuln_soft><prod name="StarOffice" vendor="Sun"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0176" published="2000-02-29" seq="2000-0176" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1016">BID 1016</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4060.php">servu-ftp-server-path(4060)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.GSO.4.10.10002291933150.12831-100000@www.securityfocus.com">Re: Serv-U FTP-Server v2.4a showing real path</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0417.html">20000228 Serv-U FTP-Server v2.4a showing real path</ref></refs><vuln_soft><prod name="Serv-U" vendor="Cat Soft"><vers num="2.5d"/><vers num="2.5c"/><vers num="2.5b"/><vers num="2.5a"/><vers num="2.5"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0177" published="2000-03-02" seq="2000-0177" severity="High" type="CVE"><desc><descript source="cve">DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4876.php">dnstools-invalid-input(4876)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000302085915.A24813@leto.net">DNSTools v1.08 has no input validation</ref><ref adv="1" patch="1" source="DNSTools" url="http://www.dnstools.com/security.html">DNSTools Software - Security Concerns</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D1028">bugtraq id 1028</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0000.html">20000302 DNSTools v1.08 has no input validation</ref><ref source="BID" url="http://www.securityfocus.com/bid/1028">1028</ref></refs><vuln_soft><prod name="DNSTools" vendor="DNSTools Software"><vers num="1.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2000-0178" published="2000-02-28" seq="2000-0178" severity="High" type="CVE"><desc><descript source="cve">ServerIron switches by Foundry Networks have predictable TCP/IP sequence numbers, which allows remote attackers to spoof or hijack sessions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1017">BID 1017</ref><ref adv="1" source="Foundry Networks" url="http://www.foundrynet.com/bugTraq.html"></ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-15&amp;msg=EMEOLGIJGHCAFMLLBDKJKELKCJAA.a.vanderstock@e-secure.com.au">20000227 Advisory: Foundry Networks ServerIron TCP/IP sequence predictability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4054.php">foundry-serveriron-tcp-seq(4054)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1017">1017</ref></refs><vuln_soft><prod name="ServerIron" vendor="Foundry Networks"><vers num="6.0"/><vers num="5.1.10t12"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0179" published="2000-02-28" seq="2000-0179" severity="Medium" type="CVE"><desc><descript source="cve">HP OpenView OmniBack 2.55 allows remote attackers to cause a denial of service via a large number of connections to port 5555.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4022.php">omniback-connection-dos(4022)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1015">BID 1015</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-22%26msg%3DNCBBIKPJMLKCCIIOHCNDKEFDCHAA.jon@hittner.com">HP Omniback remote DoS</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0387.html">20000228 HP Omniback remote DoS</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0006-115">HPSBUX0006-115</ref></refs><vuln_soft><prod name="OpenView OmniBack II" vendor="HP"><vers num="3.1"/><vers num="3.0"/><vers num="2.55"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0180" published="2000-03-14" seq="2000-0180" severity="Medium" type="CVE"><desc><descript source="cve">Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1052">BID 1052</ref><ref adv="1" source="NeoHapsis" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0201.html">SOJOURN Search engine exposes files</ref><ref source="XF" url="http://xforce.iss.net/static/4197.php">sojourn-file-read(4197)</ref></refs><vuln_soft><prod name="Sojourn" vendor="Generation Terrorists Designs and Concepts"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0181" published="2000-03-11" seq="2000-0181" severity="Medium" type="CVE"><desc><descript source="cve">Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1054">BID 1054</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=38CB00EB.A9F776F7@sover.net">20000311 Our old friend Firewall-1</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4207.php">checkpoint-exposes-internal-addresses(4207)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0119.html">20000311 Our old friend Firewall-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1054">1054</ref><ref source="OSVDB" url="http://www.osvdb.org/1256">1256</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0182" published="2000-02-23" seq="2000-0182" severity="Medium" type="CVE"><desc><descript source="cve">iPlanet Web Server 4.1 allows remote attackers to cause a denial of service via a large number of GET commands, which consumes memory and causes a kernel panic.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-22&amp;msg=200002230131.AA00461@xjr1200.lac.co.jp">DoS for the iPlanet Web Server, Enterprise Edition 4.1</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4293.php">iplanet-get-dos(4293)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-02-22%26msg%3DPine.LNX.4.10.10002231434310.16996-100000@localhost">Re: DoS for the iPlanet Web Server, Enterprise Edition 4.1</ref></refs><vuln_soft><prod name="iPlanet Web Server" vendor="iPlanet"><vers num="4.1 Enterprise"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0183" published="2000-03-10" seq="2000-0183" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in ircII 4.4 IRC client allows remote attackers to execute commands via the DCC chat capability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1046">BID 1046</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4184.php">irc-dcc-bo(4184)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D00020810435400.14713@wintermute-pub">Fwd: ircii-4.4 buffer overflow</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0093.html">20000310 Fwd: ircii-4.4 buffer overflow</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-008.html">RHSA-2000:008</ref><ref source="BID" url="http://www.securityfocus.com/bid/1046">1046</ref></refs><vuln_soft><prod name="IrcII" vendor="Michael Sandrof"><vers num="4.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0184" published="2000-03-09" seq="2000-0184" severity="Low" type="CVE"><desc><descript source="cve">Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1037">BID 1037</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4212.php">printtool-world-readable(4212)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-03-08%26msg%3D200003081943.EAA30620@duat.dhs.org">[ Hackerslab bug_paper ] Linux printtool get printer password</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0082.html">20000309</ref><ref source="BID" url="http://www.securityfocus.com/bid/1037">1037</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2000-0185" published="2000-03-08" seq="2000-0185" severity="Medium" type="CVE"><desc><descript source="cve">RealMedia RealServer reveals the real IP address of a Real Server, even if the address is supposed to be private.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1049">BID 1049</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4367.php">realserver-exposes-addresses(4367)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D4.2.0.58.20000309110518.0096b690@postoffice.worldnet.att.net">Re: RealServer exposes internal IP addresses</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0069.html">20000308 RealServer exposes internal IP addresses</ref><ref source="BID" url="http://www.securityfocus.com/bid/1049">1049</ref></refs><vuln_soft><prod name="RealServer G2" vendor="RealNetworks"><vers num="1.0"/></prod><prod name="RealServer" vendor="RealNetworks"><vers num="7.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0186" published="2000-02-28" seq="2000-0186" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1020">BID 1020</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4048.php">linux-dump-bo(4048)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200002280617.PAA13373@ce.hannam.ac.kr">[ Hackerslab bug_paper ] Linux dump buffer overflow</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-100.html">RHSA-2000:100</ref><ref source="BID" url="http://www.securityfocus.com/bid/1020">1020</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.4"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.2"/><vers edition="i386" num="6.1"/><vers edition="i386" num="6.0"/><vers edition="i386" num="5.2"/><vers num="5.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.0"/><vers num="6.1"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num="6.0.2"/><vers num="4.4"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0187" published="2000-02-27" seq="2000-0187" severity="High" type="CVE"><desc><descript source="cve">EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1014">BID 1014</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4044.php">ezshopper-loadpage-cgi(4044)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200002270932.UAA19852@jawa.chilli.net.au">EZ Shopper 3.0 shopping cart CGI remote command execution</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0356.html">20000227 EZ Shopper 3.0 shopping cart CGI remote command execution</ref></refs><vuln_soft><prod name="EZShopper" vendor="Alex Heiphetz Group"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0188" published="2000-02-27" seq="2000-0188" severity="High" type="CVE"><desc><descript source="cve">EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4044.php">ezshopper-loadpage-cgi(4044)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200002270932.UAA19852@jawa.chilli.net.au">EZ Shopper 3.0 shopping cart CGI remote command execution</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0356.html">20000227 EZ Shopper 3.0 shopping cart CGI remote command execution</ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/1014">1014</ref></refs><vuln_soft><prod name="EZShopper" vendor="Alex Heiphetz Group"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0189" published="2000-03-01" seq="2000-0189" severity="Medium" type="CVE"><desc><descript source="cve">ColdFusion Server 4.x allows remote attackers to determine the real pathname of the server via an HTTP request to the application.cfm or onrequestend.cfm files.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1021">BID 1021</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0003&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=435">20000301 ColdFusions application.cfm shows full path</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4021.php">coldfusion-reveal-pathname(4021)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1021">1021</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.5"/><vers num="4.0.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0190" published="2000-03-02" seq="2000-0190" severity="Medium" type="CVE"><desc><descript source="cve">AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4877.php">aolim-malformed-ascii-dos(4877)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-03-1%26msg%3D20000303154750.23363.qmail@hotmail.com">Aol Instant Messenger DoS vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0016.html">20000303 Aol Instant Messenger DoS vulnerability</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="3.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-16" name="CVE-2000-0191" published="2000-02-29" seq="2000-0191" severity="High" type="CVE"><desc><descript source="cve">Axis StorPoint CD allows remote attackers to access administrator URLs without authentication via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4078.php">axis-storpoint-auth(4078)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1025">bugtraq id 1025</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=41256894.00492503.00@mailgw.backupcentralen.se">Infosec.20000229.axisstorpointcd.a</ref><ref source="OSVDB" url="http://www.osvdb.org/19">19</ref></refs><vuln_soft><prod name="AXIS StorPoint CD" vendor="Axis Communications"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0192" published="2000-03-05" seq="2000-0192" severity="Medium" type="CVE"><desc><descript source="cve">The default installation of Caldera OpenLinux 2.3 includes the CGI program rpm_query, which allows remote attackers to determine what packages are installed on the system.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1036">BID 1036</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4168.php">linux-rpm-query(4168)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0003041204220.6797-100000@juggernaut.el8.org"> OpenLinux 2.3: rpm_query</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0029.html">20000304 OpenLinux 2.3: rpm_query</ref><ref source="BID" url="http://www.securityfocus.com/bid/1036">1036</ref></refs><vuln_soft><prod name="OpenLinux" vendor="Caldera"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0193" published="2000-03-02" seq="2000-0193" severity="High" type="CVE"><desc><descript source="cve">The default configuration of Dosemu in Corel Linux 1.0 allows local users to execute the system.com program and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4066.php">linux-dosemu-config(4066)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1030">bugtraq id 1030</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200003020436.PAA20168@jawa.chilli.net.au">Corel Linux 1.0 dosemu default configuration: Local root vuln</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003020436.PAA20168@jawa.chilli.net.au">20000302 Corel Linux 1.0 dosemu default configuration: Local root vuln</ref></refs><vuln_soft><prod name="Linux" vendor="Corel"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0194" published="2000-02-24" seq="2000-0194" severity="High" type="CVE"><desc><descript source="cve">buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1007">BID 1007</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=200002242318.KAA18622@jawa.chilli.net.au">Corel Linux 1.0 local root compromise</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4031.php">corel-linux-create-file(4031)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html">20000224 Corel Linux 1.0 local root compromise</ref><ref source="BID" url="http://www.securityfocus.com/bid/1007">1007</ref></refs><vuln_soft><prod name="Linux" vendor="Corel"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0195" published="2000-02-24" seq="2000-0195" severity="High" type="CVE"><desc><descript source="cve">setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user&apos;s .xserverrc file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1008">BID 1008</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4027.php">corel-linux-setxconf-root(4027)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200002242318.KAA18622@jawa.chilli.net.au">Corel Linux 1.0 local root compromise</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0323.html">20000224 Corel Linux 1.0 local root compromise</ref><ref source="BID" url="http://www.securityfocus.com/bid/1008">1008</ref></refs><vuln_soft><prod name="Linux" vendor="Corel"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0196" published="2000-02-28" seq="2000-0196" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in mhshow in the Linux nmh package allows remote attackers to execute commands via malformed MIME headers in an email message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1018">BID 1018</ref><ref patch="1" source="Debian" url="http://www.debian.org/security/2000/20000229">nmh: remote exploit in nmh</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4051.php">nmh-execute-code(4051)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/advisory.html?id=2129">emote exploit in nmh</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-006.html">RHSA-2000:006</ref><ref source="BID" url="http://www.securityfocus.com/bid/1018">1018</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/><vers edition="Sparc" num="6.0"/><vers edition="i386" num="6.0"/><vers edition="Alpha" num="6.0"/><vers edition="Sparc" num="5.2"/><vers edition="i386" num="5.2"/><vers edition="Alpha" num="5.2"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num="6.0.2"/><vers num="4.4"/><vers num="4.2"/><vers num="3.5b2"/></prod><prod name="nmh" vendor="Linux"><vers num="1.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0197" published="2000-02-14" seq="2000-0197" severity="Medium" type="CVE"><desc><descript source="cve">The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4221.php">nt-at-drive-mappjngs(4221)</ref><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1050">bugtraq id 1050</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DF91320BA2EA7D311B01400A0C9DF88FB42446C@csgexmail1.csg.stercomm.com">FW: [NTBUGTRAQ] AT Jobs - Denial of serice/Privilege Elevation</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/current/0202.html">20000313 AT Jobs - Denial of serice/Privilege Elevation</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0198" published="2000-03-15" seq="2000-0198" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="USSRLabs" url="http://www.ussrback.com/labs35.html">Local / Remote Multiples DoS Attacks in MERCUR v3.2* Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4365.php">mercur-login-dos(4365)</ref><ref patch="1" source="Atrium Software" url="http://www.atrium-software.com/pub/support_e.cfm">Product support</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/current/0206.html">20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0137.html">20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1051">1051</ref></refs><vuln_soft><prod name="Mercur POP3 Server" vendor="Atrium Software"><vers num="3.20.01"/></prod><prod name="MERCUR Mailserver" vendor="Atrium Software"><vers num="3.2"/></prod><prod name="Mercur IMAP4 Server" vendor="Atrium Software"><vers num="3.20.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-0199" published="2000-03-14" seq="2000-0199" severity="High" type="CVE"><desc><descript source="cve">When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the &quot;Always prompt for login name and password&quot; option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise45.php3">Vulnerability in Microsoft SQL Server 7.0 Encryption Used to Store</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1055">bugtraq id 1055</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/advisory.html%3Fid%3D2136">K-026: Microsoft SQL Server Admin Login Encryption Vulnerability</ref></refs><vuln_soft><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0200" published="2000-03-06" seq="2000-0200" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the &quot;Clip Art Buffer Overrun&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1034">BID 1034</ref><ref adv="1" patch="1" source="Microsoft Security Bulletin" url="http://www.microsoft.com/technet/security/bulletin/MS00-015.asp">MS00-015</ref><ref adv="1" patch="1" source="Microsoft Security FAQ" url="http://xforce.iss.net/static/4109.php">clipart-cil-bo(4109)</ref><ref adv="1" patch="1" source="L0pht Advisory" url="http://www.l0pht.com/advisories/ms-clipart.txt">03/06/00</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-015.mspx">MS00-015</ref><ref source="BID" url="http://www.securityfocus.com/bid/1034">1034</ref></refs><vuln_soft><prod name="Home Publishing" vendor="Microsoft"><vers num="2000"/></prod><prod name="Clip Art" vendor="Microsoft"><vers num="1.0"/></prod><prod name="Greetings" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0201" published="2000-03-01" seq="2000-0201" severity="Medium" type="CVE"><desc><descript source="cve">The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1033">BID 1033</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=38BD37F6.C9B3F8B@nat.bg">E 5.x allows executing arbitrary programs using .chm files</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4601.php">ie-html-helpfile-execute(4601)</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q259/1/66.ASP">UNC Path Can Be Used to Start Programs by Using .chm Files</ref><ref source="BID" url="http://www.securityfocus.com/bid/1033">1033</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-0202" published="2000-03-08" seq="2000-0202" severity="High" type="CVE"><desc><descript source="cve">Microsoft SQL Server 7.0 and Microsoft Data Engine (MSDE) 1.0 allow remote attackers to gain privileges via a malformed Select statement in an SQL query.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1041">BID 1041</ref><ref adv="1" patch="1" source="Microsoft Security Bulletin" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-014.asp">MS00-014</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=F16E03C431B5D211893000104BC5C1A702C02231@powaymail.credco.firstam.com">Microsoft SQL Query Abuse Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4110.php">mssql-query-abuse(4110)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-014.mspx">MS00-014</ref><ref source="BID" url="http://www.securityfocus.com/bid/1041">1041</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0203" published="2000-02-28" seq="2000-0203" severity="Medium" type="CVE"><desc><descript source="cve">The Trend Micro OfficeScan client tmlisten.exe allows remote attackers to cause a denial of service via malformed data to port 12345.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=412FC0AFD62ED31191B40008C7E9A11A0D481D@srvnt04.previnet.it">Re: TrendMicro OfficeScan tmlisten.exe DoS</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4039.php">trendmicro-tmlisten-dos(4039)</ref><ref adv="1" patch="1" source="Trend Micro" url="http://www.antivirus.com/download/ofce_patch_35.htm">Trend Security Bulletin - OfficeScan DoS &amp; Command Replay Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/1013">1013</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com">20000315 Trend Micro release patch for &quot;OfficeScan DoS &amp; Message Replay&quot; V ulnerabilies</ref></refs><vuln_soft><prod name="OfficeScan" vendor="Trend Micro"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0204" published="2000-02-28" seq="2000-0204" severity="Medium" type="CVE"><desc><descript source="cve">The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utilization to 100%.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=412FC0AFD62ED31191B40008C7E9A11A0D481D@srvnt04.previnet.it">Re: TrendMicro OfficeScan tmlisten.exe DoS</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4039.php">trendmicro-tmlisten-dos(4039)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-02/0340.html">20000226 DOS in Trendmicro OfficeScan</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com">20000315 Trend Micro release patch for &quot;OfficeScan DoS &amp; Message Replay&quot; V ulnerabilies</ref><ref source="BID" url="http://www.securityfocus.com/bid/1013">1013</ref><ref source="" url="http://www.antivirus.com/download/ofce_patch_35.htm"></ref></refs><vuln_soft><prod name="OfficeScan" vendor="Trend Micro"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0205" published="2000-03-03" seq="2000-0205" severity="Medium" type="CVE"><desc><descript source="cve">Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0015.html">TrendMicro OfficeScan, numerous security holes, remote files modification.</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4041.php">trendmicro-admin-command(4041)</ref><ref adv="1" patch="1" source="Tern Micro" url="http://www.antivirus.com/download/ofce_patch_35.htm">Trend Security Bulletin - OfficeScan DoS &amp; Command Replay Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/1013">1013</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com">20000315 Trend Micro release patch for &quot;OfficeScan DoS &amp; Message Replay&quot; V ulnerabilies</ref></refs><vuln_soft><prod name="OfficeScan" vendor="Trend Micro"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0206" published="2000-03-05" seq="2000-0206" severity="Medium" type="CVE"><desc><descript source="cve">The installation of Oracle 8.1.5.x on Linux follows symlinks and creates the orainstRoot.sh file with world-writeable permissions, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1035">BID 1035</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSO.4.10.10003051801030.22289-100000@obscurity.org">Oracle installer problem</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4163.php">oracle-installer(4163)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0023.html">20000305 Oracle installer problem</ref><ref source="BID" url="http://www.securityfocus.com/bid/1035">1035</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0207" published="2000-03-01" seq="2000-0207" severity="High" type="CVE"><desc><descript source="cve">SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1031">BID 1031</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10003021059360.21162-100000@inetarena.com">20000301 infosrch.cgi vulnerability (IRIX 6.5)</ref><ref adv="1" patch="1" source="Security Focus Advisory" url="http://securityfocus.com/templates/advisory.html?id=2241">20000501-01-P</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20000501-01-P">20000501-01-P</ref><ref source="BID" url="http://www.securityfocus.com/bid/1031">1031</ref></refs><vuln_soft><prod name="InfoSearch" vendor="SGI"><vers num="1.0"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.5.7"/><vers num="6.5.6"/><vers num="6.5.4"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.2m"/><vers num="6.5.1"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0208" published="2000-02-29" seq="2000-0208" severity="Medium" type="CVE"><desc><descript source="cve">The htdig (ht://Dig) CGI program htsearch allows remote attackers to read arbitrary files by enclosing the file name with backticks (`) in parameters to htsearch.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1026">BID 1026</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4052.php">htdig-remote-read(4052)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10002281422420.30728-100000@wso.williams.edu">ht://Dig remote information exposure</ref><ref source="BID" url="http://www.securityfocus.com/bid/1026">1026</ref></refs><vuln_soft><prod name="htDig" vendor="htDig"><vers num="3.2.0b1"/><vers num="3.1.4"/><vers num="3.1.3"/><vers num="3.1.2"/><vers num="3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0209" published="2000-02-27" seq="2000-0209" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Lynx 2.x allows remote attackers to crash Lynx and possibly execute commands via a long URL in a malicious web page.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1012">BID 1012</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4046.php">lynxproxy-long-url-bo(4046)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.21.0002271629490.15796-100000@dione.ids.pl">lynx - someone is deaf and blind</ref><ref source="BID" url="http://www.securityfocus.com/bid/1012">1012</ref></refs><vuln_soft><prod name="Lynx" vendor="University of Kansas"><vers num="2.8.3 dev22"/><vers num="2.8"/><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0210" published="2000-02-21" seq="2000-0210" severity="Low" type="CVE"><desc><descript source="cve">The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/998">BID 998</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.GSO.4.10.10002212252390.4077-100000@apollo.gti.net"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4294.php">sol-licensemanager-symlink(4294)</ref><ref source="BID" url="http://www.securityfocus.com/bid/998">998</ref></refs><vuln_soft><prod name="Workshop" vendor="Sun"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0211" published="2000-02-23" seq="2000-0211" severity="Medium" type="CVE"><desc><descript source="cve">The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the &quot;Misordered Windows Media Services Handshake&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1000">BID 1000</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4034.php">win-media-dos(4034)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-013.asp">MS00-013</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-013.mspx">MS00-013</ref><ref source="BID" url="http://www.securityfocus.com/bid/1000">1000</ref></refs><vuln_soft><prod name="Windows Media Services" vendor="Microsoft"><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0212" published="2000-02-24" seq="2000-0212" severity="Medium" type="CVE"><desc><descript source="cve">InterAccess TelnetID Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client configuration information.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1001">BID 1001</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPEELFCCAA.labs@ussrback.com">USSR-2000034</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4033.php">interaccess-telnet-dos(4033)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1001">1001</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4033">interaccess-telnet-dos(4033)</ref></refs><vuln_soft><prod name="InterAccess TelnetD Server" vendor="Pragma Systems"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0213" published="2000-02-23" seq="2000-0213" severity="Medium" type="CVE"><desc><descript source="cve">The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38B3E60A.6A84FEC3@cybcom.net">Sambar Server alert!</ref><ref adv="1" source="Sambar" url="http://www.sambar.com/session/highlight?url=/syshelp/history.htm&amp;words=security+&amp;color=red">Release History</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-2.php-sambar-batfiles">sambar-batfiles</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1002">BID 1002</ref></refs><vuln_soft><prod name="Sambar Server" vendor="Sambar"><vers num="4.2 beta7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0214" published="2000-02-24" seq="2000-0214" severity="Medium" type="CVE"><desc><descript source="cve">FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10002242035500.30645-100000@unreal.sekure.org">How the password could be recover using FTP Explorer&apos;s registry!</ref><ref patch="1" source="FTPx" url="http://www.ftpx.com/securityres.html">Login Security DLL</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4038.php">ftp-explorer-weak-pwd(4038)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1003">1003</ref></refs><vuln_soft><prod name="FTP Explorer" vendor="FTPx"><vers num="1.00.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0215" published="2000-02-08" seq="2000-0215" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in SCO cu program in UnixWare 7.x allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1019">BID 1019</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4275.php">sco-cu-patch(4275)</ref><ref adv="1" patch="1" source="SCO Security Bulletins" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.05a">SCO Security Bulletin 2000.05</ref><ref source="BID" url="http://www.securityfocus.com/bid/1019">1019</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1"/><vers num="7.0.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-0216" published="2000-02-29" seq="2000-0216" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0176.html">mailbombing DoS easily exploitable against mail systems using MS mail clients.</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4893.php">microsoft-mail-client-dos(4893)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num=""/></prod><prod name="windows messaging" vendor="Microsoft"><vers num=""/></prod><prod name="Outlook" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0217" published="2000-02-24" seq="2000-0217" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client&apos;s X sessions via a malicious xauth program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1006">BID 1006</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=20000224173135.A4478@ruff.cs.jmu.edu">SSH &amp; xauth</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4037.php">ssh-xauth-client(4037)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1006">1006</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.31"/><vers num="1.2.30"/><vers num="1.2.29"/><vers num="1.2.28"/><vers num="1.2.27"/><vers num="1.2.26"/><vers num="1.2.25"/><vers num="1.2.24"/><vers num="1.2.23"/><vers num="1.2.22"/><vers num="1.2.21"/><vers num="1.2.20"/><vers num="1.2.19"/><vers num="1.2.18"/><vers num="1.2.17"/><vers num="1.2.16"/><vers num="1.2.15"/><vers num="1.2.14"/><vers num="1.2.13"/><vers num="1.2.12"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2.0"/></prod><prod name="SSH2" vendor="SSH Communications Security"><vers num="2.0.9"/><vers num="2.0.8"/><vers num="2.0.7"/><vers num="2.0.6"/><vers num="2.0.5"/><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.12"/><vers num="2.0.11"/><vers num="2.0.10"/><vers num="2.0.1"/><vers num="2.0"/></prod><prod name="OpenSSH" vendor="OpenBSD"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0218" published="2000-02-03" seq="2000-0218" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Caldera" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-002.0.txt">CSSA-2000-002.0</ref><ref adv="1" patch="1" source="SuSE" url="http://www.suse.de/de/support/security/suse_security_announce_39.txt">Security hole in util &lt; 2.10f</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/411.php">linux-mount(411)</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-002.0.txt">CSSA-2000-002.0</ref><ref source="OSVDB" url="http://www.osvdb.org/6980">6980</ref><ref source="OSVDB" url="http://www.osvdb.org/7004">7004</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num=""/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0219" published="2000-02-23" seq="2000-0219" severity="High" type="CVE"><desc><descript source="cve">Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1005">BID 1005</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4026.php">redhat-single-user-auth(4026)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200002230248.NAA19185@cairo.anu.edu.au"> redhat 6.0: single user boot security hole</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0220" published="2000-02-24" seq="2000-0220" severity="Medium" type="CVE"><desc><descript source="cve">ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4295.php">zonealarm-exposes-info(4295)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-29&amp;msg=Pine.LNX.4.10.10002242319160.14025-100000@cr1001800-a"> Zonealarm exports sensitive data</ref></refs><vuln_soft><prod name="ZoneAlarm" vendor="Zone Labs"><vers num="2.0.26"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0221" published="2000-02-25" seq="2000-0221" severity="Medium" type="CVE"><desc><descript source="cve">The Nautica Marlin bridge allows remote attackers to cause a denial of service via a zero length UDP packet to the SNMP port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1009">BID 1009</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10002250826310.13536-100000@nef.esiea.fr">Scorpion Marlin</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4200.php">nautica-marlin-router-dos(4200)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1009">1009</ref></refs><vuln_soft><prod name="Nautica" vendor="Nortel"><vers num="Marlin"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0222" published="2000-02-15" seq="2000-0222" severity="High" type="CVE"><desc><descript source="cve">The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/990">BID 990</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000215155750.M4500@safe.hsc.fr">Windows 2000 installation process weakness</ref><ref source="BID" url="http://www.securityfocus.com/bid/990">990</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/><vers num="Professional"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0223" published="2000-03-10" seq="2000-0223" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the wmcdplay CD player program for the WindowMaker desktop allows local users to gain root privileges via a long parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1047">BID 1047</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=20000311143230.4C0C01EE8B@lists.securityfocus.com">20000311 TESO advisory -- wmcdplay</ref><ref source="TESO" url="http://teso.scene.at/advisories.php3">wmcdplay</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4185.php">wmcdplay-bo(4185)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0107.html">20000311 TESO advisory -- wmcdplay</ref><ref source="BID" url="http://www.securityfocus.com/bid/1047">1047</ref></refs><vuln_soft><prod name="wmcdplay" vendor="Sam Hawker"><vers num="1.0 Beta2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0224" published="2000-02-15" seq="2000-0224" severity="Low" type="CVE"><desc><descript source="cve">ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/988">BID 988</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3991.php">sco-openserver-arc-symlink(3991)</ref><ref adv="1" patch="1" source="SCO Bulletins" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.07a">SCO Security Bulletin 2000.07</ref><ref source="NAI" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-02-15&amp;msg=000101bf78af$94528870$4d2f45a1@jmagdych.na.nai.com">20000215 ARCserve symlink vulnerability</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.1.1"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0225" published="2000-03-07" seq="2000-0225" severity="Medium" type="CVE"><desc><descript source="cve">The Pocsag POC32 program does not properly prevent remote users from accessing its server port, even if the option has been disabled.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1032">bugtraq id 1032</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D003601bf854b%246893a090%240100a8c0@FIREWALKER">Pocsag remote access to client can&apos;t be disabled</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=003601bf854b$6893a090$0100a8c0@FIREWALKER">20000303 Pocsag remote access to client can&apos;t be disabled.</ref><ref source="OSVDB" url="http://www.osvdb.org/259">259</ref></refs><vuln_soft><prod name="POC32" vendor="Deti Fliegl"><vers num="2.05"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0226" published="2000-03-20" seq="2000-0226" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.0 allows attackers to cause a denial of service by requesting a large buffer in a POST or PUT command which consumes memory, aka the &quot;Chunked Transfer Encoding Buffer Overflow Vulnerability.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4117.php">iis-chunked-encoding-dos(4117)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1066">BID 1066</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-018.asp">MS00-018</ref><ref source="BID" url="http://www.securityfocus.com/bid/1066">1066</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0227" published="2000-03-23" seq="2000-0227" severity="Low" type="CVE"><desc><descript source="cve">The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max paremeter, which allows local users to cause a denial of service by requesting a large number of sockets.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000323175509.A23709@clearway.com"> Local Denial-of-Service attack against Linux</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0254.html">20000323 Local Denial-of-Service attack against Linux</ref><ref source="BID" url="http://www.securityfocus.com/bid/1072">1072</ref><ref source="XF" url="http://xforce.iss.net/static/4186.php">linux-domain-socket-dos(4186)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95421263519558&amp;w=2">20000328 Re: Local Denial-of-Service attack against Linux</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2.12"/><vers num="2.2.14"/><vers num="2.3.99 pre2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0228" published="2000-03-17" seq="2000-0228" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows Media License Manager allows remote attackers to cause a denial of service by sending a malformed request that causes the manager to halt, aka the &quot;Malformed Media License Request&quot; Vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4108.php">mwmt-malformed-media-license(4108)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1058">BID 1058</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-016.asp">MS00-016</ref><ref source="BID" url="http://www.securityfocus.com/bid/1058">1058</ref></refs><vuln_soft><prod name="Windows Media License Manager" vendor="Microsoft"><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0229" published="2000-03-22" seq="2000-0229" severity="High" type="CVE"><desc><descript source="cve">gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4151.php">linux-gpm-root(4151)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1069">BID 1069</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000322182143.4498.qmail@securityfocus.com">gpm-root,SUSE</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000009-02.html">RHSA-2000:009-02</ref><ref adv="1" patch="1" source="Turbo Linux" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-May/000010.html">RHSA-2000:009-02</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0242.html">20000322 gpm-root</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_45.html">20000405 Security hole in gpm &lt; 1.18.1</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-009.html">RHSA-2000:009</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-045.html">RHSA-2000:045</ref><ref source="BID" url="http://www.securityfocus.com/bid/1069">1069</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.2"/><vers edition="i386" num="6.1"/><vers edition="i386" num="6.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/></prod><prod name="gpm" vendor="Alessandro Rubini"><vers num="1.19"/><vers num="1.18.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2 pre potato"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0230" published="2000-03-13" seq="2000-0230" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in imwheel allows local users to gain root privileges via the imwheel-solo script and a long HOME environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4201.php">linux-imwheel-bo(4201)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1060">BID 1060</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-03-15&amp;msg=Pine.LNX.3.96.1000316143702.257C-200000@ati12.cs.uni-potsdam.de">TESO &amp; C-Skills development advisory</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000016-02.html">RHSA-2000:016-02</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0168.html">20000316 TESO &amp; C-Skills development advisory -- imwheel</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-016.html">RHSA-2000:016</ref><ref source="BID" url="http://www.securityfocus.com/bid/1060">1060</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/><vers num="6.1"/></prod><prod name="Halloween Linux" vendor="Halloween"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0231" published="2000-03-16" seq="2000-0231" severity="High" type="CVE"><desc><descript source="cve">Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4124.php">linux-kreatecd-path(4124)</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1061">BID 1061</ref><ref adv="1" patch="1" source="SuSE" url="http://www.suse.de/de/support/security/suse_security_announce_46.txt">Security hole in kreatec</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0162.html">20000316 &quot;TESO &amp; C-Skills development advisory -- kreatecd&quot; at:</ref><ref source="BID" url="http://www.securityfocus.com/bid/1061">1061</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Halloween Linux" vendor="Halloween"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0232" published="2000-03-30" seq="2000-0232" severity="Low" type="CVE"><desc><descript source="cve">Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a malformed TCP/IP print request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4203.php">win-tcpip-printing-dos(4203)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1082">BID 1082</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-021.asp">MS00-021</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0306.html">20000330 Remote DoS Attack in Windows 2000/NT 4.0 TCP/IP Print Request Server Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1082">1082</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Terminal Server" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0233" published="2000-03-15" seq="2000-0233" severity="High" type="CVE"><desc><descript source="cve">SuSE Linux IMAP server allows remote attackers to bypass IMAP authentication and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SuSE" url="http://lists.suse.com/archives/suse-security/2000-Mar/0116.html">SuSE Linux IMAP Server</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4166.php">linux-imap-remote-unauthorized-access(4166)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1277">BID 1277</ref><ref source="SUSE" url="http://archives.neohapsis.com/archives/vendor/2000-q1/0035.html">20000327 Security hole in SuSE Linux IMAP Server</ref></refs><vuln_soft><prod name="SuSE Linux IMAP Server" vendor="SuSE"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2000-0234" published="2000-03-31" seq="2000-0234" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive contents of a .htaccess file.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4239.php">cobalt-raq-remote-access(4239)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1083">BID 1083</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/advisory.html%3Fid%3D2150">Cobalt-00-006: .htaccess</ref><ref source="CONFIRM" url="http://www.securityfocus.com/templates/advisory.html?id=2150">http://www.securityfocus.com/templates/advisory.html?id=2150</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000330220757.28456.qmail@securityfocus.com">20000330 Cobalt apache configuration exposes .htaccess</ref><ref source="BID" url="http://www.securityfocus.com/bid/1083">1083</ref></refs><vuln_soft><prod name="Cobalt RaQ" vendor="Sun"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0235" published="2000-03-27" seq="2000-0235" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the huh program in the orville-write package allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4242.php">freebsd-orvillewrite-bo(4242)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1070">BID 1070</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:10-orville-write.asc">FreeBSD-SA-00:1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1070">1070</ref><ref source="OSVDB" url="http://www.osvdb.org/1263">1263</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0236" published="2000-03-17" seq="2000-0236" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1063">BID 1063</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4116.php">netscape-server-directory-indexing(4116)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D38D2173D.24E39DD0@relaygroup.com">[SAFER 000317.EXP.1.5] Netscape Enterprise Server and &apos;?wp&apos; tags</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38D2173D.24E39DD0@relaygroup.com">20000317 [SAFER 000317.EXP.1.5] Netscape Enterprise Server and &apos;?wp&apos; tags</ref><ref source="BID" url="http://www.securityfocus.com/bid/1063">1063</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.6"/><vers num="3.51"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0237" published="2000-03-11" seq="2000-0237" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4202.php">netscape-webpublisher-invalid-access(4202)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1075">bugtraq id 1075</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-03-22%26msg%3D00032322073800.02176@ninja"> [zsh] Advisory : Netscape WebPublisher Allows Directory Listing and Access</ref><ref source="MISC" url="http://zsh.stupidphat.com/advisory.cgi?000311-1">http://zsh.stupidphat.com/advisory.cgi?000311-1</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.6"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0238" published="2000-03-17" seq="2000-0238" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the web server for Norton AntiVirus for Internet Email Gateways allows remote attackers to cause a denial of service via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1064">bugtraq id 1064</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Ds8d1f3e3.036@kib.co.kodiak.ak.us">DoS with NAVIEG</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-3.php-nav-email-gateway-dos">nav-email-gateway-dos</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=s8d1f3e3.036@kib.co.kodiak.ak.us">20000317 DoS with NAVIEG</ref></refs><vuln_soft><prod name="Norton AntiVirus" vendor="Symantec"><vers edition="Internet Email Gateways" num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0239" published="2000-03-15" seq="2000-0239" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="USSRLabs" url="http://www.ussrback.com/labs35.html">Local / Remote Multiples DoS Attacks in MERCUR v3.2* Vulnerability</ref><ref source="ISS X-Force" url="http://xforce.iss.net/static/4365.php">mercur-login-dos(4365)</ref><ref source="Atrium Software" url="http://www.atrium-software.com/pub/support_e.cfm">Product support</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95325335825295&amp;w=2">20000315 Local / Remote  DoS Attack in MERCUR WebView WebMail-Client 1.0</ref><ref source="BUGTRAQ" url="http://www.ussrback.com/labs36.html">20000315 Local / Remote  DoS Attack in MERCUR WebView WebMail-Client 1.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/1056">1056</ref></refs><vuln_soft><prod name="Mercur POP3 Server" vendor="Atrium Software"><vers num="3.20.01"/></prod><prod name="MERCUR Mailserver" vendor="Atrium Software"><vers num="3.2"/></prod><prod name="Mercur IMAP4 Server" vendor="Atrium Software"><vers num="3.20.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0240" published="2000-03-21" seq="2000-0240" severity="Medium" type="CVE"><desc><descript source="cve">vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1067">bugtraq id 1067</ref><ref patch="1" source="VQSoft" url="http://www.vqsoft.com/vq/server/index.html">Product site</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-3.php-vqserver-dir-traverse">vqserver-dir-traverse</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D4.1.20000321084646.0095c7f0@olga.swip.net">vqserver /........../</ref><ref source="CONFIRM" url="http://www.vqsoft.com/vq/server/faqs/dotdotbug.html">http://www.vqsoft.com/vq/server/faqs/dotdotbug.html</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.20000321084646.0095c7f0@olga.swip.net">20000321 vqserver /........../</ref><ref source="OSVDB" url="http://www.osvdb.org/270">270</ref></refs><vuln_soft><prod name="vqServer" vendor="vqSoft"><vers num="1.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0241" published="2000-03-21" seq="2000-0241" severity="Medium" type="CVE"><desc><descript source="cve">vqSoft vqServer stores sensitive information such as passwords in cleartext in the server.cfg file, which allows attackers to gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1068">bugtraq id 1068</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.20000321084646.0095c7f0@olga.swip.net">vqserver /........../</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-3.php-vqserver-passwd-plaintext">vqserver-passwd-plaintext</ref></refs><vuln_soft><prod name="vqServer" vendor="vqSoft"><vers num="1.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0242" published="2000-03-25" seq="2000-0242" severity="Medium" type="CVE"><desc><descript source="cve">WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-3.php-windmail-fileread">windmail-fileread</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-03-22%26msg%3D20000325224146.6839.qmail@securityfocus.com">Windmail allow web user get any file</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1073">BID 1073</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-03-22&amp;msg=20000325224146.6839.qmail@securityfocus.com">20000325 Windmail allow web user get any file</ref></refs><vuln_soft><prod name="WindMail" vendor="GeoCel"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2000-0243" published="2000-03-25" seq="2000-0243" severity="Medium" type="CVE"><desc><descript source="cve">AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1076">bugtraq id 1076</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-3.php-simpleserver-exception-dos">simpleserver-exception-dos</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dweb-5645555@post2.rnci.com"> AnalogX SimpleServer 1.03 Remote Crash</ref><ref source="MISC" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=web-5645555@post2.rnci.com">20000324 AnalogX SimpleServer 1.03 Remote Crash&quot; at: </ref><ref source="XF" url="http://xforce.iss.net/static/4189.php">simpleserver-exception-dos(4189)</ref><ref source="OSVDB" url="http://www.osvdb.org/1265">1265</ref></refs><vuln_soft><prod name="SimpleServer" vendor="AnalogX"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0244" published="2000-03-29" seq="2000-0244" severity="High" type="CVE"><desc><descript source="cve">The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4216.php">citrix-encryption(4216)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1077">bugtraq id 1077</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.BSO.4.20.0003290949280.2640-100000@naughty.monkey.org">Citrix ICA Basic Encryption</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSO.4.20.0003290949280.2640-100000@naughty.monkey.org">20000328 Citrix ICA Basic Encryption</ref></refs><vuln_soft><prod name="WinFrame" vendor="Citrix"><vers num="3.5 1.8 for Windows NT"/></prod><prod name="MetaFrame" vendor="Citrix"><vers edition="Unix" num="1.0"/><vers edition="Windows 2000" num="1.8" prev="1"/><vers edition="Windows NT 4.0 TSE" num="1.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0245" published="2000-03-27" seq="2000-0245" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4206.php">irix-objectserver-create-accounts(4206)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1079">BID 1079</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200003290852.aa27218@blaze.arl.mil">Objectserver vulnerability</ref><ref source="SGI" url="ftp://sgigate.sgi.com/security/20000303-01-PX">20000303-01-PX</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/k-030.shtml">K-030</ref><ref source="BID" url="http://www.securityfocus.com/bid/1079">1079</ref><ref source="OSVDB" url="http://www.osvdb.org/1267">1267</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4206">irix-objectserver-create-accounts(4206)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-0246" published="2000-03-30" seq="2000-0246" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the &quot;Virtualized UNC Share&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4204.php">iis-virtual-unc-share</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1081">BID 1081</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-019.asp">MS00-019</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=249599">Q249599</ref><ref source="BID" url="http://www.securityfocus.com/bid/1081">1081</ref></refs><vuln_soft><prod name="proxy server" vendor="Microsoft"><vers num="2.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod><prod name="Commercial Internet System" vendor="Microsoft"><vers num="2.5"/><vers num="2.0"/></prod><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/><vers num="Commerce 3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2000-0247" published="2000-03-22" seq="2000-0247" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in Generic-NQS (GNQS) allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref source="MISC" url="http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt">http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0236.html">Local root compromise in GNQS 3.50.6 and 3.50.7</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/4306">Generic NQS local root</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1842">GNQS Root Access Vulnerability</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:13.generic-nqs.asc">FreeBSD-SA-00:13</ref></refs><vuln_soft><prod name="GNQS" vendor="GNQS"><vers num="3.50.6"/><vers num="3.50.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2000-0248" published="2000-04-24" seq="2000-0248" severity="High" type="CVE"><desc><descript source="cve">The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise46.php3">Backdoor Password in Red Hat Linux Virtual Server Package</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1148">BID1148</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DEnip.BSO.23.0004241601140.28851-100000@www.whitehats.com">piranha default password/exploit</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0249" published="2000-04-26" seq="2000-0249" severity="High" type="CVE"><desc><descript source="cve">The AIX Fast Response Cache Accelerator (FRCA) allows local users to modify arbitrary files via the configuration capability in the frcactrl program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bin/1152">BID 1152</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3926.php">aix-frcactrl(3926)</ref><ref adv="1" patch="1" source="ISS Security Advisory" url="http://www-1.ibm.com/services/continuity/recover1.nsf/advisories/8525680F006B9445852568CE0055C78A/$file/oar075.txt">Insecure file handling in IBM AIX frcactrl program</ref><ref source="ISS" url="http://xforce.iss.net/alerts/advise47.php3">20000426 Insecure file handling in IBM AIX frcactrl program</ref><ref source="BID" url="http://www.securityfocus.com/bid/1152">1152</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-0250" published="2000-04-14" seq="2000-0250" severity="High" type="CVE"><desc><descript source="cve">The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/1114">BID 1114</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0072.html">qnx crypt comprimised</ref><ref source="ISS X-Force" url="http://xforce.iss.net/static/4866.php">qnx-weak-encryption(4866)</ref></refs><vuln_soft><prod name="QNX" vendor="QNX"><vers num="4.25A"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0251" published="2000-04-06" seq="2000-0251" severity="Medium" type="CVE"><desc><descript source="cve">HP-UX 11.04 VirtualVault (VVOS) sends data to unprivileged processes via an interface that has multiple aliased IP addresses.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1090">BID 1090</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4237.php">hp-virtual-vault(4237)</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.10002250826310.13536-100000@nef.esiea.fr">RE: [fw-wiz] Re: Anti-Defacement Products...</ref><ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0021.html">HPSBUX0004-112</ref><ref source="BID" url="http://www.securityfocus.com/bid/1090">1090</ref></refs><vuln_soft><prod name="VVOS" vendor="HP"><vers num="3.50"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0252" published="2000-04-11" seq="2000-0252" severity="Medium" type="CVE"><desc><descript source="cve">The dansie shopping cart application cart.pl allows remote attackers to execute commands via a shell metacharacters in a form variable.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1115">BID 1115</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.GSO.4.05.10004141056510.8165-100000@los-angeles.mtvnodn.com"> more problems with that POS dansie cart software!</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0051.html">Back Door in Commercial Shopping Cart</ref><ref source="XF" url="http://xforce.iss.net/static/4975.php">dansie-shell-metacharacters</ref></refs><vuln_soft><prod name="Dansie Shopping Cart" vendor="Craig Dansie"><vers num="3.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0253" published="2000-04-11" seq="2000-0253" severity="High" type="CVE"><desc><descript source="cve">The dansie shopping cart application cart.pl allows remote attackers to modify sensitive purchase information via hidden form fields.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4621.php">shopping-cart-form-tampering(4621)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1115">BID 1115</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise42.php">Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications</ref></refs><vuln_soft><prod name="Dansie Shopping Cart" vendor="Craig Dansie"><vers num="3.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0254" published="2000-04-14" seq="2000-0254" severity="Medium" type="CVE"><desc><descript source="cve">The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configuration information via a URL that references either the env, db, or vars form variables.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1115">BID 1115</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4954.php">dansie-form-variables(4954)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0088.html">Re: more problems with that POS dansie cart software!</ref></refs><vuln_soft><prod name="Dansie Shopping Cart" vendor="Craig Dansie"><vers num="3.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0255" published="2000-04-05" seq="2000-0255" severity="Medium" type="CVE"><desc><descript source="cve">The Nbase-Xyplex EdgeBlaster router allows remote attackers to cause a denial of service via a scan for the FormMail CGI program.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1091">BID 1091</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0022.html">SilverBack Security Advisory: Nbase-Xyplex DoS</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4236.php">nbase-xyplex-router(4236)</ref></refs><vuln_soft><prod name="EdgeBlaster" vendor="NBase-Xyplex"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0256" published="2000-04-19" seq="2000-0256" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the &quot;Server-Side Image Map Components&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1117">BID 1117</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-028.asp">Microsoft Security Bulletin (MS00-028)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4484.php">frontpage-ext-image-map(4484)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470458/100/0/threaded">20070603 CERN &amp;#304;mage Map Dispatcher</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/34720">frontpage-cern-bo(34720)</ref></refs><vuln_soft><prod name="NT Option Pack" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Frontpage" vendor="Microsoft"><vers num=""/></prod><prod name="Personal Web Server" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0257" published="2000-04-19" seq="2000-0257" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the NetWare remote web administration utility allows remote attackers to cause a denial of service or execute commands via a long URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1118">BID 1118</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0004171825340.10088-100000@nimue.tpi.pl">Novell Netware 5.1 (server 5.00h, Dec 11, 1999)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4310.php">netware-remote-admin-overflow(4310)</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0258" published="2000-04-12" seq="2000-0258" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.0 and 5.0 allows remote attackers to cause a denial of service by sending many URLs with a large number of escaped characters, aka the &quot;Myriad Escaped Characters&quot; Vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-023.asp">MS00-023</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1101">BID 1101</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4279.php">iis-myriad-escape-chars(4279)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1101">1101</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0259" published="2000-04-12" seq="2000-0259" severity="High" type="CVE"><desc><descript source="cve">The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4332.php">winnt-cryptkeys-compromise(4332)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1105">BID 1105</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-024.asp">Microsoft Security Bulletin (MS00-024)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Terminal Server" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0260" published="2000-04-14" seq="2000-0260" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or execute commands, aka the &quot;Link View Server-Side Component&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1109">BID 1109</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-025.asp">MS00-025</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4333.php">frontpage-ext-dvwssr-bo(4333)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1109">1109</ref><ref source="OSVDB" url="http://www.osvdb.org/282">282</ref></refs><vuln_soft><prod name="InterDev" vendor="Microsoft"><vers num="1.0"/></prod><prod name="FrontPage" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0261" published="2000-04-12" seq="2000-0261" severity="Medium" type="CVE"><desc><descript source="cve">The AVM KEN! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1103">BID 1103</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4303.php">ken-download-files(4303)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D385866587.955805213719.JavaMail.root@web32.pub01">AVM&apos;s Statement</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html">20000415 (no subject)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com">20000418 AVM&apos;s Statement</ref><ref source="BID" url="http://www.securityfocus.com/bid/1103">1103</ref><ref source="OSVDB" url="http://www.osvdb.org/1282">1282</ref></refs><vuln_soft><prod name="KEN" vendor="AVM"><vers num="1.4.30"/><vers num="1.3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0262" published="2000-04-12" seq="2000-0262" severity="Medium" type="CVE"><desc><descript source="cve">The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1103">BID 1103</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4301.php">ken-dos(4301)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D385866587.955805213719.JavaMail.root@web32.pub01">AVM&apos;s Statement</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0073.html">20000415 (no subject)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=383085010.956159226625.JavaMail.root@web305-mc.mail.com">20000418 AVM&apos;s Statement</ref><ref source="BID" url="http://www.securityfocus.com/bid/1103">1103</ref></refs><vuln_soft><prod name="KEN" vendor="AVM"><vers num="1.4.30"/><vers num="1.3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0263" published="2000-04-16" seq="2000-0263" severity="Low" type="CVE"><desc><descript source="cve">The X font server xfs in Red Hat Linux 6.x allows an attacker to cause a denial of service via a malformed request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1111">BID 1111</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0079.html">xfs</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4305.php">redhat-fontserver-dos(4305)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/><vers edition="Sparc" num="6.0"/><vers edition="i386" num="6.0"/><vers edition="Alpha" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0264" published="2000-04-17" seq="2000-0264" severity="Low" type="CVE"><desc><descript source="cve">Panda Security 3.0 with registry editing disabled allows users to edit the registry and gain privileges by directly executing a .reg file or using other methods.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1119">BID 1119</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4334.php">panda-admin-privileges(4334)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-04-22%26msg%3D38FB45F2.550EA000@teleline.es">bugs in Panda Security 3.0</ref><ref source="CONFIRM" url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es">20000417 bugs in Panda Security 3.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/1119">1119</ref></refs><vuln_soft><prod name="Panda Security" vendor="Panda"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0265" published="2000-04-17" seq="2000-0265" severity="Medium" type="CVE"><desc><descript source="cve">Panda Security 3.0 allows users to uninstall the Panda software via its Add/Remove Programs applet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4865.php">panda-uninstall-program(4865)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1119">BID 1119</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FB45F2.550EA000@teleline.es">bugs in Panda Security 3.0</ref><ref source="CONFIRM" url="http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip">http://updates.pandasoftware.com/docs/us/Avoidvulnerability.zip</ref></refs><vuln_soft><prod name="Panda Security" vendor="Panda"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0266" published="2000-04-18" seq="2000-0266" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4387.php">ie-java-crossframe-security(4387)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D38FC6130.D6D178FD@nat.bg"> IE 5 security vulnerablity - circumventing Cross-frame security policy using Java/JavaScript (and disabling Active Scripting is not that easy)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-05-01%26msg%3D39044009.7F640BDB@nat.bg"> Re: IE 5 security vulnerablity - circumventing Cross-framesecurity policy using Java/JavaScript (and disabling ActiveScripting is not that easy)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1121">1121</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=38FC6130.D6D178FD@nat.bg">20000418 IE 5 security vulnerablity - circumventing Cross-frame security policy using Java/JavaScript (and disabling Active Scripting is not that easy)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0267" published="2000-04-20" seq="2000-0267" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Catalyst 5.4.x allows a user to gain access to the &quot;enable&quot; mode without a password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1122">BID 1122</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4313.php">cisco-catalyst-password-bypass(4313)</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/catos-enable-bypass-pub.shtml">Cisco Catalyst Enable Password Bypass Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1122">1122</ref><ref source="OSVDB" url="http://www.osvdb.org/1288">1288</ref></refs><vuln_soft><prod name="Catalyst 5500" vendor="Cisco"><vers num="5.4.1"/></prod><prod name="Catalyst 6500" vendor="Cisco"><vers num="5.4.1"/></prod><prod name="Catalyst 4000" vendor="Cisco"><vers num="5.4.1"/></prod><prod name="Catalyst 5000" vendor="Cisco"><vers num="5.4.1"/></prod><prod name="Catalyst 6000" vendor="Cisco"><vers num="5.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2000-0268" published="2000-04-20" seq="2000-0268" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1123">BID 1123</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/iostelnetopt-pub.shtml">Cisco IOS Software TELNET Option Handling Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4312.php">cisco-ios-option-handling(4312)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1123">1123</ref><ref source="OSVDB" url="http://www.osvdb.org/1289">1289</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0.7"/><vers num="12.0.6"/><vers num="12.0.5"/><vers num="12.0.4T"/><vers num="12.0.4S"/><vers num="12.0.4"/><vers num="12.0.3T2"/><vers num="12.0.2XG"/><vers num="12.0.2XF"/><vers num="12.0.2XD"/><vers num="12.0.2XC"/><vers num="12.0.2"/><vers num="11.3AA"/></prod><prod name="Cisco 7500 Router" vendor="Cisco"><vers num=""/></prod><prod name="Cisco 7200 Router" vendor="Cisco"><vers num=""/></prod><prod name="Cisco 7100 Router" vendor="Cisco"><vers num=""/></prod><prod name="System Controller" vendor="Cisco"><vers num="SC3640"/></prod><prod name="Access Server" vendor="Cisco"><vers num="AS5800"/><vers num="AS5300"/><vers num="AS5200"/></prod><prod name="Voice Gateway" vendor="Cisco"><vers num="AS5800"/></prod><prod name="Cisco 3660 Router" vendor="Cisco"><vers num=""/></prod><prod name="AccessPath" vendor="Cisco"><vers num="VS-3"/><vers num="TS-3"/><vers num="LS-3"/></prod><prod name="Cisco Cable Router" vendor="Cisco"><vers num="ubr7200"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0269" published="2000-04-18" seq="2000-0269" severity="Low" type="CVE"><desc><descript source="cve">Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php-emacs-local-eavesdrop">emacs-local-eavesdrop</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-04-15%26msg%3Dtg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de">RUS-CERT Advisory 200004-01: GNU Emacs 20</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-15&amp;msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de">20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1125">BID 1125</ref></refs><vuln_soft><prod name="GNU Emacs" vendor="Gnu"><vers num="20.6"/><vers num="20.5"/><vers num="20.4"/><vers num="20.3"/><vers num="20.2"/><vers num="20.1"/><vers num="20.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0270" published="2000-04-18" seq="2000-0270" severity="Low" type="CVE"><desc><descript source="cve">The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1126">BID 1126</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">emacs-tempfile-creation</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-04-15%26msg%3Dtg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de">RUS-CERT Advisory 200004-01: GNU Emacs 20</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-15&amp;msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de">20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20</ref></refs><vuln_soft><prod name="GNU Emacs" vendor="Gnu"><vers num="20.6"/><vers num="20.5"/><vers num="20.4"/><vers num="20.3"/><vers num="20.2"/><vers num="20.1"/><vers num="20.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0271" published="2000-04-18" seq="2000-0271" severity="Medium" type="CVE"><desc><descript source="cve">read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1125">BID 1125</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php-emacs-password-history">emacs-password-history</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-04-15%26msg%3Dtg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de">RUS-CERT Advisory 200004-01: GNU Emacs 20</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-15&amp;msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de">20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20</ref></refs><vuln_soft><prod name="GNU Emacs" vendor="Gnu"><vers num="20.6"/><vers num="20.5"/><vers num="20.4"/><vers num="20.3"/><vers num="20.2"/><vers num="20.1"/><vers num="20.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2000-0272" published="2000-04-20" seq="2000-0272" severity="High" type="CVE"><desc><descript source="cve">RealNetworks RealServer allows remote attackers to cause a denial of service by sending malformed input to the server at port 7070.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4400.php">realserver-remote-dos(4400)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1128">bugtraq id 1128</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95625288231045&amp;w=2">Remote DoS attack in Real Networks Real Server Vulnerability</ref><ref source="CONFIRM" url="http://service.real.com/help/faq/servg270.html">http://service.real.com/help/faq/servg270.html</ref></refs><vuln_soft><prod name="RealServer" vendor="RealNetworks"><vers num="7.0"/><vers num="Pro"/><vers num="Intranet"/><vers num="Plus"/><vers num="Basic"/><vers num="G2 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0273" published="2000-04-09" seq="2000-0273" severity="Medium" type="CVE"><desc><descript source="cve">PCAnywhere allows remote attackers to cause a denial of service by terminating the connection before PCAnywhere provides a login prompt.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1095">BID 1095</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php-pcanywhere-login-dos">pcanywhere-login-dos</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0031.html">A funny way to DOS pcANYWHERE8.0 and 9.0</ref></refs><vuln_soft><prod name="PCAnywhere" vendor="Symantec"><vers num="9.0"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0274" published="2000-04-10" seq="2000-0274" severity="Low" type="CVE"><desc><descript source="cve">The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1096">BID 1096</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4243.php">linux-trustees-patch-dos(4243)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000410142058.W19474@univ.uniyar.ac.ru">linux trustees 1.5 long path name vulnerability</ref><ref source="CONFIRM" url="http://www.braysystems.com/linux/trustees.html">http://www.braysystems.com/linux/trustees.html</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0035.html">20000410 linux trustees 1.5 long path name vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1096">1096</ref></refs><vuln_soft><prod name="Linux Trustees" vendor="Bray Systems"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0275" published="2000-04-10" seq="2000-0275" severity="Low" type="CVE"><desc><descript source="cve">CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user&apos;s PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4300.php">cryptoadmin-weak-encryption(4300)</ref><ref adv="1" source="lOpht" url="http://www.l0pht.com/advisories/cc-pinextract.txt">CRYPTOCard PalmToken PIN Extraction</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0033.html">20000410 CRYPTOAdmin 4.1 server with PalmPilot PT-1 token 1.04 PIN Extract ion</ref><ref source="BID" url="http://www.securityfocus.com/bid/1097">1097</ref></refs><vuln_soft><prod name="CRYPTOAdmin" vendor="CRYPTOCard"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0276" published="2000-04-10" seq="2000-0276" severity="Low" type="CVE"><desc><descript source="cve">BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1098">bugtraq id 1098</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000410131628.659.qmail@securityfocus.com">BeOS syscall bug</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">beos-syscall-dos</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000410131628.659.qmail@securityfocus.com">20000410 BeOS syscall bug</ref></refs><vuln_soft><prod name="BeOS" vendor="Be"><vers num="5.0"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0277" published="2000-04-03" seq="2000-0277" severity="High" type="CVE"><desc><descript source="cve">Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the &quot;XLM Text Macro&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1087">BID 1087</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-022.asp">MS00-022</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4224.php">excel-xlm(4224)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1087">1087</ref><ref source="OSVDB" url="http://www.osvdb.org/1272">1272</ref></refs><vuln_soft><prod name="Excel" vendor="Microsoft"><vers num="97"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0278" published="2000-08-03" seq="2000-0278" severity="Medium" type="CVE"><desc><descript source="cve">The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1089">BID 1089</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D38E547DA.2504A2AB@internetworking.com"> SalesLogix Eviewer Web App Bug: URL request crashes eviewer web application</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4217.php">eviewer-admin-request-dos(4217)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0006.html">20000331 SalesLogix Eviewer Web App Bug: URL request crashes eviewer web application</ref></refs><vuln_soft><prod name="Corporation eViewer" vendor="SalesLogix"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-24" name="CVE-2000-0279" published="2000-04-07" seq="2000-0279" severity="Medium" type="CVE"><desc><descript source="cve">BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the length of the headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1100">BID 1100</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4277.php">beos-networking-dos(4277)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dm12dhV0-000W5EC@malasada.lava.net">BeOS Networking DOS</ref><ref source="" url="http://bebugs.be.com/devbugs/detail.php3?oid=2505312"></ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0029.html">20000407 BeOS Networking DOS</ref><ref source="BID" url="http://www.securityfocus.com/bid/1100">1100</ref></refs><vuln_soft><prod name="BeOS" vendor="Be"><vers num="5.0"/><vers num="4.5"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2000-0280" published="2000-04-03" seq="2000-0280" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0018.html">Win32 RealPlayer 6/7 Buffer Overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1088">BID 1088</ref></refs><vuln_soft><prod name="RealPlayer" vendor="RealNetworks"><vers edition="Win" num="7.0"/><vers edition="Win" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0281" published="2000-03-26" seq="2000-0281" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0299.html">Napster, Inc. response to Colten Edwards</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0277.html">neat little napster bug</ref></refs><vuln_soft><prod name="Napster client" vendor="Napster"><vers num="beta 5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0282" published="2000-04-12" seq="2000-0282" severity="Medium" type="CVE"><desc><descript source="cve">TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a .. (dot dot) attack on the webplus CGI program.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1102">bugtraq id 1102</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0050.html">TalentSoft Web+ Input Validation Bug Vulnerability</ref><ref adv="1" patch="1" source="TalentSoft" url="ftp://ftp.talentsoft.com/Download/Webplus/Unix/webplus46p%20Read%20me.html">Security update</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4282.php">talentsoft-web-input(4282)</ref><ref source="CONFIRM" url="ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html">ftp://ftp.talentsoft.com/Download/Webplus/Unix/Patches/Webplus46p%20Read%20me.html</ref></refs><vuln_soft><prod name="Web+" vendor="TalentSoft"><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0283" published="2000-04-12" seq="2000-0283" severity="Medium" type="CVE"><desc><descript source="cve">The default installation of IRIX Performance Copilot allows remote attackers to access sensitive system information via the pmcd daemon.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4283.php">irix-pmcd-info(4283)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1106">bugtraq id 1106</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html">Performance Copilot for IRIX 6.5</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.6"/><vers num="6.5.4"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0284" published="2000-04-16" seq="2000-0284" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1110">bugtraq id 1110</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4338.php">imap-mailserver-bo(4338)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0074.html">imapd4r1 v12.264</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0085.html">20000416 imapd4r1 v12.264</ref></refs><vuln_soft><prod name="IMAP" vendor="University of Washington"><vers num="12.264"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0285" published="2000-04-16" seq="2000-0285" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4867.php">xfree86-xkbmap-parameter-bo(4867)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0076.html">XFree86 server overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/1306">1306</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.0"/><vers num="3.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0286" published="2000-04-16" seq="2000-0286" severity="Low" type="CVE"><desc><descript source="cve">X fontserver xfs allows local users to cause a denial of service via malformed input to the server.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1111">bugtraq id 1111</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4305.php">redhat-fontserver-dos(4305)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10004161525040.1186-200000@localhost"> xfs</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0079.html">20000416 xfs</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/><vers edition="Sparc" num="6.0"/><vers edition="i386" num="6.0"/><vers edition="Alpha" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0287" published="2000-04-12" seq="2000-0287" severity="High" type="CVE"><desc><descript source="cve">The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the dbname parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4246.php">http-cgi-bizdb(4246)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1104">bugtraq id 1104</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0058.htm">BizDB Search Script Enables Shell Command Execution at the Server</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0058.html">20000412 BizDB Search Script Enables Shell Command Execution at the Server</ref></refs><vuln_soft><prod name="Technology BizDB" vendor="CNC"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0288" published="2000-04-12" seq="2000-0288" severity="Medium" type="CVE"><desc><descript source="cve">Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/static/4289.php">http-cgi-infonautics-getdoc(4289)</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0049.html">Infonautic&apos;s getdoc.cgi may allow unauthorized access to documents</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0289" published="2000-03-27" seq="2000-0289" severity="Medium" type="CVE"><desc><descript source="cve">IP masquerading in Linux 2.2.x allows remote attackers to route UDP packets through the internal interface by modifying the external source IP address and port number to match those of an established connection.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1078">BID 1078</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4233.php">linux-ip-masquerading(4233)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-03/0284.html">Security Problems with Linux 2.2.x IP Masquerading</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_48.html">20000520 Security hole in kernel &lt; 2.2.15</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/><vers edition="Sparc" num="6.0"/><vers edition="i386" num="6.0"/><vers edition="Alpha" num="6.0"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.2.14"/><vers num="2.2.12"/><vers num="2.2.10"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2 pre potato"/><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-21" name="CVE-2000-0290" published="2000-03-31" seq="2000-0290" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Webstar HTTP server allows remote attackers to cause a denial of service via a long GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0005.html">Webstar 4.0 Buffer overflow vulnerability</ref><ref source="" url="http://xforce.iss.net/xforce/xfdb/4792"></ref><ref source="XF" url="http://xforce.iss.net/static/4792.php">macos-webstar-get-bo(4792)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1822">1822</ref></refs><vuln_soft><prod name="Webstar HTTP server" vendor="4D"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0291" published="2000-04-16" seq="2000-0291" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1112">bugtraq id 1112</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4304.php">staroffice-long-url-bo(4304)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0077.html">StarOffice 5.1</ref></refs><vuln_soft><prod name="StarOffice" vendor="Sun"><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0292" published="2000-04-19" seq="2000-0292" severity="Medium" type="CVE"><desc><descript source="cve">The Adtran MX2800 M13 Multiplexer allows remote attackers to cause a denial of service via a ping flood to the Ethernet interface, which causes the device to crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">adtran-ping-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1129">bugtraq id 1129</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10004190908140.32750-100000@localhost.localdomain">Adtran DoS</ref></refs><vuln_soft><prod name="MX2800" vendor="AdTran"><vers num="M13"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0293" published="2000-05-02" seq="2000-0293" severity="Low" type="CVE"><desc><descript source="cve">aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/1130">BID 1130</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-5.php">aaabase-file-deletion</ref><ref adv="1" patch="1" source="SuSe" url="http://www.suse.de/de/support/security/suse_security_announce_47.txt">SuSE Security Announcement</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1 alpha"/><vers num="6.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0294" published="2000-04-10" seq="2000-0294" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in healthd for FreeBSD allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1107">BID 1107</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4281.php">freebsd-healthd(4281)</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:12-healthd.asc">FreeBSD-SA-00:12</ref><ref source="FREEBSD" url="http://www.securityfocus.com/templates/advisory.html?id=2162">FreeBSD-SA-00:12</ref><ref source="BID" url="http://www.securityfocus.com/bid/1107">1107</ref><ref source="OSVDB" url="http://www.osvdb.org/606">606</ref></refs><vuln_soft><prod name="healthd" vendor="Jim Housley"><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0295" published="2000-04-21" seq="2000-0295" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1131">bugtraq id 1131</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4315.php">lcdproc-remote-overflow(4315)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000421010946.15318I-200000@schizo.strange.net"> Remote vulnerability in LCDproc 0.4</ref><ref source="GENTOO" url="http://www.securityfocus.com/archive/1/archive/1/305589/30/26390/threaded">GLSA-200301-07</ref><ref source="SECUNIA" url="http://secunia.com/advisories/7829">7829</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4315">lcdproc-remote-overflow(4315)</ref></refs><vuln_soft><prod name="LCDProc" vendor="LCDProc"><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0296" published="2000-03-31" seq="2000-0296" severity="High" type="CVE"><desc><descript source="cve">fcheck allows local users to gain privileges by embedding shell metacharacters into file names that are processed by fcheck.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1086">bugtraq id 1086</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.BSI.4.05L.10003311803200.12106-200000@zoom1.telepath.com"> fcheck v.2.7.45 and insecure use of Perl&apos;s system()</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/current/0011.html">20000331 fcheck v.2.7.45 and insecure use of Perl&apos;s system()</ref></refs><vuln_soft><prod name="Fcheck" vendor="Michael A. Gumienny"><vers num="2.7.45"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0297" published="2000-04-03" seq="2000-0297" severity="Medium" type="CVE"><desc><descript source="cve">Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1085">BID 1085</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4226.php">allaire-forums-allaccess(4226)</ref><ref adv="1" patch="1" source="Allaire Security Advisory" url="http://www.allaire.com/handlers/index.cfm?ID=15099&amp;Method=Full">Allaire Security Bulletin (ASB00-06)</ref><ref source="ALLAIRE" url="http://www2.allaire.com/handlers/index.cfm?ID=15099&amp;Method=Full">ASB00-06</ref><ref source="BID" url="http://www.securityfocus.com/bid/1085">1085</ref><ref source="OSVDB" url="http://www.osvdb.org/1270">1270</ref></refs><vuln_soft><prod name="Forums" vendor="Allaire"><vers num="2.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0298" published="2000-04-07" seq="2000-0298" severity="High" type="CVE"><desc><descript source="cve">The unattended installation of Windows 2000 with the OEMPreinstall option sets insecure permissions for the All Users and Default Users directories.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">win2k-unattended-install</ref><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0004&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=1606">All Users startup folder left open if unattended install and OEMP reinstall=1</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0027.html">20000407 All Users startup folder left open if unattended install and OEMP reinstall=1</ref><ref source="XF" url="http://xforce.iss.net/static/4278.php">win2k-unattended-install(4278)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1758">1758</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0299" published="2000-04-04" seq="2000-0299" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">webobjects-post-dos</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-04-01&amp;msg=OCELLGABDLDELPDEFKNACELGCBAA.gdead@fortnocs.com">WebObjects DoS</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0020.html">20000404 WebObjects DoS</ref></refs><vuln_soft><prod name="WebObjects" vendor="Apple"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0300" published="2000-04-06" seq="2000-0300" severity="High" type="CVE"><desc><descript source="cve">The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1093">bugtraq id 1093</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000406030958.23902.qmail@securityfocus.com">PcAnywhere weak password encryption</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4234.php">pcanywhere-weak-encryption(4234)</ref></refs><vuln_soft><prod name="PCAnywhere" vendor="Symantec"><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0301" published="2000-04-06" seq="2000-0301" severity="Medium" type="CVE"><desc><descript source="cve">Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1094">bugtraq id 1094</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4238.php">ipswitch-imail-dos(4238)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95505800117143&amp;w=2">Re: IMAIL (Ipswitch) DoS with Eudora (Qualcomm)</ref><ref adv="1" patch="1" source="IpSwitch" url="http://support.ipswitch.com/kb/IM-20000208-DM02.htm">IMail - SMTP login problem for Eudora</ref></refs><vuln_soft><prod name="Imail" vendor="Ipswitch"><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.0.8"/><vers num="5.0.7"/><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0302" published="2000-03-31" seq="2000-0302" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename in the CiWebHitsFile argument to the null.htw URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-006.asp">MS:MS00-006</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95453598317340&amp;w=2">Alert: MS Index Server (CISADV000330)</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/1084">BID 1084</ref><ref source="OSVDB" url="http://www.osvdb.org/271">271</ref></refs><vuln_soft><prod name="Index Server" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0303" published="2000-05-03" seq="2000-0303" severity="Medium" type="CVE"><desc><descript source="cve">Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Quake 3 Arena" url="http://www.quake3arena.com/news/index.html">Vulnerability in Quake3Arena Auto-Download</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1169">BID 1169</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise50.php">quake3-auto-download</ref><ref source="ISS" url="http://xforce.iss.net/alerts/advise50.php3">20000503 Vulnerability in Quake3Arena Auto-Download Feature</ref><ref source="BID" url="http://www.securityfocus.com/bid/1169">1169</ref><ref source="OSVDB" url="http://www.osvdb.org/7531">7531</ref></refs><vuln_soft><prod name="Quake 3 Arena" vendor="id Software"><vers num="1.16n"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0304" published="2000-05-10" seq="2000-0304" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the &quot;Undelimited .HTR Request&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1191">BID 1191</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-031.asp">MS00-031</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise52.php">20000511 Microsoft IIS Remote Denial of Service Attack</ref><ref source="ISS" url="http://xforce.iss.net/alerts/advise52.php3">20000511 Microsoft IIS Remote Denial of Service Attack</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx">MS00-031</ref><ref source="BID" url="http://www.securityfocus.com/bid/1191">1191</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0305" published="2000-05-19" seq="2000-0305" severity="Medium" type="CVE"><desc><descript source="cve">Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the &quot;IP Fragment Reassembly&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1236">BID 1236</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4518.php">ip-fragment-reassembly-dos(4518)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-029.asp">MS00-029</ref><ref source="BINDVIEW" url="http://www.securityfocus.com/templates/advisory.html?id=2240">20000519 jolt2 - Remote DoS against NT, W2K, 9x</ref><ref source="BID" url="http://www.securityfocus.com/bid/1236">1236</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="BeOS" vendor="Be"><vers num="5.0"/></prod><prod name="Terminal Server" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0306" published="2001-03-12" seq="2000-0306" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-12-29&amp;msg=AAh6GYsGU1@leshka.chuvashia.su">BUGTRAQ:19981229 Local/remote exploit for SCO UNIX.</ref><ref adv="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.02a">SB-99.02</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="5.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0307" published="2001-03-12" seq="2000-0307" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in xserver in SCO UnixWare 2.1.x and OpenServer 5.05 and earlier allows an attacker to cause a denial of service which prevents access to reserved port numbers below 1024.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.07b">Security Bulletin 99.07</ref></refs><vuln_soft><prod name="Open Desktop" vendor="SCO"><vers num=""/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.05" prev="1"/></prod><prod name="UnixWare" vendor="SCO"><vers num="2.1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0308" published="2001-03-12" seq="2000-0308" severity="High" type="CVE"><desc><descript source="cve">Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.08a"></ref></refs><vuln_soft><prod name="Netscape Proxy Server" vendor="Netscape"><vers num="2.5"/></prod><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="2.0"/></prod><prod name="UnixWare" vendor="SCO"><vers num="2.1.3" prev="1"/><vers num="7.0"/></prod><prod name="FastTrack" vendor="Netscape"><vers num="2.0"/><vers num="2.01"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0309" published="2001-03-12" seq="2000-0309" severity="Low" type="CVE"><desc><descript source="cve">The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata24.htmltrctrap">19990212 i386 trace-trap handling when DDB was configured could cause a system crash.</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata24.html#trctrap">19990212 i386 trace-trap handling when DDB was configured could cause a system crash.</ref><ref source="OSVDB" url="http://www.osvdb.org/6126">6126</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0310" published="2001-03-12" seq="2000-0310" severity="Medium" type="CVE"><desc><descript source="cve">IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata24.htmlmaxqueue">19990217 IP fragment assembly can bog the machine excessively and cause problems.</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata24.html#maxqueue">19990217 IP fragment assembly can bog the machine excessively and cause problems.</ref><ref source="OSVDB" url="http://www.osvdb.org/7539">7539</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0311" published="2000-04-20" seq="2000-0311" severity="Low" type="CVE"><desc><descript source="cve">The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the &quot;Mixed Object Access&quot; vulnerability.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4336.php">ms-mixed-object(4336)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1145">BID 1145</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-026.asp">MS00-026</ref><ref source="BID" url="http://www.securityfocus.com/bid/1145">1145</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0312" published="2001-03-12" seq="2000-0312" severity="High" type="CVE"><desc><descript source="cve">cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron&apos;s fake popen function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="OPENBSD" url="http://www.openbsd.org/errata25.html#cron">19990830 In cron(8), make sure argv[] is NULL terminated in the fake popen() and run sendmail as the user, not as root.</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0313" published="2001-03-12" seq="2000-0313" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref source="" url="http://www.openbsd.org/errata.htmlifmedia"></ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html#ifmedia">19991109 Any user can change interface media configurations.</ref><ref source="OSVDB" url="http://www.osvdb.org/7540">7540</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-25" name="CVE-2000-0314" published="2001-03-12" seq="2000-0314" severity="Medium" type="CVE"><desc><descript source="cve">traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91893782027835&amp;w=2">BUGTRAQ:19990213 traceroute as a flooder</ref><ref adv="1" patch="1" source="NetBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc">NetBSD-SA1999-004</ref><ref source="OSVDB" url="http://www.osvdb.org/7574">7574</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="2.0.34"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3" prev="1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0.34 kernel"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="2.0.34"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-25" name="CVE-2000-0315" published="2001-03-12" seq="2000-0315" severity="Medium" type="CVE"><desc><descript source="cve">traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91893782027835&amp;w=2">BUGTRAQ:19990213 traceroute as a flooder</ref><ref adv="1" patch="1" source="NetBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc">NetBSD-SA1999-004</ref><ref source="OSVDB" url="http://www.osvdb.org/7575">7575</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="2.0.34"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3" prev="1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0.34 kernel"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="2.0.34"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0316" published="2000-04-24" seq="2000-0316" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris 7 lp allows local users to gain root privileges via a long -d option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4361.php">solaris-lp-bo(4361)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1143">BID 1143</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.96.1000424151520.4813E-100000@carma.isirc.is">Re: Solaris 7 x86 lp exploit</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0191.html">20000424 Solaris 7 x86 lp exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/1143">1143</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0317" published="2000-04-24" seq="2000-0317" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0192.html">Solaris 7 x86 lpset exploit</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0236.html">Re: Solaris Sparc 2.6 &amp; 7 lp/lpset/lpstat root compromise exploit</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1138">bugtraaq id 1138</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">solaris-lpset-bo</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95729763119559&amp;w=2">20000427 Re: Solaris/SPARC 2.7 lpset exploit (well not likely !)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0318" published="2000-04-21" seq="2000-0318" severity="High" type="CVE"><desc><descript source="cve">Atrium Mercur Mail Server 3.2 allows local attackers to read other user&apos;s email and create arbitrary files via a dot dot (..) attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4368.php">mercur-remote-dot-attack(4368)</ref><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0004&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5261">Security problems with Atrium Mercur Mailserver 3.20</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1144">BID 1144</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0057.html">20000413 Security problems with Atrium Mercur Mailserver 3.20</ref></refs><vuln_soft><prod name="MERCUR Mailserver" vendor="Atrium Software"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0319" published="2000-04-23" seq="2000-0319" severity="Medium" type="CVE"><desc><descript source="cve">mail.local in Sendmail 8.10.x does not properly identify the .\n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 2047 characters long and ends in .\n.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0311.html">Re: [TL-Security-Announce] Linux Kernel TLSA2000013-1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1146">BID 1146</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4556.php">sendmail-maillocal-dos(4556)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=2694.000424@SECURITY.NNOV.RU">20000424 unsafe fgets() in sendmail&apos;s mail.local</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="5.58"/><vers num="5.59"/><vers num="8.6.x"/><vers num="8.7.x"/><vers num="8.7.1"/><vers num="8.7.2"/><vers num="8.7.3"/><vers num="8.7.4"/><vers num="8.7.5"/><vers num="8.7.6"/><vers num="8.8"/><vers num="8.8.x"/><vers num="8.8.1"/><vers num="8.8.2"/><vers num="8.8.3"/><vers num="8.8.4"/><vers num="8.8.5"/><vers num="8.9.1"/><vers num="8.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2000-0320" published="2000-04-21" seq="2000-0320" severity="Medium" type="CVE"><desc><descript source="cve">Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1133">BID 1133</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=9763.000421@SECURITY.NNOV.RU">unsafe fgets() in qpopper</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">qpopper-fgets-spoofing</ref></refs><vuln_soft><prod name="qpopper" vendor="Qualcomm"><vers num="3.0"/><vers num="2.53"/></prod><prod name="Cobalt RaQ" vendor="Sun"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0321" published="2000-04-24" seq="2000-0321" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in IC Radius package allows a remote attacker to cause a denial of service via a long user name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1147">BID 1147</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0190.html">Buffer Overflow in version .14</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">icradius-username-bo</ref></refs><vuln_soft><prod name="ICRADIUS" vendor="ICRadius"><vers num="0.14"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0322" published="2000-04-24" seq="2000-0322" severity="High" type="CVE"><desc><descript source="cve">The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execure arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1149">bugtraq id 1149</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">piranha-passwd-execute</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DEnip.BSO.23.0004241601140.28851-100000@www.whitehats.com">piranha default password/exploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Enip.BSO.23.0004241601140.28851-100000@www.whitehats.com">20000424 piranha default password/exploit</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-014.html">RHSA-2000:014</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2000-0323" published="1999-07-28" seq="2000-0323" severity="High" type="CVE"><desc><descript source="cve">The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the &quot;Text I-ISAM&quot; vulnerability. </descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-08-22%26msg%3D19990729195531.25108.qmail@underground.org">Alert : MS Office 97</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3156.php">jet-text-isam(3156)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/595">BID 595</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1999-08-22&amp;msg=19990729195531.25108.qmail@underground.org">19990728 Alert : MS Office 97 Vulnerability</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-030.asp">MS99-030</ref><ref source="BID" url="http://www.securityfocus.com/level2/?go=vulnerabilities&amp;id=595">595</ref></refs><vuln_soft><prod name="Jet" vendor="Microsoft"><vers num="4.0"/><vers num="3.51"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0324" published="2000-04-25" seq="2000-0324" severity="Medium" type="CVE"><desc><descript source="cve">pcAnywhere 8.x and 9.0 allows remote attackers to cause a denial of service via a TCP SYN scan, e.g. by nmap.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0258.html">20010212 Re: Symantec pcAnywhere 9.0 DoS / Buffer Overflow </ref><ref source="XF" url="http://www.iss.net/security_center/static/4347.php">pcanywhere-tcpsyn-dos(4347)</ref><ref source="OSVDB" url="http://www.osvdb.org/1301">1301</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1150">BID 1150</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000425150157.13567A-100000@sword.damocles.com">Denial of Service Against pcAnywhere.</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-4.php">pcanywhere-tcpsyn-dos</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0201.html">20010211 Symantec pcAnywhere 9.0 DoS / Buffer Overflow</ref></refs><vuln_soft><prod name="PCAnywhere" vendor="Symantec"><vers num="9.2"/><vers num="9.0"/><vers num="8.0.2"/><vers num="8.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0325" published="1999-08-20" seq="2000-0325" severity="High" type="CVE"><desc><descript source="cve">The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the &quot;VBA Shell&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-030.asp">Microsoft Security Program: Microsoft Security Bulletin (MS99-030)</ref><ref source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-7.php"></ref><ref source="XF" url="http://xforce.iss.net/static/3155.php">jet-vba-shell(3155)</ref><ref source="BID" url="http://www.securityfocus.com/bid/548">548</ref></refs><vuln_soft><prod name="Jet" vendor="Microsoft"><vers num="3.5"/><vers num="3.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0326" published="2000-04-25" seq="2000-0326" severity="Medium" type="CVE"><desc><descript source="cve">Meeting Maker uses weak encryption (a polyalphabetic substitution cipher) for passwords, which allows remote attackers to sniff and decrypt passwords for Meeting Maker accounts.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1151">BID 1151</ref><ref adv="1" source="ON Technology Support Center" url="http://support.on.com/support/mmxp.nsf/31af51e08bcc93eb852565a90056138b/11af70407a16b165852568c50056a952?OpenDocument">MEETING MAKER TECH NOTE</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0223.html">finding Meeting Maker passwords using tcpdump</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4348.php">meetingmaker-weak-encryption</ref></refs><vuln_soft><prod name="Meeting Maker" vendor="ON Technology"><vers num="6.0"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0327" published="1999-10-21" seq="2000-0327" severity="High" type="CVE"><desc><descript source="cve">Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the &quot;Virtual Machine Verifier&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3378.php">msvm-verifier-java(3378)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-045.asp">MS99-045</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/740">BID 740</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93993545118416&amp;w=2">19991014 Another Microsoft Java Flaw Disovered</ref></refs><vuln_soft><prod name="Virtual Machine" vendor="Microsoft"><vers num="3000"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2000-0328" published="1999-08-24" seq="2000-0328" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/139.php">tcp-seq-predict(139)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/604">BID 604</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-046.asp">MS99-046</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.19990824165629.00abcb40@192.168.124.1">19990824 NT Predictable Initial TCP Sequence numbers - changes observed with SP4</ref><ref source="BID" url="http://www.securityfocus.com/bid/604">604</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0329" published="1999-11-11" seq="2000-0329" severity="Medium" type="CVE"><desc><descript source="cve">A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the &quot;Active Setup Control&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3494.php">ie-active-setup-control(3494)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-048.asp">MS99-048</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/775">BID 775</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows NT 4.0" num="50"/><vers edition="Windows 98" num="5.0"/><vers edition="Windows 95" num="5.0"/><vers edition="Windows 2000" num="5.0"/><vers edition="Windows NT 4.0" num="4.1"/><vers edition="Windows 98" num="4.1"/><vers edition="Windows 95" num="4.1"/><vers edition="Windows NT" num="4.0.1"/><vers edition="Windows 98" num="4.0.1"/><vers edition="Windows 95" num="4.0.1"/><vers edition="Windows NT" num="4.0"/><vers edition="Windows 98" num="4.0"/><vers num="4.0"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="98"/><vers num="2000"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="5.0"/><vers num="4.72.3612.1700"/><vers num="4.72.3120"/><vers num="4.72.2106.4"/><vers num="4.27.3110.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0330" published="1999-11-12" seq="2000-0330" severity="High" type="CVE"><desc><descript source="cve">The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the &quot;File Access URL&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3492.php">win-fileurl-overflow(3492)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-049.asp">MS99-049</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/advisories/1863">Patch Available for &quot;File Access URL&quot; Vulnerability</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0331" published="2000-04-20" seq="2000-0331" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the &quot;Malformed Environment Variable&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4337.php">nt-cmd-overflow(4337)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1135">BID 1135</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-027.asp">MS00-027</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0147.html">20000421 CMD.EXE overflow (CISADV000420)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Terminal Server" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0332" published="2000-05-03" seq="2000-0332" severity="Medium" type="CVE"><desc><descript source="cve">UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1164">BID 1164</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000503091316.99073.qmail@hotmail.com">Fun with UltraBoard V1.6X</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4408.php">ultraboard-printabletopic-fileread</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000503091316.99073.qmail@hotmail.com">20000502 Fun with UltraBoard V1.6X</ref><ref source="OSVDB" url="http://www.osvdb.org/1309">1309</ref><ref source="OSVDB" url="http://www.osvdb.org/4065">4065</ref></refs><vuln_soft><prod name="UltraBoard" vendor="UltraScripts"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0333" published="1999-05-31" seq="2000-0333" severity="Medium" type="CVE"><desc><descript source="cve">tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1165">bugtraq id 1165</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4859.php">sniffer-dns-decode-dos</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.SOL.4.10.10005021942380.2077-100000@paranoia.pgci.ca">Denial of service attack against tcpdump</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.6"/><vers num="0.8.5"/><vers num="0.8.4"/></prod><prod name="tcpdump" vendor="LBL"><vers num="3.5a"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0334" published="2000-04-24" seq="2000-0334" severity="Low" type="CVE"><desc><descript source="cve">The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4555.php">allaire-spectra-container-editor-preview(4555)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1181">Bugtraq id 1181</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=15411&amp;Method=Full">Allaire Security Bulletin (ASB00-10)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1181">1181</ref></refs><vuln_soft><prod name="Spectra" vendor="Allaire"><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0335" published="2000-05-03" seq="2000-0335" severity="High" type="CVE"><desc><descript source="cve">The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1166">BID 1166</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4861.php">glibc-resolver-id-predictable</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000503034046.A9579@nagash.marmoc.net">glibc resolver weakness</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.2.2"/><vers num="8.2.1"/><vers num="8.2"/></prod><prod name="glibc" vendor="Gnu"><vers num="2.1.3"/><vers num="2.1.2"/><vers num="2.1.1"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0336" published="2000-04-21" seq="2000-0336" severity="Low" type="CVE"><desc><descript source="cve">Linux OpenLDAP server allows local users to modify arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4369.php">openldap-symlink-attack(4369)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1232">BID 1232</ref><ref adv="1" patch="1" source="Caldera Systems" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-009.0.txt">misconfigured OpenLDAP</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-012.html">RHSA-2000:012</ref><ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-May/000009.html">TLSA2000010-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1232">1232</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.0"/><vers num="6.1"/></prod><prod name="OpenLDAP" vendor="OpenLDAP"><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.10"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num="6.0.2"/><vers num="4.4"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0337" published="2000-04-24" seq="2000-0337" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Xsun X server in Solaris 7 allows local users to gain root privileges via a long -dev parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1140">BID 1140</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4360.php">solaris-xsun-bo(4360)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.3.96.1000424145711.4813C-100000@carma.isirc.is">Solaris x86 Xsun overflow.</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0188.html">20000424 Solaris x86 Xsun overflow.</ref><ref source="BID" url="http://www.securityfocus.com/bid/1140">1140</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0338" published="2000-04-23" seq="2000-0338" severity="Medium" type="CVE"><desc><descript source="cve">Concurrent Versions Software (CVS) uses predictable temporary file names for locking, which allows local users to cause a denial of service by creating the lock directory before it is created for use by a legitimate CVS user.</descript></desc><loss_types><avail/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1136">BID 1136</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4329.php">cvs-tempfile-dos</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000423174038.A520@clico.pl">CVS DoS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000423174038.A520%40clico.pl">20000423 CVS DoS</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.10.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0339" published="2000-04-24" seq="2000-0339" severity="High" type="CVE"><desc><descript source="cve">ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4356.php">zonealarm-portscan(4356)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1137">BID 1137</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000421044123.2353.qmail@securityfocus.com">ZoneAlarm</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000421044123.2353.qmail@securityfocus.com">20000420 ZoneAlarm</ref><ref source="BID" url="http://www.securityfocus.com/bid/1137">1137</ref><ref source="OSVDB" url="http://www.osvdb.org/1294">1294</ref></refs><vuln_soft><prod name="ZoneAlarm" vendor="Zone Labs"><vers num="2.2.10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0340" published="2000-04-29" seq="2000-0340" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Gnomelib in SuSE Linux 6.3 allows local users to execute arbitrary commands via the DISPLAY environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1155">BID 1155</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4426.php">linux-gnomelib-bo</ref><ref source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=00042902575201.09597@wintermute-pub">SuSE 6.3 Gnomelib buffer overflow</ref><ref source="CONFIRM" url="http://www.suse.com/us/support/download/updates/axp_63.html">http://www.suse.com/us/support/download/updates/axp_63.html</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.4"/><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0341" published="2000-05-01" seq="2000-0341" severity="Medium" type="CVE"><desc><descript source="cve">ATRIUM Cassandra NNTP Server 1.10 allows remote attackers to cause a denial of service via a long login name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1156">bugtraq id 1156</ref><ref source="NT Bugtraq" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=95736106504870&amp;w=2">Remote DoS attack in CASSANDRA NNTPServer v1.10 from ATRIUM</ref></refs><vuln_soft><prod name="Cassandra NNTP Server" vendor="Atrium Software"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0342" published="2000-04-28" seq="2000-0342" severity="Medium" type="CVE"><desc><descript source="cve">Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka &quot;Stealth Attachment.&quot;</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4383.php">eudora-warning-message(4383)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1157">BID 1157</ref><ref adv="1" source="CNET News" url="http://news.cnet.com/news/0-1005-200-1773077.html?tag=st.ne.fd.lthd.1005-200-1773077">Qualcomm warns of Eudora security hole</ref><ref source="MISC" url="http://www.peacefire.org/security/stealthattach/explanation.html">http://www.peacefire.org/security/stealthattach/explanation.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/1157">1157</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num="4.3"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0343" published="2000-05-02" seq="2000-0343" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1158">BID 1158</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4411.php">sniffit-lmail-bo</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200005021736.TAA01991@ALuSSi">spj-003-000 - S0ftPj Advisory</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000525155405.A22030@via.ecp.fr">&apos;sniffit -L mail&apos; vulnerabilities</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005021736.TAA01991@ALuSSi">20000502 spj-003-000 - S0ftPj Advisory</ref></refs><vuln_soft><prod name="Sniffit" vendor="Brecht Claerhout"><vers num="0.3.7beta"/><vers num="0.3.6HIP"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0344" published="2000-05-01" seq="2000-0344" severity="Medium" type="CVE"><desc><descript source="cve">The knfsd NFS server in Linux kernel 2.2.x allows remote attackers to cause a denial of service via a negative size value.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1160">BID 1160</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4409.php">linux-knfsd-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0005012042550.6419-100000@ferret.lmh.ox.ac.uk">Linux knfsd DoS issue</ref><ref patch="1" source="Red Hat Support" url="http://www.redhat.com/support/errata/RHBA-2000018-10.html">Updated kernel available for Red Hat Linux</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0345" published="2000-05-03" seq="2000-0345" severity="Low" type="CVE"><desc><descript source="cve">The on-line help system options in Cisco routers allows non-privileged users without &quot;enabled&quot; access to obtain sensitive information via the show command.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1161">BID 1161</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4407.php">cisco-online-help</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000502222246.28423.qmail@securityfocus.com">Possible issue with Cisco on-line help?</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000502222246.28423.qmail@securityfocus.com">20000502 Possible issue with Cisco on-line help?</ref></refs><vuln_soft><prod name="Router" vendor="Cisco"><vers num="7500"/><vers num="7200"/><vers num="4000"/><vers num="3600"/><vers num="2600"/><vers num="2500"/></prod><prod name="IOS" vendor="Cisco"><vers num="9.14"/><vers num="12.0.7"/><vers num="12.0.6"/><vers num="12.0.5"/><vers num="12.0.4T"/><vers num="12.0.4S"/><vers num="12.0.4"/><vers num="12.0.3T2"/><vers num="12.0.2XG"/><vers num="12.0.2XF"/><vers num="12.0.2XD"/><vers num="12.0.2XC"/><vers num="12.0.2"/><vers num="12.0.1XE"/><vers num="12.0.1XB"/><vers num="12.0.1XA3"/><vers num="12.0.1W"/><vers num="12.0T"/><vers num="12.0S"/><vers num="12.0DB"/><vers num="12.0(9)S"/><vers num="12.0(8)"/><vers num="12.0(7)T"/><vers num="12.0(5)T1"/><vers num="12.0"/><vers num="11.2.9XA"/><vers num="11.2.9P"/><vers num="11.2.8SA5"/><vers num="11.2.8SA3"/><vers num="11.2.8SA1"/><vers num="11.2.8P"/><vers num="11.2.8"/><vers num="11.2.4F1"/><vers num="11.2.10BC"/><vers num="11.2.10"/><vers num="11.2P"/><vers num="11.2(17)"/><vers num="11.2"/><vers num="11.1.17CT"/><vers num="11.1.17CC"/><vers num="11.1.16IA"/><vers num="11.1.16AA"/><vers num="11.1.16"/><vers num="11.1.15CA"/><vers num="11.1.13IA"/><vers num="11.1.13CA"/><vers num="11.1.13AA"/><vers num="11.1.13"/><vers num="11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0346" published="2000-05-02" seq="2000-0346" severity="Medium" type="CVE"><desc><descript source="cve">AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1162">BID 1162</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4429.php">macos-appleshare-invalid-range(4429)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-05-01%26msg%3D20000502133240.21807.qmail@securityfocus.com">INFO:AppleShare IP 6.3.2 squashes security bug</ref><ref source="CONFIRM" url="http://asu.info.apple.com/swupdates.nsf/artnum/n11670">http://asu.info.apple.com/swupdates.nsf/artnum/n11670</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000502133240.21807.qmail@securityfocus.com">20000502 INFO:AppleShare IP 6.3.2 squashes security bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/1162">1162</ref></refs><vuln_soft><prod name="AppleShare IP" vendor="Apple"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0347" published="2000-05-02" seq="2000-0347" severity="Medium" type="CVE"><desc><descript source="cve">Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4397.php">win-netbios-source-null(4397)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1163">BID 1163</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=95737580922397&amp;w=2">20000501 el8.org advisory - Win 95/98 DoS (RFParalyze.c)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1163">1163</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0348" published="2001-03-12" seq="2000-0348" severity="High" type="CVE"><desc><descript source="cve">A vulnerability in the Sendmail configuration file sendmail.cf as installed in SCO UnixWare 7.1.0 and earlier allows an attacker to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.10a">SB-99.10</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0349" published="2001-03-12" seq="2000-0349" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in the passthru driver in SCO UnixWare 7.1.0 allows an attacker to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.13a">SB-99.13</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0350" published="2000-05-17" seq="2000-0350" severity="Medium" type="CVE"><desc><descript source="cve">A debugging feature in NetworkICE ICEcap 2.0.23 and earlier is enabled, which allows a remote attacker to bypass the weak authentication and post unencrypted events.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1216">BID 1216</ref><ref adv="1" patch="1" source="NetworkICE" url="http://advice.networkice.com/advice/Support/KB/q000165/default.htm">Grinding passwords on ICEcap</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4476.php">netice-icecap-default(4476)</ref><ref source="MISC" url="http://www.securityfocus.com/templates/advisory.html?id=2220">http://www.securityfocus.com/templates/advisory.html?id=2220</ref><ref source="CONFIRM" url="http://advice.networkice.com/advice/Support/KB/q000166/">http://advice.networkice.com/advice/Support/KB/q000166/</ref><ref source="BID" url="http://www.securityfocus.com/bid/1216">1216</ref><ref source="OSVDB" url="http://www.osvdb.org/312">312</ref></refs><vuln_soft><prod name="ICECap Manager" vendor="NetworkICE"><vers num="2.0.23" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0351" published="2001-03-12" seq="2000-0351" severity="Medium" type="CVE"><desc><descript source="cve">Some packaging commands in SCO UnixWare 7.1.0 have insecure privileges, which allows local users to add or remove software packages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.09b">SB-99.09</ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-99.09b">SB-99.09</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.1.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0352" published="1999-11-18" seq="2000-0352" severity="High" type="CVE"><desc><descript source="cve">Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/810">BID 810</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1695.php">pine-remote-exe(1695)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.9911171818220.12375-100000@ray.compu-aid.com"> Pine: expanding env vars in URLs (seems to be fixed as of 4.21)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9911171818220.12375-100000@ray.compu-aid.com">19991117 Pine: expanding env vars in URLs (seems to be fixed as of 4.21)</ref><ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-036.0.txt">CSSA-1999-036.0</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_36.html">19991227 Security hole in Pine &lt; 4.21</ref><ref source="BID" url="http://www.securityfocus.com/bid/810">810</ref></refs><vuln_soft><prod name="Pine" vendor="University of Washington"><vers num="4.21"/><vers num="4.20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0353" published="1999-06-28" seq="2000-0353" severity="High" type="CVE"><desc><descript source="cve">Pine 4.x allows a remote attacker to execute arbitrary commands via an index.html file which executes lynx and obtains a uudecoded file from a malicious web server, which is then executed by Pine.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SecuriTeam.com" url="http://www.securiteam.com/unixfocus/HHP-Pine_remote_exploit.html">HHP-Pine_remote_exploit</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1247">BID 1247</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4851.php">pine-lynx-execute-commands(4851)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_6.html">19990628 Execution of commands in Pine 4.x</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/pine_update_announcement.html">19990911 Update for Pine (fixed IMAP support)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1247">1247</ref></refs><vuln_soft><prod name="Pine" vendor="University of Washington"><vers num="4.2"/><vers num="4.10"/><vers num="4.0"/><vers num="3.98"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0354" published="2000-09-28" seq="2000-0354" severity="Medium" type="CVE"><desc><descript source="cve">mirror 2.8.x in Linux systems allows remote attackers to create files one level above the local target directory.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3319.php">mirror-perl-remote-file-creation(3319)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/681">BID 681</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D15769.990928@tomcat.ru">mirror 2.9 hole</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=15769.990928@tomcat.ru">19990928 mirror 2.9 hole</ref><ref source="DEBIAN" url="http://www.debian.org/security/1999/19991018">19991018 Incorrect directory name handling in mirror</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_22.html">19991001 Security hole in mirror</ref><ref source="BID" url="http://www.securityfocus.com/bid/681">681</ref></refs><vuln_soft><prod name="Mirror" vendor="Lee McLoughlin"><vers num="2.9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0355" published="1999-08-21" seq="2000-0355" severity="High" type="CVE"><desc><descript source="cve">pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3237.php">linux-pg-fileread(3237)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3239.php">linux-pb-fileread(3239)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1271">BID 1271</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_21.html">19990920 Security hole in pbpg</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.2"/></prod><prod name="pbpg" vendor="Bent Bagger"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0356" published="1999-10-13" seq="2000-0356" severity="Medium" type="CVE"><desc><descript source="cve">Pluggable Authentication Modules (PAM) in Red Hat Linux 6.1 does not properly lock access to disabled NIS accounts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/697">BID 697</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3330.php">linux-pam-nis-login(3330)</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/1999/19991027">nis: various security problems in nis</ref><ref source="REDHAT" url="http://www.securityfocus.com/templates/advisory.html?id=1789">RHSA-1999:040</ref><ref source="BID" url="http://www.securityfocus.com/bid/697">697</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0357" published="1999-12-03" seq="2000-0357" severity="High" type="CVE"><desc><descript source="cve">ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4157.php">linux-orbit-esound-authentication-keys(4157)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1275">RedHat Linux 6.1 ORBit and esound Weak Authentication Vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/RHSA1999058-01.html">RHSA-1999:058-01</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0358" published="1999-12-03" seq="2000-0358" severity="Medium" type="CVE"><desc><descript source="cve">ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1283">RedHat Linux 6.1 ORBit and gnome-session Remote DoS Vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/RHSA1999058-01.html">RHSA-1999:058-01</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2000-0359" published="2000-10-20" seq="2000-0359" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1248">BID 1248</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4852.php">thttpd-ifmodifiedsince-header(4852)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-11-8%26msg%3D382DA5D5.A9D1F810@thievco.com">thttpd 2.04 stack overflow (VD#6)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1626.html">19991113 thttpd 2.04 stack overflow (VD#6)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_30.html">19991116 Security hole in thttpd 1.90a - 2.04</ref><ref source="BID" url="http://www.securityfocus.com/bid/1248">1248</ref></refs><vuln_soft><prod name="thttpd" vendor="Acme Labs"><vers num="2.0.4"/><vers num="2.0.3"/><vers num="2.0.2"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.95"/><vers num="1.90a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0360" published="2000-10-20" seq="2000-0360" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in INN 2.2.1 and earlier allows remote attackers to cause a denial of service via a maliciously formatted article.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4176.php">inn-remote-dos(4176)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1249">BID 1249</ref><ref adv="1" patch="1" source="Caldera Systems" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-038.0.txt">DoS attack on inn</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_34.html">19991124 Security hole in inn &lt;= 2.2.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1249">1249</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="2.2.1"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.7.2"/><vers num="1.7"/><vers num="1.5.1"/><vers num="1.5"/><vers num="1.4unoff4"/><vers num="1.4unoff3"/><vers num="1.4sec2"/><vers num="1.4sec"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0361" published="1999-12-14" seq="2000-0361" severity="Low" type="CVE"><desc><descript source="cve">The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4172.php">wvdial-gain-dialup-info(4172)</ref><ref adv="1" patch="1" source="SuSE" url="http://www.suse.de/de/support/security/suse_security_announce_35.txt">Security hole in wvdia</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/advisories/1970">SuSE Security Announcement wvdial &lt;= 1.4</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_35.html">19991214 Security hole in wvdial &lt;= 1.4</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-08-02" name="CVE-2000-0362" published="1999-10-22" seq="2000-0362" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Linux cdwtools 093 and earlier allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3282.php">linux-cdda2cdr(3282)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/738">Bugtraq id 738</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_25.html">19991019 Security hole in cdwtools &lt; 093</ref><ref source="BID" url="http://www.securityfocus.com/bid/738">738</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.2"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0363" published="1999-10-22" seq="2000-0363" severity="Medium" type="CVE"><desc><descript source="cve">Linux cdwtools 093 and earlier allows local users to gain root privileges via the /tmp directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3282.php">linux-cdda2cdr(3282)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/738">Bugtraq id 738</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D1999-09-29%26msg%3D19990930185514.20605.qmail@nwcst314.netaddress.usa.net">Linux cdda2cdr local exploit</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_25.html">19991019 Security hole in cdwtools &lt; 093</ref><ref source="BID" url="http://www.securityfocus.com/bid/738">738</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.2"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0364" published="1999-06-01" seq="2000-0364" severity="Medium" type="CVE"><desc><descript source="cve">screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4857.php">linux-tty-improper-mode(4857)</ref><ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/RHSA1999014_01.html">RHSA1999014_01</ref><ref source="BID" url="http://www.securityfocus.com/bid/309">309</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92877527701347&amp;w=2">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92886009012161&amp;w=2">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0365" published="1999-06-01" seq="2000-0365" severity="Medium" type="CVE"><desc><descript source="cve">Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4858.php">linux-dev-insecure-mode(4858)</ref><ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/RHSA1999014_01.html">RHSA1999014_01</ref><ref source="BID" url="http://www.securityfocus.com/bid/308">308</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92877527701347&amp;w=2">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92886009012161&amp;w=2">19990606 RedHat 6.0, /dev/pts permissions bug when using xterm</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-2000-0366" published="1999-12-02" seq="2000-0366" severity="Low" type="CVE"><desc><descript source="cve">dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.</descript></desc><loss_types><int/></loss_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1442">Debian Linux 2.1 dump Symlink Restore Vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/1999/19991202">19991202 problem restoring symlinks</ref><ref source="BID" url="http://www.securityfocus.com/bid/1442">1442</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-2000-0367" published="1999-02-18" seq="2000-0367" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1804.php">linux-eterm(1804)</ref><ref adv="1" source="Debian" url="http://www.debian.org/security/1999/19990218">19990218 Root exploit in eterm</ref></refs><vuln_soft><prod name="eterm" vendor="Michael Jennings"><vers num="0.8.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0368" published="2001-03-12" seq="2000-0368" severity="Low" type="CVE"><desc><descript source="cve">Classic Cisco IOS 9.1 and later allows attackers with access to the loging prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-009.shtml">J-009</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/ioshist-pub.shtml">Cisco IOS Command History Release at Login Prompt</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="9.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0369" published="1999-10-08" seq="2000-0369" severity="Medium" type="CVE"><desc><descript source="cve">The IDENT server in Caldera Linux 2.3 creates multiple threads for each IDENT request, which allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4860.php">caldera-ident-server-dos(4860)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1266">Caldera IDENT daemon Denial of Service Vulnerability</ref><ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-029.1.txt">CSSA-1999-029.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1266">1266</ref></refs><vuln_soft><prod name="OpenLinux" vendor="Caldera"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0370" published="1999-01-29" seq="2000-0370" severity="High" type="CVE"><desc><descript source="cve">The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1268">Bugtraq id 1268</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4854.php">caldera-smail-rmail-command(4854)</ref><ref adv="1" patch="1" source="Bugtraq" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-001.0.txt">rmail problem in smail</ref><ref source="BID" url="http://www.securityfocus.com/bid/1268">1268</ref></refs><vuln_soft><prod name="OpenLinux" vendor="Caldera"><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0371" published="1999-03-01" seq="2000-0371" severity="Low" type="CVE"><desc><descript source="cve">The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2160.php">kde-mediatool(2160)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1269">BID 1269</ref><ref adv="1" patch="1" source="Caldera" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-005.0.txt">KDE mediatool(multimedia) lib</ref><ref source="BID" url="http://www.securityfocus.com/bid/1269">1269</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0372" published="2000-07-12" seq="2000-0372" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2268.php">linux-rmt(2268)</ref><ref adv="1" patch="1" source="Caldera" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-014.0.txt">CSSA-1999-014.0</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/advisories/1588">/sbin/rmt with suid allows superuser privileges</ref><ref source="OSVDB" url="http://www.osvdb.org/7940">7940</ref></refs><vuln_soft><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0373" published="1999-06-01" seq="2000-0373" severity="High" type="CVE"><desc><descript source="cve">Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2266.php">kde-kvt(2266)</ref><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-1999-015.0.txt">CSSA-1999:015.0</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA1999015_01.html">RHSA-1999:015-01</ref><ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-015.0.txt">CSSA-1999-015.0</ref></refs><vuln_soft><prod name="kvt" vendor="KDE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-2000-0374" published="1999-08-22" seq="2000-0374" severity="High" type="CVE"><desc><descript source="cve">The default configuration of kdm in Caldera and Mandrake Linux, and possibly other distributions, allows XDMCP connections from any host, which allows remote attackers to obtain sensitive information or bypass additional access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1446">Caldera kdm XDMCP Access Control Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4856.php">caldera-kdm-default-configuration(4856)</ref><ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-021.0.txt">CSSA-1999-021.0</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2002:025">MDKSA-2002:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/1446">1446</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4856">xdmcp-kdm-default-configuration(4856)</ref></refs><vuln_soft><prod name="OpenLinux" vendor="Caldera"><vers num="2.2"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0375" published="2001-03-12" seq="2000-0375" severity="Low" type="CVE"><desc><descript source="cve">The kernel in FreeBSD 3.2 follows symbolic links when it creates core dump files, which allows local attackers to modify arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-99:04.core.asc"></ref><ref source="OSVDB" url="http://www.osvdb.org/6084">6084</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0376" published="2000-06-07" seq="2000-0376" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1324">BID 1324</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4613.php">idrive-filo-bo(4613)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/64017"> Internet Security Systems Security Advisory: Buffer Overflow in i-drive Filo (tm) software</ref><ref source="BID" url="http://www.securityfocus.com/bid/1324">1324</ref></refs><vuln_soft><prod name="Filo" vendor="i-drive"><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0377" published="2000-06-08" seq="2000-0377" severity="Medium" type="CVE"><desc><descript source="cve">The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the &quot;Remote Registry Access Authentication&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1331">BID 1331</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4648.php">nt-registry-request-dos(4648)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-040.asp">MS00-040</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=264684">Q264684</ref><ref source="BID" url="http://www.securityfocus.com/bid/1331">1331</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1021">oval:org.mitre.oval:def:1021</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0378" published="2000-05-03" seq="2000-0378" severity="High" type="CVE"><desc><descript source="cve">The pam_console PAM module in Linux systems performs a chown on various devices upon a user login, but an open file descriptor for those devices can be maintained after the user logs out, which allows that user to sniff activity on these devices when subsequent users log in.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4869.php">linux-pam-sniff-activities(4869)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1176">Multiple Linux Vendor pam_console Vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0023.html">20000502 pam_console bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/1176">1176</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/><vers num="6.1"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0379" published="2000-05-16" seq="2000-0379" severity="Low" type="CVE"><desc><descript source="cve">The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1177">BID 1177</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4428.php">netopia-snmp-comm-strings(4428)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005082054.NAA32590@linux.mtndew.com">Advisory: Netopia R9100 router vulnerability</ref><ref source="CONFIRM" url="http://www.netopia.com/equipment/purchase/fmw_update.html">http://www.netopia.com/equipment/purchase/fmw_update.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/1177">1177</ref></refs><vuln_soft><prod name="R-series routers" vendor="Netopia"><vers num="4.6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0380" published="2000-04-26" seq="2000-0380" severity="Medium" type="CVE"><desc><descript source="cve">The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1154">BID 1154</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4357.php">cisco-ios-http-dos(4357)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/57567">Re: Cisco HTTP possible bug:</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0261.html">20000426 Cisco HTTP possible bug:</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/ioshttpserver-pub.shtml">20000514 Cisco IOS HTTP Server Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1154">1154</ref><ref source="OSVDB" url="http://www.osvdb.org/1302">1302</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0.7"/><vers num="12.0.6"/><vers num="12.0.5"/><vers num="12.0.4T"/><vers num="12.0.4S"/><vers num="12.0.4"/><vers num="12.0.3T2"/><vers num="12.0.2XG"/><vers num="12.0.2XF"/><vers num="12.0.2XD"/><vers num="12.0.2XC"/><vers num="12.0.2"/><vers num="12.0.1XE"/><vers num="12.0.1XB"/><vers num="12.0.1XA3"/><vers num="12.0.1W"/><vers num="12.0T"/><vers num="12.0S"/><vers num="12.0DB"/><vers num="12.0(9)S"/><vers num="12.0(8)"/><vers num="12.0(7)T"/><vers num="12.0(5)T1"/><vers num="12.0"/><vers num="11.3.1T"/><vers num="11.3.1ED"/><vers num="11.3.1"/><vers num="11.3T"/><vers num="11.3"/><vers num="11.2.9XA"/><vers num="11.2.9P"/><vers num="11.2.8P"/><vers num="11.2.8"/><vers num="11.2.4F1"/><vers num="11.2.10BC"/><vers num="11.2.10"/><vers num="11.2P"/><vers num="11.2(17)"/><vers num="11.2"/><vers num="11.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0381" published="2000-05-05" seq="2000-0381" severity="Medium" type="CVE"><desc><descript source="cve">The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1178">BID 1178</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4494.php">http-cgi-dbman-db(4494)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/61076">Black Watch Labs Vulnerability Alert</ref><ref source="MISC" url="http://www.perfectotech.com/blackwatchlabs/vul5_05.html">http://www.perfectotech.com/blackwatchlabs/vul5_05.html</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0067.html">20000505 Black Watch Labs Vulnerability Alert</ref><ref source="BID" url="http://www.securityfocus.com/bid/1178">1178</ref></refs><vuln_soft><prod name="DBMan" vendor="Gossamer Threads"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0382" published="2000-05-08" seq="2000-0382" severity="Low" type="CVE"><desc><descript source="cve">ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1179">BID 1179</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4436.php">allaire-clustercats-url-redirect(4436)</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=15697&amp;Method=Full">Allaire Security Bulletin (ASB00-12)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1179">1179</ref></refs><vuln_soft><prod name="ClusterCATS" vendor="Allaire"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0383" published="2000-05-08" seq="2000-0383" severity="Medium" type="CVE"><desc><descript source="cve">The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1180">AOL Instant Messenger Path Disclosure Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4427.php">aolim-file-path(4427)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1180">1180</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=002401bfb918$7310d5a0$1ef084ce@karemor.com">20000507 AOL Instant Messenger</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-09" name="CVE-2000-0384" published="2000-05-08" seq="2000-0384" severity="High" type="CVE"><desc><descript source="cve">NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure&apos;s MAC address, which could allow remote attackers to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="L0pht" url="http://www.lopht.com/advisories/ipivot7110.html">20000508 NetStructure 7180 remote backdoor vulnerability</ref><ref adv="1" patch="1" source="L0pht" url="http://www.l0pht.com/advisories/ipivot7180.html">20000508 NetStructure 7110 console backdoor</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1182">BID 1182</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1183">BID 1183</ref><ref source="CONFIRM" url="http://216.188.41.136/">http://216.188.41.136/</ref></refs><vuln_soft><prod name="NetStructure" vendor="Intel"><vers num="7110.0"/><vers num="7180.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0385" published="2000-05-02" seq="2000-0385" severity="Medium" type="CVE"><desc><descript source="cve">FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4431.php">macos-filemaker-xml(4431)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4432.php">macos-filemaker-email(4432)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1159">FileMaker Pro 5.0 Web Companion Software Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html">http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html</ref><ref source="CONFIRM" url="http://www.filemaker.com/support/webcompanion.html">http://www.filemaker.com/support/webcompanion.html</ref></refs><vuln_soft><prod name="FileMaker Pro" vendor="FileMaker"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0386" published="2000-05-02" seq="2000-0386" severity="High" type="CVE"><desc><descript source="cve">FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4433.php">macos-filemaker-anonymous-email(4433)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1159">FileMaker Pro 5.0 Web Companion Software Multiple Vulnerabilities</ref><ref source="MISC" url="http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html">http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html</ref><ref source="CONFIRM" url="http://www.filemaker.com/support/webcompanion.html">http://www.filemaker.com/support/webcompanion.html</ref></refs><vuln_soft><prod name="FileMaker Pro" vendor="FileMaker"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0387" published="2000-05-09" seq="2000-0387" severity="Low" type="CVE"><desc><descript source="cve">The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1184">BID 1184</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4424.php">golddig-overwrite-files(4424)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/47/59228">FreeBSD Security Advisory: FreeBSD-SA-00:16.golddig</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:16.golddig.asc">FreeBSD-SA-00:16</ref><ref source="BID" url="http://www.securityfocus.com/bid/1184">1184</ref></refs><vuln_soft><prod name="golddig" vendor="Alexander Siegel"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0388" published="1990-05-09" seq="2000-0388" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FreeBSD libmytinfo library allows local users to execute commands via a long TERMCAP environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1185">BID 1185</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4422.php">libmytinfo-bo(4422)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/47/59231">FreeBSD Security Advisory: FreeBSD-SA-00:17.libmytinfo</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A17.libmytinfo.asc">FreeBSD-SA-00:17</ref><ref source="BID" url="http://www.securityfocus.com/bid/1185">1185</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0389" published="2000-05-16" seq="2000-0389" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1220">BID 1220</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4519.php">kerberos-krb-rd-req-bo(4519)</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html">CA-2000-06</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="5.0_1.1.1"/><vers num="5.0_1.0"/></prod><prod name="CyGNUs Network Security" vendor="CyGNUs"><vers num="4.0"/></prod><prod name="KerbNet" vendor="CyGNUs"><vers num="5.0"/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0 patch 10"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0390" published="2000-05-16" seq="2000-0390" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1220">BID 1220</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4520.php">kerberos-krb425-conv-principal-bo(4520)</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html">CA-2000-06</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref><ref source="OSVDB" url="http://www.osvdb.org/4884">4884</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="5.0_1.1.1"/><vers num="5.0_1.0"/></prod><prod name="CyGNUs Network Security" vendor="CyGNUs"><vers num="4.0"/></prod><prod name="KerbNet" vendor="CyGNUs"><vers num="5.0"/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0 patch 10"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0391" published="2000-05-16" seq="2000-0391" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1220">BID 1220</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4521.php">kerberos-krshd-bo(4521)</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html">CA-2000-06</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref><ref source="OSVDB" url="http://www.osvdb.org/4876">4876</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="5.0_1.1.1"/><vers num="5.0_1.0"/></prod><prod name="CyGNUs Network Security" vendor="CyGNUs"><vers num="4.0"/></prod><prod name="KerbNet" vendor="CyGNUs"><vers num="5.0"/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0 patch 10"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0392" published="2000-05-16" seq="2000-0392" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1220">BID 1220</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4522.php">kerberos-ksu-bo(4522)</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-06.html">CA-2000-06</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0184.html">20000516 BUFFER OVERRUN VULNERABILITIES IN KERBEROS</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-05/0295.html">FreeBSD-SA-00:20</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-025.html">RHSA-2000:025</ref><ref source="BID" url="http://www.securityfocus.com/bid/1220">1220</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="5.0_1.1.1"/><vers num="5.0_1.0"/></prod><prod name="CyGNUs Network Security" vendor="CyGNUs"><vers num="4.0"/></prod><prod name="KerbNet" vendor="CyGNUs"><vers num="5.0"/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0 patch 10"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0393" published="2000-05-16" seq="2000-0393" severity="High" type="CVE"><desc><descript source="cve">The KDE kscd program does not drop privileges when executing a program specified in a user&apos;s SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1206">bugtraq id 1206</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4468.php">kscd-shell-env-variable(4468)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/60353">kscd vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0172.html">20000516 kscd vulnerability</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_50.html">20000529 kmulti &lt;= 1.1.2</ref><ref source="BID" url="http://www.securityfocus.com/bid/1206">1206</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="2.0 BETA"/><vers num="1.2"/><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0394" published="2000-05-18" seq="2000-0394" severity="Medium" type="CVE"><desc><descript source="cve">NetProwler 3.0 allows remote attackers to cause a denial of service by sending malformed IP packets that trigger NetProwler&apos;s Man-in-the-Middle signature.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1225">BID 1225</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4493.php">axent-netprowler-ipfrag-dos(4493)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-05-15%26msg%3DPine.LNX.4.10.10005191304330.11537-100000@eight.wiretrip.net"> RFP2K05: NetProwler vs. RFProwler</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95878603510835&amp;w=2">20000519 RFP2K05: NetProwler vs. RFProwler</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=392AD3B3.3E9BE3EA@axent.com">20000522 RFP2K05 - NetProwler &quot;Fragmentation&quot; Issue </ref><ref source="BID" url="http://www.securityfocus.com/bid/1225">1225</ref></refs><vuln_soft><prod name="NetProwler" vendor="Axent"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0395" published="2000-05-16" seq="2000-0395" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1213">BID 1213</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4460.php">cproxy-http-dos(4460)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D007d01bfbf48%24e44f0e40%2401dc11ac@peopletel.org">CProxy v3.3 SP 2 DoS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=007d01bfbf48$e44f0e40$01dc11ac@peopletel.org">20000516 CProxy v3.3 SP 2 DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/1213">1213</ref></refs><vuln_soft><prod name="CProxy Server" vendor="Computalynx"><vers num="3.3SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0396" published="2000-05-24" seq="2000-0396" severity="Medium" type="CVE"><desc><descript source="cve">The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, which could allow the attacker to read source code for web scripts such as .ASP files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1245">BID 1245</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4542.php">carello-file-duplication(4542)</ref><ref adv="1" patch="1" source="Cerberus" url="http://www.cerberus-infosec.co.uk/advcarello.html">Cerberus Information Security Advisory (CISADV000524b)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0285.html">20000524 Alert: Carello File Creation flaw</ref><ref source="BID" url="http://www.securityfocus.com/bid/1245">1245</ref></refs><vuln_soft><prod name="Carello" vendor="Pacific Software"><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0397" published="2000-05-15" seq="2000-0397" severity="Medium" type="CVE"><desc><descript source="cve">The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user&apos;s email account.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1203">BID 1203</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4454.php">http://xforce.iss.net/static/4454.php</ref><ref adv="1" patch="1" source="SCO Security Bulletin" url="ftp://ftp.sco.com/SSE/security_bulletins/SB-00.01a">Buffer Overflow Vulnerabilities in OpenServer pkg* tools</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0160.html">20000515 Vulnerability in EMURL-based e-mail providers</ref><ref source="BID" url="http://www.securityfocus.com/bid/1203">1203</ref></refs><vuln_soft><prod name="Emurl" vendor="Seattle Lab Software"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0398" published="2000-05-24" seq="2000-0398" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1244">BID 1244</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4537.php">mailsite-get-overflow(4537)</ref><ref adv="1" patch="1" source="Cerberus" url="http://www.cerberus-infosec.co.uk/advhttpma.html">Cerberus Information Security Advisory (CISADV000524a)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0286.html">20000524 Alert: Buffer overflow in Rockliffe&apos;s MailSite</ref><ref source="BID" url="http://www.securityfocus.com/bid/1244">1244</ref></refs><vuln_soft><prod name="MailSite" vendor="Rockliffe"><vers num="4.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0399" published="2000-05-24" seq="2000-0399" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in MDaemon POP server allows remote attackers to cause a denial of service via a long user name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1250">BID 1250</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4539.php">deerfield-mdaemon-dos(4539)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200005241728.KAA13584@mail5.hushmail.com">Deerfield Communications MDaemon Mail Server DoS</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0301.html">20000524 Deerfield Communications MDaemon Mail Server DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/1250">1250</ref></refs><vuln_soft><prod name="MDaemon" vendor="Alt-N"><vers num="3.1 Beta"/><vers num="3.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0400" published="2000-05-13" seq="2000-0400" severity="High" type="CVE"><desc><descript source="cve">The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user&apos;s system by encoding it within an email message or news post.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1221">Microsoft Active Movie Control Filetype Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4513.php">ie-active-movie-control(4513)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1221">1221</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95868514521257&amp;w=2">20000516 MICROSOFT SECURITY FLAW?</ref></refs><vuln_soft><prod name="Active Movie Control" vendor="Microsoft"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0401" published="2000-05-01" seq="2000-0401" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4546.php">pdgsoft-changepw-bo(4546)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4545.php">pdgsoft-redirect-bo(4545)</ref><ref source="CONFIRM" url="http://www.pdgsoft.com/Security/security2.html">http://www.pdgsoft.com/Security/security2.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/1256">1256</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95928319715983&amp;w=2">20000525 Alert: PDG Cart Overflows</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=95928667119963&amp;w=2">20000525 Alert: PDG Cart Overflows</ref></refs><vuln_soft><prod name="PDG Shopping Cart" vendor="PDGSoft"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-0402" published="2000-05-30" seq="2000-0402" severity="Low" type="CVE"><desc><descript source="cve">The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the &quot;SQL Server 7.0 Service Pack Password&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1281">BID 1281</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4584.php">mssql-sa-pw-in-sqlsplog(4584)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/MS00-035.asp">MS00-035</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=263968">Q263968</ref><ref source="BID" url="http://www.securityfocus.com/bid/1281">1281</ref></refs><vuln_soft><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="7.0 SP2"/><vers num="7.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0403" published="2000-05-25" seq="2000-0403" severity="Medium" type="CVE"><desc><descript source="cve">The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the &quot;HostAnnouncement Flooding&quot; or &quot;HostAnnouncement Frame&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1261">BID 1261</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4547.php">win-browser-hostannouncement(4547)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-036.asp">ms00-036</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=263307">Q263307</ref><ref source="BID" url="http://www.securityfocus.com/bid/1261">1261</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0404" published="2000-05-25" seq="2000-0404" severity="Medium" type="CVE"><desc><descript source="cve">The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the &quot;ResetBrowser Frame&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1262">BID 1262</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4552.php">win-browser-reset-frame(4552)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-036.asp">MS00-036</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=262694">Q262694</ref><ref source="BID" url="http://www.securityfocus.com/bid/1262">1262</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Terminal Server" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0405" published="2000-05-16" seq="2000-0405" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in L0pht AntiSniff allows remote attackers to execute arbitrary commands via a malformed DNS response packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1207">BID 1207</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4459.php">antisniff-dns-overflow(4459)</ref><ref adv="1" patch="1" source="L0pht" url="http://www.l0pht.com/advisories/asniff_advisory.txt">AntiSniff version 1.01</ref><ref source="BID" url="http://www.securityfocus.com/bid/1207">1207</ref><ref source="OSVDB" url="http://www.osvdb.org/3179">3179</ref></refs><vuln_soft><prod name="AntiSniff" vendor="atStake"><vers num="1.0.1"/><vers edition="Researchers" num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0406" published="2000-05-10" seq="2000-0406" severity="Low" type="CVE"><desc><descript source="cve">Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the &quot;Acros-Suencksen SSL&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1188">BID 1188</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-05.html">CA-2000-05</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4474.php">netscape-invalid-ssl-sessions(4474)</ref><ref source="" url="http://www.acrossecurity.com/aspr/ASPR-2000-04-06-1-PUB.txt"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-028.html">RHSA-2000:028</ref><ref source="BID" url="http://www.securityfocus.com/bid/1188">1188</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.72"/><vers num="4.7"/><vers num="4.61"/><vers num="4.6"/><vers num="4.51"/><vers num="4.5 BETA"/><vers num="4.5"/><vers num="4.0"/><vers num="4.07"/><vers num="4.06"/><vers num="4.05"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0407" published="2000-05-12" seq="2000-0407" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1200">BID 1200</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4451.php">sol-netpr-bo(4451)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000512215804.8714.qmail@hades.rpini.com">New Solaris root exploit for /usr/lib/lp/bin/netpr</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0141.html">20000512 New Solaris root exploit for /usr/lib/lp/bin/netpr</ref><ref source="BID" url="http://www.securityfocus.com/bid/1200">1200</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0408" published="2000-05-11" seq="2000-0408" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the &quot;Malformed Extension Data in URL&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1190">BID 1190</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4430.php">iis-url-extension-data-dos(4430)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-030.asp">ms00-030</ref><ref source="MISC" url="http://www.ussrback.com/labs40.html">http://www.ussrback.com/labs40.html</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=260205">Q260205</ref><ref source="BID" url="http://www.securityfocus.com/bid/1190">1190</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0409" published="2000-05-10" seq="2000-0409" severity="Low" type="CVE"><desc><descript source="cve">Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1201">BID 1201</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4478.php">netscape-import-certificate-symlink(4478)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-05-8%26msg%3DPine.BSF.4.21.0005101547150.99077-100000@blacklisted.intranova.net">Possible symlink problems with Netscape 4.73</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0126.html">20000510 Possible symlink problems with Netscape 4.73</ref><ref source="BID" url="http://www.securityfocus.com/bid/1201">1201</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.73"/><vers num="4.72"/><vers num="4.7"/><vers num="4.61"/><vers num="4.6"/><vers num="4.51"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0410" published="2000-05-10" seq="2000-0410" severity="Medium" type="CVE"><desc><descript source="cve">ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1192">bugtraq id 1192</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4435.php">coldfusion-cfcache-dos(4435)</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0005&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=4843">Cold Fusion Server 4.5.1 DoS Vulnerability.</ref><ref source="BID" url="http://www.securityfocus.com/bid/1192">1192</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0411" published="2000-05-10" seq="2000-0411" severity="Medium" type="CVE"><desc><descript source="cve">Matt Wright&apos;s FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1187">BID 1187</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4480.php">http-cgi-formmail-environment(4480)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/60025">issues with free Perl CGI&apos;s (Re: Black Watch Labs...)</ref><ref source="MISC" url="http://www.perfectotech.com/blackwatchlabs/vul5_10.html">http://www.perfectotech.com/blackwatchlabs/vul5_10.html</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0125.html">20000510 Black Watch Labs Vulnerability Alert</ref><ref source="BID" url="http://www.securityfocus.com/bid/1187">1187</ref></refs><vuln_soft><prod name="FormMail" vendor="Matt Wright"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0412" published="1999-05-01" seq="2000-0412" severity="High" type="CVE"><desc><descript source="cve">The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4462.php">knapster-view-files(4462)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0124.html">20000510 KNapster Vulnerability Compromises User-readable Files</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0127.html">20000510 Gnapster Vulnerability Compromises User-readable Files</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:18-gnapster.adv">FreeBSD-SA-00:18</ref><ref source="BID" url="http://www.securityfocus.com/bid/1186">1186</ref></refs><vuln_soft><prod name="Knapster" vendor="Napster"><vers num="Napster"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0413" published="2000-05-06" seq="2000-0413" severity="Medium" type="CVE"><desc><descript source="cve">The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4439.php">iis-shtml-reveal-path(4439)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1174">Microsoft Frontpage Server Extensions Path Disclosure Vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0084.html">20000506 shtml.exe reveal local path of IIS web directory</ref><ref source="BID" url="http://www.securityfocus.com/bid/1174">1174</ref></refs><vuln_soft><prod name="Frontpage" vendor="Microsoft"><vers num=""/></prod><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0414" published="2000-05-04" seq="2000-0414" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1214">BID 1214</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4418.php">hp-shutdown-privileges(4418)</ref><ref source="HP" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0047.html">HPSBUX0005-113</ref><ref source="BID" url="http://www.securityfocus.com/bid/1214">1214</ref></refs><vuln_soft><prod name="VVOS" vendor="HP"><vers num="11.4"/><vers num="10.24"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.20"/><vers num="10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0415" published="2000-05-12" seq="2000-0415" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1195">BID 1195</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0140.html">20000512 Overflow in Outlook Express 4.* - too long filenames with graphic format extension</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="98"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="4.72.3612.1700"/><vers num="4.72.3120"/><vers num="4.72.2106.4"/><vers num="4.27.3110.1"/><vers num="4.01"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0416" published="2000-05-11" seq="2000-0416" severity="Medium" type="CVE"><desc><descript source="cve">NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail&apos;s web configuration server.</descript></desc><loss_types><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1196">BID 1196</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4815.php">ntmail-bypass-proxy(4815)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DNABBJLKKPKIHDIMKFKGCMEFANMAB.georger@nls.net">NTMail Proxy Exploit</ref><ref source="CONFIRM" url="http://www.gordano.com/support/archives/ntmail/2000-05/00001114.htm">http://www.gordano.com/support/archives/ntmail/2000-05/00001114.htm</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NABBJLKKPKIHDIMKFKGCMEFANMAB.georger@nls.net">20000511 NTMail Proxy Exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/1196">1196</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Mail 5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0417" published="2000-05-17" seq="2000-0417" severity="Medium" type="CVE"><desc><descript source="cve">The HTTP administration interface to the Cayman 3220-H DSL router allows remote attackers to cause a denial of service via a long username or password.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1219">BID 1219</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4479.php">cayman-router-dos(4479)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/58800">Cayman 3220-H DSL Router DOS</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0075.html">20000505 Cayman 3220-H DSL Router DOS</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0280.html">20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/1219">1219</ref></refs><vuln_soft><prod name="3220-H DSL Router" vendor="Cayman"><vers num="1.0"/></prod><prod name="GatorSurf" vendor="Cayman"><vers num="5.5Build R0"/><vers num="5.3Build R2"/><vers num="5.3Build R1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0418" published="2000-05-23" seq="2000-0418" severity="Medium" type="CVE"><desc><descript source="cve">The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1240">BID 1240</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4532.php">cayman-dsl-dos(4532)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200005232351.QAA13204@mail5.hushmail.com">Cayman 3220H DSL Router Software Update and New Bonus Attack</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0280.html">20000523 Cayman 3220H DSL Router Software Update and New Bonus Attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/1240">1240</ref></refs><vuln_soft><prod name="3220-H DSL Router" vendor="Cayman"><vers num="1.0"/></prod><prod name="GatorSurf" vendor="Cayman"><vers num="5.5Build R1"/><vers num="5.5Build R0"/><vers num="5.3Build R2"/><vers num="5.3Build R1"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0419" published="2000-05-11" seq="2000-0419" severity="High" type="CVE"><desc><descript source="cve">The Office 2000 UA ActiveX Control is marked as &quot;safe for scripting,&quot; which allows remote attackers to conduct unauthorized activities via the &quot;Show Me&quot; function in Office Help, aka the &quot;Office 2000 UA Control&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1197">BID 1197</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-034.asp">MS00-034</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4445.php">office-ua-control(4445)</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=262767">Q262767</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2000-07.html">CA-2000-07</ref><ref source="BID" url="http://www.securityfocus.com/bid/1197">1197</ref></refs><vuln_soft><prod name="Excel" vendor="Microsoft"><vers num="2000"/></prod><prod name="Project" vendor="Microsoft"><vers num="2000"/></prod><prod name="Photodraw" vendor="Microsoft"><vers num="2000.1"/></prod><prod name="Works" vendor="Microsoft"><vers num="2000"/></prod><prod name="FrontPage" vendor="Microsoft"><vers num="2000"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2000"/></prod><prod name="Access" vendor="Microsoft"><vers num="2000"/></prod><prod name="Office" vendor="Microsoft"><vers num="2000"/></prod><prod name="PowerPoint" vendor="Microsoft"><vers num="2000"/></prod><prod name="Word" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0420" published="2000-05-11" seq="2000-0420" severity="High" type="CVE"><desc><descript source="cve">The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4819.php">win2k-syskey-default-configuration(4819)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1198">Microsoft Windows 2000 Default SYSKEY Configuration Vulnerability</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0112.html">20000511 ISS SAVANT Advisory 00/26</ref><ref source="BID" url="http://www.securityfocus.com/bid/1198">1198</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0421" published="2000-05-11" seq="2000-0421" severity="High" type="CVE"><desc><descript source="cve">The process_bug.cgi script in Bugzilla allows remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1199">BID 1199</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4816.php">bugzilla-unchecked-system-call(4816)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/59454">Advisory: Unchecked system(blaat $var blaat) call in Bugzilla 2.8</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0128.html">20000510 Advisory: Unchecked system(blaat $var blaat) call in Bugzilla 2.8</ref><ref source="BID" url="http://www.securityfocus.com/bid/1199">1199</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0422" published="2000-05-04" seq="2000-0422" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1171">Netwin Dmailweb Server utoken Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4420.php">http-cgi-dmailweb-bo(4420)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1171">1171</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95749276827558&amp;w=2">20000504 Alert: DMailWeb buffer overflow</ref></refs><vuln_soft><prod name="Dmail" vendor="NetWin"><vers num="2.5d"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0423" published="2000-05-05" seq="2000-0423" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1172">BID 1172</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4421.php">http-cgi-dnews-bo(4421)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1172">1172</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95764950403250&amp;w=2">20000505 Alert: DNewsWeb buffer overflow</ref></refs><vuln_soft><prod name="Dnews" vendor="NetWin"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0424" published="2000-05-15" seq="2000-0424" severity="High" type="CVE"><desc><descript source="cve">The CGI counter 4.0.7 by George Burgyan allows remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1202">BID 1202</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2052.php">http-cgi-textcounter(2052)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/60168">Vulnerability in CGI counter 4.0.7 by George Burgyan</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200005151024.aa01811@blaze.arl.mil">20000514 Vulnerability in CGI counter 4.0.7 by George Burgyan</ref><ref source="BID" url="http://www.securityfocus.com/bid/1202">1202</ref></refs><vuln_soft><prod name="CGI Counter" vendor="George Burgyan"><vers num="4.0.7"/><vers num="4.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0425" published="2000-05-03" seq="2000-0425" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1167">BID 1167</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4419.php">http-cgi-listserv-wa-bo(4419)</ref><ref source="CONFIRM" url="http://www.lsoft.com/news/default.asp?item=Advisory0">http://www.lsoft.com/news/default.asp?item=Advisory0</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0048.html">20000505 Alert: Listserv Web Archives (wa) buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/1167">1167</ref></refs><vuln_soft><prod name="Listserv" vendor="L-Soft"><vers num="1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0426" published="2000-05-05" seq="2000-0426" severity="Medium" type="CVE"><desc><descript source="cve">UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1175">BID 1175</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4438.php">ultraboard-cgi-dos(4438)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0059.html">20000505 Re: Fun with UltraBoard V1.6X</ref><ref source="BID" url="http://www.securityfocus.com/bid/1175">1175</ref></refs><vuln_soft><prod name="UltraBoard" vendor="UltraScripts"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0427" published="2000-05-04" seq="2000-0427" severity="Medium" type="CVE"><desc><descript source="cve">The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1170">BID 1170</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4434.php">aladdin-etoken-pin-reset(4434)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/advisories/2191">eToken Private Information Extraction and Physical Attack</ref><ref source="L0PHT" url="http://www.l0pht.com/advisories/etoken-piepa.txt">20000504 eToken Private Information Extraction and Physical Attack</ref><ref source="BID" url="http://www.securityfocus.com/bid/1170">1170</ref><ref source="OSVDB" url="http://www.osvdb.org/3266">3266</ref></refs><vuln_soft><prod name="eToken" vendor="Aladdin Knowledge Systems"><vers num="3.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0428" published="2000-05-04" seq="2000-0428" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the SMTP gateway for InterScan Virus Wall 3.32 and earlier allows a remote attacker to execute arbitrary commands via a long filename for a uuencoded attachment.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1168">BID 1168</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3767.php">interscan-viruswall-bypass(3767)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/12682">BlackHats Advisory -- InterScan VirusWall</ref><ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/39_Trend.asp">20000503 Trend Micro InterScan VirusWall Remote Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/1168">1168</ref></refs><vuln_soft><prod name="InterScan VirusWall" vendor="Trend Micro"><vers num="3.32"/><vers num="3.3"/><vers num="3.2.3"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0429" published="2000-04-27" seq="2000-0429" severity="High" type="CVE"><desc><descript source="cve">A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1153">BID 1153</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4351.php">cart32-admin-password(4351)</ref><ref source="CONFIRM" url="http://www.cart32.com/kbshow.asp?article=c048">http://www.cart32.com/kbshow.asp?article=c048</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95686068203138&amp;w=2">20000427 Alert: Cart32 secret password backdoor (CISADV000427)</ref></refs><vuln_soft><prod name="Cart32" vendor="McMurtrey Whitaker and Associates"><vers num="3.0"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0430" published="2000-05-03" seq="2000-0430" severity="Medium" type="CVE"><desc><descript source="cve">Cart32 allows remote attackers to access sensitive debugging information by appending /expdate to the URL request.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1358">BID 1358</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4398.php">cart32-expdate(4398)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95738697301956&amp;w=2">20000503 Another interesting Cart32 command</ref><ref source="BID" url="http://www.securityfocus.com/bid/1358">1358</ref></refs><vuln_soft><prod name="Cart32" vendor="McMurtrey Whitaker and Associates"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2000-0431" published="2000-05-22" seq="2000-0431" severity="High" type="CVE"><desc><descript source="cve">Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000523100045.B11049@HiWAAY.net">Problem with FrontPage on Cobalt RaQ2/RaQ3</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1238">BID 1238</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4531.php">cobalt-cgiwrap-bypass(4531)</ref><ref source="CONFIRM" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0305.html">http://archives.neohapsis.com/archives/bugtraq/2000-05/0305.html</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000523100045.B11049@HiWAAY.net">20000522  Problem with FrontPage on Cobalt RaQ2/RaQ3</ref><ref source="OSVDB" url="http://www.osvdb.org/1346">1346</ref></refs><vuln_soft><prod name="Cobalt RaQ" vendor="Sun"><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-21" name="CVE-2000-0432" published="2000-05-16" seq="2000-0432" severity="High" type="CVE"><desc><descript source="cve">The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Security Focus" url="http://securityfocus.com/bid/1215">BID 1215</ref><ref patch="1" source="Matt Kruse" url="http://mkruse.netexpress.net/scripts/calendar/bugfix.html"></ref><ref patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/60376">Vuln in calender.pl (Matt Kruse calender script)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0173.html">20000516 Vuln in calender.pl (Matt Kruse calender script)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1215">1215</ref></refs><vuln_soft><prod name="Calendar Script" vendor="Matt Kruse"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0433" published="2000-05-02" seq="2000-0433" severity="Medium" type="CVE"><desc><descript source="cve">The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to gain privileges to those accounts by creating standard user startup scripts such as profiles.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1357">SuSE Linux aaabase User Account with /tmp Home Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4403.php">aaabase-execute-dot-files(4403)</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_47.html">20000502 aaabase &lt; 2000.5.2</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1 alpha"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0434" published="2000-05-13" seq="2000-0434" severity="High" type="CVE"><desc><descript source="cve">The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1217">Allmanage Administrator Password Retrieval Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4466.php">http-cgi-allmanage-plaintext-admin(4466)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0167.html">20000516 Allmanage.pl Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/1217">1217</ref></refs><vuln_soft><prod name="Allmanage" vendor="Matthew Redman"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0435" published="2000-05-13" seq="2000-0435" severity="High" type="CVE"><desc><descript source="cve">The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1217">BID 1217</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/60281">Allmanage.pl Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4465.php">http-cgi-allmanage-account-access(4465)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0167.html">20000516 Allmanage.pl Vulnerabilities</ref><ref source="BID" url="http://www.securityfocus.com/bid/1217">1217</ref><ref source="OSVDB" url="http://www.osvdb.org/1337">1337</ref></refs><vuln_soft><prod name="Allmanage" vendor="Matthew Redman"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0436" published="2000-05-19" seq="2000-0436" severity="Medium" type="CVE"><desc><descript source="cve">MetaProducts Offline Explorer 1.2 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1231">BID 1231</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/61367">MetaProducts Offline Explorer Directory Traversal Vulnerability</ref><ref patch="1" source="Offline Explorer Download" url="http://www.metaproducts.com/mpOE-HY.html">Offline Explorer Development History</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0254.html">20000522 MetaProducts Offline Explorer Directory Traversal Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1231">1231</ref></refs><vuln_soft><prod name="Offline Explorer" vendor="MetaProducts"><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0437" published="2000-05-18" seq="2000-0437" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the CyberPatrol daemon &quot;cyberdaemon&quot; used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1234">BID 1234</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4503.php">gauntlet-cyberdaemon-bo(4503)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/12/61263">ISN] Security Hole found in NAI Firewall</ref><ref source="CONFIRM" url="http://www.tis.com/support/cyberadvisory.html">http://www.tis.com/support/cyberadvisory.html</ref><ref source="CONFIRM" url="http://www.pgp.com/jump/gauntlet_advisory.asp">http://www.pgp.com/jump/gauntlet_advisory.asp</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0249.html">20000522 Gauntlet CyberPatrol Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/1234">1234</ref><ref source="OSVDB" url="http://www.osvdb.org/322">322</ref></refs><vuln_soft><prod name="Gauntlet Firewall" vendor="Network Associates"><vers num="5.5"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/></prod><prod name="WebShield E-ppliance" vendor="Network Associates"><vers num="300.0"/><vers num="100.0"/></prod><prod name="WebShield" vendor="Network Associates"><vers edition="Solaris" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-0438" published="2000-05-22" seq="2000-0438" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in fdmount on Linux systems allows local users in the &quot;floppy&quot; group to execute arbitrary commands via a long mountpoint parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1239">BID 1239</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4534.php">linux-fdmount-bo(4534)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/61564">Re: fdmount buffer overflow</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0245.html">20000522 fdmount buffer overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/1239">1239</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4.1"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="7.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="4.0"/><vers num="3.9"/><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0439" published="2000-05-11" seq="2000-0439" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the &quot;Unauthorized Cookie Access&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1194">BID 1194</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4447.php">ie-cookie-disclosure(4447)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-033.asp">ms00-33</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000511135609.D7774@securityfocus.com">20000510 IE Domain Confusion Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NDBBKGHPMKBKDDGLDEEHAEHMDIAA.rms2000@bellatlantic.net">20000511 IE Domain Confusion Vulnerability is an Email problem also</ref><ref source="BID" url="http://www.securityfocus.com/bid/1194">1194</ref><ref source="OSVDB" url="http://www.osvdb.org/1326">1326</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4447">ie-cookie-disclosure(4447)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="4.0.1"/><vers num="4.0.0.1"/><vers num="4.0"/><vers num="3.0.2"/><vers num="3.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0440" published="2000-05-01" seq="2000-0440" severity="Medium" type="CVE"><desc><descript source="cve">NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4868.php">netbsd-unaligned-ip-options(4868)</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-002.txt.asc">NetBSD-SA2000-002</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0088.html">20000506 [NHC20000504a.0: NetBSD Panics when sent unaligned IP options]</ref><ref source="BID" url="http://www.securityfocus.com/bid/1173">1173</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.4"/><vers num="4.0"/><vers num="5.0"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.1"/><vers num="1.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0441" published="2000-05-24" seq="2000-0441" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in AIX 3.2.x and 4.x allows local users to gain write access to files on locally or remotely mounted AIX filesystems.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1241">BID 1241</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4533.php">aix-local-filesystem(4533)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/advisories/2247">Filesystem vulnerability in AIX</ref><ref source="IBM" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0275.html">ERS-OAR-E01-2000:087.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1241">1241</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2000-0442" published="2000-05-24" seq="2000-0442" severity="High" type="CVE"><desc><descript source="cve">Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1242">BID 1242</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4548.php">qualcomm-qpopper-euidl(4548)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/advisories/2371">popper port contains remote vulnerability [REVISED]</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0267.html">20000523 Qpopper 2.53 remote problem, user can gain gid=mail</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_51.html">20000608 pop &lt;= 2000.3.4</ref><ref source="BID" url="http://www.securityfocus.com/bid/1242">1242</ref></refs><vuln_soft><prod name="qpopper" vendor="Qualcomm"><vers num="2.53"/><vers num="2.52"/></prod><prod name="Cobalt RaQ" vendor="Sun"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0443" published="2000-05-24" seq="2000-0443" severity="High" type="CVE"><desc><descript source="cve">The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1243">HP Web JetAdmin Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4525.php">hp-jetadmin-directory-traversal(4525)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0281.html">20000524 HP Web JetAdmin Version 5.6 Web interface Server Directory Traversal Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1243">1243</ref><ref source="OSVDB" url="http://www.osvdb.org/1350">1350</ref></refs><vuln_soft><prod name="JetAdmin" vendor="HP"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0444" published="2000-05-24" seq="2000-0444" severity="Medium" type="CVE"><desc><descript source="cve">HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1246">HP Web JetAdmin 6.0 Printing DoS Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4524.php">hp-jetadmin-malformed-url-dos(4524)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0277.html">20000524 HP Web JetAdmin Version 6.0 Remote DoS attack Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1246">1246</ref></refs><vuln_soft><prod name="JetAdmin" vendor="HP"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0445" published="2000-05-24" seq="2000-0445" severity="Low" type="CVE"><desc><descript source="cve">The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1251">Multiple Vendor PGP5 Automatic Key Generation Routine Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4570.php">pgp-key-predictable(4570)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0273.html">20000523 Key Generation Security Flaw in PGP 5.0</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2000-09.html">CA-2000-09</ref><ref source="BID" url="http://www.securityfocus.com/bid/1251">1251</ref><ref source="OSVDB" url="http://www.osvdb.org/1355">1355</ref></refs><vuln_soft><prod name="PGP" vendor="PGP"><vers num="6.5 Linux"/><vers num="5.0 Linux"/><vers num="5.0i"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0446" published="2000-05-24" seq="2000-0446" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1252">MDBMS Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0274.html">20000524 Remote xploit for MDBMS</ref><ref source="BID" url="http://www.securityfocus.com/bid/1252">1252</ref></refs><vuln_soft><prod name="MDBMS" vendor="Marty Bochane"><vers num="0.9 xbx"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0447" published="2000-05-01" seq="2000-0447" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4540.php">nai-webshield-bo(4540)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=6C740781F92BD411831F0090273A8AB806FD4A@exchange.servers.delphis.net">20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool </ref><ref source="BID" url="http://www.securityfocus.com/bid/1254">1254</ref><ref source="OSVDB" url="http://www.osvdb.org/327">327</ref></refs><vuln_soft><prod name="WebShield" vendor="Network Associates"><vers num="4.5.44"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0448" published="2000-05-01" seq="2000-0448" severity="Medium" type="CVE"><desc><descript source="cve">The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4540.php">nai-webshield(4540)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=6C740781F92BD411831F0090273A8AB806FD4A@exchange.servers.delphis.net">20000525 DST2K0003 : Buffer Overrun in NAI WebShield SMTP v4.5.44 Managem ent Tool </ref><ref source="BID" url="http://www.securityfocus.com/bid/1253">1253</ref><ref source="OSVDB" url="http://www.osvdb.org/326">326</ref></refs><vuln_soft><prod name="WebShield" vendor="Network Associates"><vers num="4.5.44"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0449" published="2000-05-01" seq="2000-0449" severity="High" type="CVE"><desc><descript source="cve">Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4543.php">omnis-studio-weak-encryption(4543)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0311.html">20000525 Omnis Weak Encryption - Many products affected</ref><ref source="BID" url="http://www.securityfocus.com/bid/1255">1255</ref></refs><vuln_soft><prod name="Studio" vendor="Omnis"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0450" published="2000-05-18" seq="2000-0450" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in bbd server in Big Brother System and Network Monitor allows an attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1257">Big Brother bbd.c Buffer Overflow Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4817.php">big-brother-bbd-bo(4817)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0216.html">20000518 FW: Security Notice: Big Brother System and Network Monitor</ref><ref source="BID" url="http://www.securityfocus.com/bid/1257">1257</ref></refs><vuln_soft><prod name="Big Brother" vendor="Sean MacGuire"><vers num="1.4h1"/><vers num="1.4g"/><vers num="1.4"/><vers num="1.3b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0451" published="2000-05-19" seq="2000-0451" severity="Medium" type="CVE"><desc><descript source="cve">The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1228">Intel Express 8100 ISDN Router Fragmented ICMP Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4818.php">intel-8100-remote-dos(4818)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0229.html">20000518 Remote Dos attack against Intel express 8100 router</ref><ref source="BID" url="http://www.securityfocus.com/bid/1228">1228</ref></refs><vuln_soft><prod name="Intel Express" vendor="Intel"><vers num="8100"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0452" published="2000-05-18" seq="2000-0452" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1229">BID 1229</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4499.php">lotus-domino-esmtp-bo(4499)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/60847">Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl))</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0219.html">20000518 Lotus ESMTP Service (Lotus Domino Release 5.0.1 (Intl))</ref><ref source="BID" url="http://www.securityfocus.com/bid/1229">1229</ref><ref source="OSVDB" url="http://www.osvdb.org/321">321</ref></refs><vuln_soft><prod name="Domino Enterprise Server" vendor="Lotus"><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/></prod><prod name="Domino Mail Server" vendor="Lotus"><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0453" published="2000-05-18" seq="2000-0453" severity="Medium" type="CVE"><desc><descript source="cve">XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1235">BID 1235</ref><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-012.0.txt">CSSA-2000-012.0</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/60869">Nasty XFree Xserver DoS</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0223.html">20000518 Nasty XFree Xserver DoS</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-012.0.txt">CSSA-2000-012.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/1235">1235</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num="4.0"/><vers num="3.3.6"/><vers num="3.3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0454" published="2000-05-29" seq="2000-0454" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux cdrecord allows local users to gain privileges via the dev parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1265">bugtraq id 1265</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4559.php">linux-cdrecord-execute(4559)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/63864">Conectiva Linux Security Announcement - cdrecord</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0367.html">20000527 Mandrake 7.0: /usr/bin/cdrecord gid=80 (strike #2)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0434.html">20000603 [Gael Duval ] [Security Announce] cdrecord</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0019.html">20000607 Conectiva Linux Security Announcement - cdrecord</ref><ref source="BID" url="http://www.securityfocus.com/bid/1265">1265</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0455" published="2000-05-29" seq="2000-0455" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in xlockmore xlock program version 4.16 and earlier allows local users to read sensitive data from memory via a long -mode option.</descript></desc><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1267">BID 1267</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4561.php">xlock-bo-read-passwd(4561)</ref><ref adv="1" patch="1" source="NetBSD" url="http://www.netbsd.org/Security/advisory.html">NetBSD-SA2000-003</ref><ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/41initialized.asp">20000529 Initialized Data Overflow in Xlock</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-003.txt.asc">NetBSD-SA2000-003</ref><ref source="TURBO" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0375.html">TLSA2000012-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1267">1267</ref></refs><vuln_soft><prod name="xlock" vendor="David Bagley"><vers num="4.16"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0456" published="2000-05-28" seq="2000-0456" severity="Low" type="CVE"><desc><descript source="cve">NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in the kernel which do not yield the CPU, aka &quot;cpu-hog&quot;.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1272">BID 1272</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4562.php">bsd-syscall-cpu-dos(4562)</ref><ref adv="1" patch="1" source="NetBSD" url="http://www.netbsd.org/Security/advisory.html">NetBSD-SA2000-005</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-005.txt.asc">NetBSD-SA2000-005</ref><ref source="BID" url="http://www.securityfocus.com/bid/1272">1272</ref><ref source="OSVDB" url="http://www.osvdb.org/1365">1365</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.2 x86"/><vers num="1.4.2 arm32"/><vers num="1.4.2 SPARC"/><vers num="1.4.2 Alpha"/><vers num="1.4.1 x86"/><vers num="1.4.1 arm32"/><vers num="1.4.1 SPARC"/><vers num="1.4.1 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0457" published="2000-05-11" seq="2000-0457" severity="High" type="CVE"><desc><descript source="cve">ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the &quot;.HTR File Fragment Reading&quot; or &quot;File Fragment Reading via .HTR&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1193">Microsoft IIS 4.0/5.0 Malformed Filename Request Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4448.php">iis-ism-file-access(4448)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95810120719608&amp;w=2">20000511 Alert: IIS ism.dll exposes file contents</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-031.mspx">MS00-031</ref><ref source="BID" url="http://www.securityfocus.com/bid/1193">1193</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0458" published="2000-04-22" seq="2000-0458" severity="Low" type="CVE"><desc><descript source="cve">The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4330.php">imp-tmpfile-view(4330)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1360">IMP/MSWordView /tmp File Permission Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95672120116627&amp;w=2">20000424 Two Problems in IMP 2</ref><ref source="BID" url="http://www.securityfocus.com/bid/1360">1360</ref></refs><vuln_soft><prod name="IMP" vendor="IMP"><vers num="2.2 pre9"/><vers num="2.2 pre10"/><vers num="2.0.9"/><vers num="2.0.11"/><vers num="2.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0459" published="2000-04-22" seq="2000-0459" severity="Medium" type="CVE"><desc><descript source="cve">IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4331.php">imp-wordfile-dos(4331)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.net/bid/1361">IMP/MSWordView /tmp File Deletion Denial of Service Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95672120116627&amp;w=2">20000424 Two Problems in IMP 2</ref><ref source="BID" url="http://www.securityfocus.com/bid/1361">1361</ref></refs><vuln_soft><prod name="IMP" vendor="IMP"><vers num="2.2 pre9"/><vers num="2.2 pre12"/><vers num="2.2 pre11"/><vers num="2.2 pre10"/><vers num="2.0.9"/><vers num="2.0.11"/><vers num="2.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0460" published="2000-05-27" seq="2000-0460" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1274">BID 1274</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4557.php">kde-display-environment-overflow(4557)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0353.html">KDE: /usr/bin/kdesud, gid = 0 exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/1274">1274</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="1.2"/><vers num="1.1.2"/><vers num="1.1.1"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0461" published="2000-05-29" seq="2000-0461" severity="Low" type="CVE"><desc><descript source="cve">The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1270">BID 1270</ref><ref adv="1" patch="1" source="NetBSD" url="http://www.netbsd.org/Security/advisory.html">NetBSD-SA2000-004</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4560.php">bsd-semaphore-dos(4560)</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata26.html#semconfig">20000526</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-004.txt.asc">NetBSD-SA2000-004</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:19.semconfig.asc">FreeBSD-SA-00:19</ref><ref source="BID" url="http://www.securityfocus.com/bid/1270">1270</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.2.8"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2"/><vers num="2.1.7.1"/><vers num="2.1.6.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.2 x86"/><vers num="1.4.2 arm32"/><vers num="1.4.2 SPARC"/><vers num="1.4.2 Alpha"/><vers num="1.4.1 arm32"/><vers num="1.4.1 SPARC"/><vers num="1.4.1 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0462" published="2000-05-28" seq="2000-0462" severity="Low" type="CVE"><desc><descript source="cve">ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1273">BID 1273</ref><ref adv="1" patch="1" source="NetBSD" url="http://www.netbsd.org/Security/">NetBSD-SA2000-006</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4568.php">netbsd-ftpchroot-parsing(4358)</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-006.txt.asc">NetBSD-SA2000-006</ref><ref source="BID" url="http://www.securityfocus.com/bid/1273">1273</ref><ref source="OSVDB" url="http://www.osvdb.org/1366">1366</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.2 x86"/><vers num="1.4.2 arm32"/><vers num="1.4.2 SPARC"/><vers num="1.4.2 Alpha"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0463" published="2000-05-18" seq="2000-0463" severity="Medium" type="CVE"><desc><descript source="cve">BeOS 5.0 allows remote attackers to cause a denial of service via fragmented TCP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1222">BID 1222</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4483.php">beos-tcp-frag-dos(4483)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/60652">AUX Security Advisory on Be/OS 5.0 (DoS)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0197.html">20000517 AUX Security Advisory on Be/OS 5.0 (DoS)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1222">1222</ref></refs><vuln_soft><prod name="BeOS" vendor="Be"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0464" published="2000-05-17" seq="2000-0464" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 4.x and 5.x allows remote attackers to execute arbitrary commands via a buffer overflow in the ActiveX parameter parsing capability, aka the &quot;Malformed Component Attribute&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1223">BID 1223</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4502.php">ie-malformed-component-attribute(4502)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-033.asp">MS00-033</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=261257">Q261257</ref><ref source="BID" url="http://www.securityfocus.com/bid/1223">1223</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.0"/><vers num="4.0.0.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0465" published="2000-05-17" seq="2000-0465" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 4.x and 5.x does properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files via the frame, aka the &quot;Frame Domain Verification&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1224">BID 1224</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4500.php">ie-frame-domain-verification(4500)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms00-033.asp">MS00-033</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=251108">Q251108</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=255676">Q255676</ref><ref source="BID" url="http://www.securityfocus.com/bid/1224">1224</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5 preview"/><vers num="5.01"/><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0466" published="2000-06-20" seq="2000-0466" severity="High" type="CVE"><desc><descript source="cve">AIX cdmount allows local users to gain root privileges via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1384">bugtraq id 1384</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise55.php"></ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0467" published="2000-06-01" seq="2000-0467" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the screen locking function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1346/">bugtraq id 1346</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20000605a">20000605 root exploit in splitvt</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0125.html">20000614 Splitvt exploit</ref><ref source="BID" url="http://www.securityfocus.com/bid/1346">1346</ref></refs><vuln_soft><prod name="splitvt" vendor="Sam Lantinga"><vers num="1.6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0468" published="2000-06-02" seq="2000-0468" severity="Medium" type="CVE"><desc><descript source="cve">man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1302">BID 1302</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0441.html">HP Securtity vulnerability in man command</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4590.php">HP man-file-overwrite</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.SOL.4.02.10006021014400.4779-100000@nofud.nwest.attws.com">20000601 HP Security vulnerability in the man command</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0469" published="2000-02-02" seq="2000-0469" severity="Medium" type="CVE"><desc><descript source="cve">Selena Sol WebBanner 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-02.html">Malicious HTML Tags Embedded in Client Web Requests</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-22&amp;msg=ILENKALMCAFBLHBGEOFKGEJCCAAA.jwesterink@jwesterink.daxis.nl">CGI: Selena Sol&apos;s WebBanner ( Random Banner Generator ) Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-6.php">WebBanner input validation error</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.2.0.58.20000620193604.00979950@mail.clark.net">20000620 Re: CGI: Selena Sol&apos;s WebBanner ( Random Banner Generator ) Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1347">1347</ref></refs><vuln_soft><prod name="WebBanner" vendor="Selena Sol"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0470" published="2000-06-01" seq="2000-0470" severity="High" type="CVE"><desc><descript source="cve">Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D704581F27ECBD31199390080C87739DD5BECE5@MAILFAXSRV">Hardware Exploit - Gets network Down</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4588.php">rompager-malformed-dos</ref><ref adv="1" source="Net Security" url="http://net-security.org/cgi-bin/bugs/fullnews.cgi?newsid959906417,99542,">Allegro rompager</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0398.html">20000601 Hardware Exploit - Gets network Down</ref><ref source="BID" url="http://www.securityfocus.com/bid/1290">1290</ref></refs><vuln_soft><prod name="ROM Pager" vendor="Allegro"><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0471" published="2000-06-14" seq="2000-0471" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ufsrestore in Solaris 8 and earlier allows local users to gain root privileges via a long pathname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1348">BID 1348</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4711.php">Solaris ufsrestore buffer overflow</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0114.html">20000614 Vulnerability in Solaris ufsrestore</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/210">00210</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/36866">VU#36866</ref><ref source="OSVDB" url="http://www.osvdb.org/1398">1398</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="5.6"/><vers num="5.5.1"/><vers edition="x86" num="5.5.1"/><vers num="5.5"/><vers edition="x86" num="5.5"/><vers num="5.4"/><vers edition="x86" num="5.4"/><vers num="5.3"/><vers edition="HW5" num="2.6"/><vers edition="HW3" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers edition="JL" num="1.1.4"/><vers num="1.1.4"/><vers edition="U1" num="1.1.3"/><vers num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1a"/><vers num="1.1"/><vers edition="x86" num="Any"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.6"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0472" published="2000-02-06" seq="2000-0472" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in innd 2.2.2 allows remote attackers to execute arbitrary commands via a cancel request containing a long message ID.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.08.innd.html">CERT* Advisory CA-97.08</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4615.php">innd-cancel-overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.10006061557230.30518-100000@squirrel.tpi.pl">innd 2.2.2 remote buffer overflow</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0003.html">20000106 innd 2.2.2 remote buffer overflow</ref><ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-016.0.txt">CSSA-2000-016.0</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0097.html">20000707 inn update</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0298.html">20000721 [ANNOUNCE] INN 2.2.3 available</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0330.html">20000722 MDKSA-2000:023 inn update</ref><ref source="BID" url="http://www.securityfocus.com/bid/1316">1316</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.2.1"/><vers num="2.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2000-0473" published="2000-06-15" seq="2000-0473" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1349">BID 1349</ref><ref patch="1" source="AnalogX" url="http://www.analogx.com/contents/download/network/sswww.htm">Product home page</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4297.php">simpleserver-get-bo(4297)</ref></refs><vuln_soft><prod name="SimpleServer" vendor="AnalogX"><vers num="1.06"/><vers num="1.05"/><vers num="1.04"/><vers num="1.03"/><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2000-0474" published="2000-06-01" seq="2000-0474" severity="High" type="CVE"><desc><descript source="cve">Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in the viewsource directory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4400.php">realserver-remote-dos(4400)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1288">BID 1288</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4587.php">realserver-malformed-remote-dos(4587)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0410.html">20000601 Remote DoS attack in Real Networks Real Server (Strike #2) Vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0427.html">20000601 Remote DoS attack in RealServer: USSR-2000043</ref></refs><vuln_soft><prod name="RealServer" vendor="RealNetworks"><vers num="7.0"/><vers num="7.0.1"/><vers num="8.0 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0475" published="2000-06-15" seq="2000-0475" severity="Medium" type="CVE"><desc><descript source="cve">Windows 2000 allows a local user process to access another user&apos;s desktop within the same windows station, aka the &quot;Desktop Separation&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-020.asp">Desktop Separation</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1350">BID 1350</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4714.php">win2k-desktop-separation(4714)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0476" published="2000-06-01" seq="2000-0476" severity="Medium" type="CVE"><desc><descript source="cve">xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0409.html">[rootshell.com] Xterm DoS Attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1298">BID 1298</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4987.php">xterm-control-characters-dos(4987)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0420.html">20000601 [rootshell.com] Xterm DoS Attack</ref></refs><vuln_soft><prod name="PuTTY" vendor="PuTTY"><vers num="0.48"/></prod><prod name="rxvt" vendor="rxvt"><vers num="2.6.1"/></prod><prod name="Eterm" vendor="Michael Jennings"><vers num="0.8.10"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="4.0"/><vers num="3.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0477" published="2000-06-14" seq="2000-0477" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1351">BID 1351</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D3947F2D8.18900.89F003@localhost">Vulnerabilities in Norton Antivirus for Exchange</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-6.php">antivirus-nav-zip-bo</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0136.html">20000614 Vulnerabilities in Norton Antivirus for Exchange</ref><ref source="XF" url="http://xforce.iss.net/static/4710.php">antivirus-nav-zip-bo</ref></refs><vuln_soft><prod name="Norton Antivirus" vendor="Symantec"><vers edition="MS Exchange" num="2.0"/><vers edition="MS Exchange" num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0478" published="2000-06-14" seq="2000-0478" severity="Medium" type="CVE"><desc><descript source="cve">In some cases, Norton Antivirus for Exchange (NavExchange) enters a &quot;fail-open&quot; state which allows viruses to pass through the server.</descript></desc><loss_types><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D3947F2D8.18900.89F003@localhost">Vulnerabilities in Norton Antivirus for Exchange</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-6.php">antivirus-nav-fail-open</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1351">BID 1351</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0136.html">20000614 Vulnerabilities in Norton Antivirus for Exchange</ref><ref source="XF" url="http://xforce.iss.net/static/4709.php">antivirus-nav-fail-open</ref><ref source="OSVDB" url="http://www.osvdb.org/6266">6266</ref></refs><vuln_soft><prod name="Norton Antivirus" vendor="Symantec"><vers edition="MS Exchange" num="2.0"/><vers edition="MS Exchange" num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0479" published="2000-06-16" seq="2000-0479" severity="Medium" type="CVE"><desc><descript source="cve">Dragon FTP server allows remote attackers to cause a denial of service via a long USER command.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4691.php">dragon-ftp-dos(4691)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1352">BID 1352</ref><ref adv="1" source="USSR Labs" url="http://www.ussrback.com/labs46.html">Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00 Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96113734714517&amp;w=2">20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00</ref></refs><vuln_soft><prod name="Dragon Server" vendor="Shadow Op Software"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0480" published="2000-06-16" seq="2000-0480" severity="Medium" type="CVE"><desc><descript source="cve">Dragon telnet server allows remote attackers to cause a denial of service via a long username.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1352">bugtraq id 1352</ref><ref adv="1" source="USSR Labs" url="http://www.ussrback.com/labs46.html">Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00 Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4690.php">dragon-telnet-dos(4690)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96113734714517&amp;w=2">20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00</ref></refs><vuln_soft><prod name="Dragon Server" vendor="Shadow Op Software"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0481" published="1999-06-01" seq="2000-0481" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1380">BID 1380</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2265.php">kde-kmail(2265)</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=82&amp;date=2000-06-22&amp;msg=00060200422401.01667@lez">KDE Heap Overflow</ref><ref source="XF" url="http://xforce.iss.net/static/4993.php">kde-kmail-attachment-dos</ref></refs><vuln_soft><prod name="K-Mail" vendor="KDE"><vers num="1.0.29.1"/><vers num="1.0.29"/><vers num="1.0.28"/><vers num="1.0.27"/><vers num="1.0.26"/><vers num="1.0.25"/><vers num="1.0.24"/><vers num="1.0.23"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0482" published="2000-06-06" seq="2000-0482" severity="Medium" type="CVE"><desc><descript source="cve">Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1312">bugtraq id 1312</ref><ref adv="1" patch="1" source="Checpoint" url="http://www.checkpoint.com/techsupport/alerts/ipfrag_dos.html">IP Fragment-driven Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.10006051908190.31513-100000@otto.spitzner.net">FW-1 IP Fragmentation Vulnerability</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#IP_Fragmentation">http://www.checkpoint.com/techsupport/alerts/list_vun.html#IP_Fragmentation</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0473.html">20000605 FW-1 IP Fragmentation Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/4609.php">fw1-packet-fragment-dos</ref><ref source="OSVDB" url="http://www.osvdb.org/1379">1379</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="1.4.1"/><vers num="1.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0483" published="2000-06-15" seq="2000-0483" severity="High" type="CVE"><desc><descript source="cve">The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4716.php">zope-dtml-remote-modify</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0144.html">Zope security alert and 2.1.7 update</ref><ref patch="1" source="Zope Org" url="http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert">Zope security alert and hotfix product</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-038.html">RHSA-2000:038</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A38.zope.asc">FreeBSD-SA-00:38</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0412.html">20000728 MDKSA-2000:026 Zope update</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000616103807.A3768@conectiva.com.br">2000615 Conectiva Linux Security Announcement - ZOPE</ref><ref source="BID" url="http://www.securityfocus.com/bid/1354">1354</ref></refs><vuln_soft><prod name="Zope" vendor="Zope"><vers num="2.1.7"/><vers num="2.1.1"/><vers num="1.10.3"/></prod><prod name="PowerTools" vendor="Linux"><vers num="6.1"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0484" published="2000-06-15" seq="2000-0484" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Small HTTP Server allows remote attackers to cause a denial of service via a long GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4692.php">small-http-get-overflow-dos(4692)</ref><ref adv="1" source="USSR Labs" url="http://www.ussrback.com/labs47.html">Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability</ref><ref patch="1" source="Max Feoktistov" url="http://wwwwin.wplus.net/pp/mrdoors/srv/index.htm">Small HTTP Server</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96113651713414&amp;w=2">20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=96151775004229&amp;w=2">20000616 Remote DoS Attack in Small HTTP Server ver. 1.212 Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1355">1355</ref></refs><vuln_soft><prod name="Small HTTP Server" vendor="Max Feoktistov"><vers num="1.212"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-0485" published="2000-05-30" seq="2000-0485" severity="Low" type="CVE"><desc><descript source="cve">Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the &quot;DTS Password&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1292">bugtraq id 1292</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4582.php">mssql-dts-reveal-passwords(4582)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-041.asp">Microsoft Security Bulletin (MS00-041)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/62771">20000530 Fw: Steal Passwords Using SQL Server EM</ref><ref source="BID" url="http://www.securityfocus.com/bid/1292">1292</ref></refs><vuln_soft><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0486" published="2000-05-30" seq="2000-0486" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Cisco TACACS+ tac_plus server allows remote attackers to cause a denial of service via a malformed packet with a long length field.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1293">bugtraq id 1293</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4598.php">tacacsplus-replay(4598)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0369.html">An Analysis of the TACACS+ Protocol and its Implementations</ref><ref source="CONFIRM" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0370.html">http://archives.neohapsis.com/archives/bugtraq/2000-05/0370.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/1293">1293</ref><ref source="XF" url="http://xforce.iss.net/static/4985.php">tacacsplus-packet-length-dos</ref></refs><vuln_soft><prod name="tac_plus" vendor="Cisco"><vers num="4.0.3alpha"/><vers num="4.0.2alpha"/></prod><prod name="IOS" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0487" published="2000-06-01" seq="2000-0487" severity="Low" type="CVE"><desc><descript source="cve">The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the &quot;Protected Store Key Length&quot; vulnerability.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1295">BID 1295</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4589.php">ms-protected-store(4589)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-032.asp">Microsoft Security Bulletin (MS00-032)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0488" published="2000-05-30" seq="2000-0488" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1285">BID 1285</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4580.php">ithouse-rcpt-overflow(4580)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0148.html">Buffer Overrun in ITHouse Mail Server v1.04</ref><ref source="BID" url="http://www.securityfocus.com/bid/1285">1285</ref></refs><vuln_soft><prod name="ITHouse Mail Server" vendor="ITHouse"><vers num="1.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0489" published="1999-09-05" seq="2000-0489" severity="Low" type="CVE"><desc><descript source="cve">FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs using the socketpair function, setting a large buffer size via setsockopt, then writing large buffers.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3298.php">bsd-setsockopt-dos(3298)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.9908270039010.16315-100000@thetis.deor.org">Local DoS in FreeBSD</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9908270039010.16315-100000@thetis.deor.org">19990826 Local DoS in FreeBSD</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NCBBKFKDOLAGKIAPMILPCEJLCEAA.labs@ussrback.com">20000601 Local FreeBSD, Openbsd, NetBSD, DoS Vulnerability - Mac OS X affected</ref><ref source="BID" url="http://www.securityfocus.com/bid/622">622</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0 alpha"/><vers num="4.0"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.1"/><vers num="3.0"/><vers num="3.2"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.2_x86"/><vers num="1.4.2_arm32"/><vers num="1.4.2_SPARC"/><vers num="1.4.2_Alpha"/><vers num="1.4.1_x86"/><vers num="1.4.1_arm32"/><vers num="1.4.1_SPARC"/><vers num="1.4.1_Alpha"/><vers num="1.4_x86"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0490" published="2000-06-01" seq="2000-0490" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1297">BID 1297</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4579.php">dmail-etrn-dos(4579)</ref><ref adv="1" patch="1" source="CGI Nessus" url="http://cgi.nessus.org/plugins/dump.php3?id=10438">Gain root remotely</ref><ref source="CONFIRM" url="http://netwinsite.com/dmail/security.htm">http://netwinsite.com/dmail/security.htm</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0407.html">20000601 Netwin&apos;s Dmail package</ref></refs><vuln_soft><prod name="Dmail" vendor="NetWin"><vers num="2.8h"/><vers num="2.8g"/><vers num="2.8f"/><vers num="2.8e"/><vers num="2.7q"/><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0491" published="2000-05-24" seq="2000-0491" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4530.php">gnome-gdm-bo(4530)</ref><ref adv="1" patch="1" source="SuSE" url="http://www.suse.de/de/support/security/suse_security_announce_49.txt">SuSE Security Announcement</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0241.html">20000521 &quot;gdm&quot; remote hole</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_49.html">20000524 Security hole in gdm &lt;= 2.0beta4-25</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0025.html">20000607 Conectiva Linux Security Announcement - gdm</ref><ref adv="1" patch="1" source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-013.0.txt">CSSA-2000-013.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/1233">1233</ref><ref source="BID" url="http://www.securityfocus.com/bid/1279">1279</ref><ref source="BID" url="http://www.securityfocus.com/bid/1370">1370</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.2"/><vers num="6.4"/></prod><prod name="gdm" vendor="GNOME"><vers num="1.0"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0492" published="2000-06-04" seq="2000-0492" severity="Medium" type="CVE"><desc><descript source="cve">PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1300">BID 1300</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4596.php">passwd-weak-encryption(4596)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0450.html">Insecure encryption in PassWD v1.2</ref><ref source="BID" url="http://www.securityfocus.com/bid/1300">1300</ref></refs><vuln_soft><prod name="PassWD" vendor="PassWD"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0493" published="2000-06-01" seq="2000-0493" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1289">BID 1289</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4602.php">timesync-bo-execute(4602</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0843.html">Vulnerability in SNTS</ref><ref source="BID" url="http://www.securityfocus.com/bid/1289">1289</ref></refs><vuln_soft><prod name="Time Sync" vendor="Atrius Trivalie SN"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2000-0494" published="2000-06-16" seq="2000-0494" severity="High" type="CVE"><desc><descript source="cve">Veritas Volume Manager creates a world writable .server_pids file, which allows local users to add arbitrary commands into the file, which is then executed by the vmsa_server script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1356">BID 1356</ref><ref adv="1" patch="1" source="Security Team" url="http://www.securiteam.com/unixfocus/Veritas_Volume_Manager_security_hole.html">Veritas Volume Manager security hole</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0151.html">Veritas Volume Manager 3.0.x hole</ref><ref source="CONFIRM" url="http://seer.support.veritas.com/tnotes/volumeman/230053.htm">http://seer.support.veritas.com/tnotes/volumeman/230053.htm</ref></refs><vuln_soft><prod name="Volume Manager" vendor="Symantec Veritas"><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0495" published="2000-05-30" seq="2000-0495" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the &quot;Malformed Windows Media Encoder Request&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4585.php">ms-malformed-media-dos(4585</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1282">bugtraq id 1282</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-038.asp">Microsoft Security Bulletin (MS00-038)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1282">1282</ref></refs><vuln_soft><prod name="Windows Media Services" vendor="Microsoft"><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-21" name="CVE-2000-0497" published="2000-06-08" seq="2000-0497" severity="Medium" type="CVE"><desc><descript source="cve">IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1328">BID 1328</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4697.php">websphere-jsp-source-read(4697)</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0263.html">IBM WebSphere JSP showcode vulnerability</ref><ref source="CONFIRM" url="http://www-4.ibm.com/software/webservers/appserv/efix.html">http://www-4.ibm.com/software/webservers/appserv/efix.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/1328">1328</ref></refs><vuln_soft><prod name="Websphere Application Server" vendor="IBM"><vers num="3.0.21"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0498" published="2000-06-08" seq="2000-0498" severity="Medium" type="CVE"><desc><descript source="cve">Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1328">BID 1328</ref><ref adv="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0250.html">Potential vulnerability in Unify eWave ServletExecFrom</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4649.php">ewave-servletexec-jsp-source-read(4649)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1328">1328</ref></refs><vuln_soft><prod name="eWave ServletExec" vendor="Unify"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0499" published="2000-06-08" seq="2000-0499" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of BEA WebLogic 3.1.8 through 4.5.1 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1328">BID 1328</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0262.html">BEA WebLogic JSP showcode vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4775.php">weblogic-file-source-read(4775)</ref><ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000612.html">http://developer.bea.com/alerts/security_000612.html</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0262.htm">20000612 BEA WebLogic JSP showcode vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/4694.php">weblogic-jsp-source-read</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="4.5.1"/><vers num="4.0.4"/><vers num="3.1.8"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0500" published="2000-06-21" seq="2000-0500" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of BEA WebLogic 5.1.0 allows a remote attacker to view source code of programs by requesting a URL beginning with /file/, which causes the default servlet to display the file without further processing.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1378">BID 1378</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4775.php">weblogic-file-source-read(4775)</ref><ref adv="1" patch="1" source="Weblogic" url="http://www.weblogic.com/docs51/admindocs/http.html">Using the WebLogic Server as a webserver</ref><ref source="CONFIRM" url="http://www.weblogic.com/docs51/admindocs/http.html#file">http://www.weblogic.com/docs51/admindocs/http.html#file</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96161462915381&amp;w=2">20000621 BEA WebLogic /file/ showcode vulnerability</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="5.1"/><vers num="4.5"/><vers num="4.0"/><vers num="3.1.8"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="5.1"/><vers num="4.5"/><vers num="4.0"/><vers num="3.1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0501" published="2000-06-16" seq="2000-0501" severity="Low" type="CVE"><desc><descript source="cve">Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command and quickly exiting the server.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4745.php">mdaemon-pass-dos(4745)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1366">BID 1366</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0277.html">mdaemon 2.8.5.0 WinNT and Win9x remote DoS</ref><ref source="BID" url="http://www.securityfocus.com/bid/1366">1366</ref></refs><vuln_soft><prod name="MDaemon" vendor="Alt-N"><vers num="2.8.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0502" published="2000-06-08" seq="2000-0502" severity="Low" type="CVE"><desc><descript source="cve">Mcafee VirusScan 4.03 does not properly restrict access to the alert text file before it is sent to the Central Alert Server, which allows local users to modify alerts in an arbitrary fashion.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1326">BID 1326</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0038.html">Mcafee Alerting DOS vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/4641.php">mcafee-alerting-dos(4641)</ref><ref source="OSVDB" url="http://www.osvdb.org/6287">6287</ref></refs><vuln_soft><prod name="VirusScan" vendor="McAfee"><vers num="4.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0503" published="2000-06-06" seq="2000-0503" severity="Low" type="CVE"><desc><descript source="cve">The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.</descript></desc><loss_types><conf/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1311">BID 1311</ref><ref adv="1" patch="1" source="Win2K security advice" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0154.html">IE 5 Cross-frame security vulnerability using IFRAME and WebBrowser control</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4500.php">ie-frame-domain-verification(4500)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.20.javascript.html">CERT Advisory CA-97.20 JavaScript Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1311">1311</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5 preview"/><vers num="5.01"/><vers num="5.0"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0504" published="2000-06-19" seq="2000-0504" severity="Medium" type="CVE"><desc><descript source="cve">libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1369">BID 1369</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4761.php">linux-libice-dos(4761)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0170.html">XFree86: libICE DoS</ref><ref source="CONFIRM" url="http://www.xfree86.org/security/">http://www.xfree86.org/security/</ref></refs><vuln_soft><prod name="X" vendor="Open Group"><vers num="11.0R6.4"/><vers num="11.0R6.3"/><vers num="11.0R6.2"/><vers num="11.0R6.1"/><vers num="11.0R6"/><vers num="11.0R5"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="4.0"/><vers num="3.3.6"/><vers num="3.3.5"/><vers num="3.3.4"/><vers num="3.3.3"/></prod><prod name="gdm" vendor="GNOME"><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-2000-0505" published="2000-05-31" seq="2000-0505" severity="Medium" type="CVE"><desc><descript source="cve">The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a URL containing a large number of / characters.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1284">BID 1284</ref><ref adv="1" patch="1" source="Security Team" url="http://www.securiteam.com/securitynews/Apache_for_Windows_vulnerable_to_root_directory_revealing.html"> Apache for Windows vulnerable to root directory revealing</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSF.4.20.0006031912360.45740-100000@alive.znep.com">IBM HTTP SERVER / APACHE</ref><ref source="XF" url="http://xforce.iss.net/static/4575.php">ibm-http-file-retrieve</ref></refs><vuln_soft><prod name="IBM HTTP Server" vendor="IBM"><vers num="1.3.6.2 win32"/><vers num="1.3.3 win32"/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers edition="Win32" num="1.3.9"/><vers edition="Win32" num="1.3.6"/><vers edition="Win32" num="1.3.12"/><vers edition="Win32" num="1.3.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-16" name="CVE-2000-0506" published="2000-06-09" seq="2000-0506" severity="High" type="CVE"><desc><descript source="cve">The &quot;capabilities&quot; feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the &quot;Linux kernel setuid/setcap vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006090852340.3475-300000@alfa.elzabsoft.pl">Sendmail &amp; procmail local root exploits on Linux kernel up to 2.2.16pre5</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-037-05.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-037.html">RHSA-2000:037</ref><ref source="SGI" url="ftp://sgigate.sgi.com/security/20000802-01-P">20000802-01-P</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0062.html">20000609 Trustix Security Advisory</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0063.html">20000608 CONECTIVA LINUX SECURITY ANNOUNCEMENT - kernel</ref><ref source="BID" url="http://www.securityfocus.com/bid/1322">1322</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2.16 pre5"/><vers num="2.2.16"/><vers num="2.2.15 pre20"/><vers num="2.2.15 pre16"/><vers num="2.2.15"/><vers num="2.2.14"/><vers num="2.2.13"/><vers num="2.2.12"/><vers num="2.2.10"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0.38"/><vers num="2.0.37"/><vers num="2.0.36"/><vers num="2.0.35"/><vers num="2.0.34"/><vers num="2.0.33"/><vers num="2.0.30"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0507" published="2000-06-01" seq="2000-0507" severity="Medium" type="CVE"><desc><descript source="cve">Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1286">BID 1286</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4586.php">nt-webmail-dos(4586)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95990195708509&amp;w=2">Denial of Service Possibility</ref></refs><vuln_soft><prod name="Imate Webmail Server" vendor="Concatus"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0508" published="1994-12-19" seq="2000-0508" severity="Medium" type="CVE"><desc><descript source="cve">rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1372">BID 1372</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0073.html">Remote DOS in linux rpc.lockd</ref><ref source="XF" url="http://xforce.iss.net/static/5050.php">linux-lockd-remote-dos</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0509" published="2000-06-01" seq="2000-0509" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1287">BID 1287</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4592.php">sambar-dll-bo(4592)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95990103207665&amp;w=2">20000601 DST2K0008: Buffer Overrun in Sambar Server 4.3</ref></refs><vuln_soft><prod name="Sambar Server" vendor="Sambar"><vers num="4.3 beta 9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0510" published="2000-06-21" seq="2000-0510" severity="Medium" type="CVE"><desc><descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a malformed IPP request.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1373">BID 1373</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4736.php">debian-cups-malformed-ipp (4736)</ref><ref adv="1" patch="1" source="Easy SW" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch">CUPS 1.0.5 Denial of Service Patch Set #1</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref><ref source="XF" url="http://xforce.iss.net/static/4846.php">debian-cups-malformed-ipp</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.3"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2000-0511" published="2000-06-21" seq="2000-0511" severity="Medium" type="CVE"><desc><descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service via a CGI POST request.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1373">BID 1373</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4736.php">debian-cups-malformed-ipp (4736)</ref><ref adv="1" patch="1" source="Easy SW" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch">CUPS 1.0.5 Denial of Service Patch Set #1</ref><ref source="CONFIRM" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch">ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref><ref source="XF" url="http://xforce.iss.net/static/4846.php">debian-cups-posts</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.3"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2000-0512" published="2000-06-16" seq="2000-0512" severity="Medium" type="CVE"><desc><descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier does not properly delete request files, which allows a remote attacker to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1373">BID 1373</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4736.php">debian-cups-malformed-ipp (4736)</ref><ref adv="1" patch="1" source="Easy SW" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch">CUPS 1.0.5 Denial of Service Patch Set #1</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref><ref source="XF" url="http://xforce.iss.net/static/4846.php">debian-cups-posts</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2000-0513" published="2000-06-21" seq="2000-0513" severity="Medium" type="CVE"><desc><descript source="cve">CUPS (Common Unix Printing System) 1.04 and earlier allows remote attackers to cause a denial of service by authenticating with a user name that does not exist or does not have a shadow password.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1373">BID 1373</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4736.php">debian-cups-malformed-ipp (4736)</ref><ref adv="1" patch="1" source="Easy SW" url="ftp://ftp.easysw.com/pub/cups/1.0.5/cups-DoS.patch">CUPS 1.0.5 Denial of Service</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0188.html">20000620 CUPS DoS Bugs</ref><ref source="BID" url="http://www.securityfocus.com/bid/1373">1373</ref><ref source="XF" url="http://xforce.iss.net/static/4846.php">debian-cups-posts</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0514" published="2000-06-14" seq="2000-0514" severity="High" type="CVE"><desc><descript source="cve">GSSFTP FTP daemon in Kerberos 5 1.1.x does not properly restrict access to some FTP commands, which allows remote attackers to cause a denial of service, and local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dldvsnufao18.fsf@saint-elmos-fire.mit.edu">REMOTE ROOT VULNERABILITY IN GSSFTP DAEMON</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4734.php">kerberos-gssftpd-dos(4734)</ref><ref adv="1" patch="1" source="MIT" url="http://web.mit.edu/kerberos/www/advisories/ftp.txt">REMOTE ROOT VULNERABILITY IN GSSFTP DAEMON</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=ldvsnufao18.fsf@saint-elmos-fire.mit.edu">20000614 Security Advisory: REMOTE ROOT VULNERABILITY IN GSSFTP DAEMON</ref><ref source="BID" url="http://www.securityfocus.com/bid/1374">1374</ref><ref source="OSVDB" url="http://www.osvdb.org/4885">4885</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="1.1"/><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0515" published="2000-06-07" seq="2000-0515" severity="High" type="CVE"><desc><descript source="cve">The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200006070511.OAA05492@dogfoot.hackerslab.org">HP-UX SNMP daemon vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4643.php">hpux-snmp-daemon</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1282">BID 1282</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006070511.OAA05492@dogfoot.hackerslab.org">20000607 [ Hackerslab bug_paper ] HP-UX SNMP daemon vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006090640.XAA00779@hpchs.cup.hp.com">20000608 Re: HP-UX SNMP daemon vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1327">1327</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.00"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-09" name="CVE-2000-0516" published="2000-06-06" seq="2000-0516" severity="High" type="CVE"><desc><descript source="cve">When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1329">BID 1329</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0008.html">Shiva Access Manager 5.0.0 Plaintext LDAP root password</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4612.php">shiva-plaintext-ldap-password(4612)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1329">1329</ref></refs><vuln_soft><prod name="Shiva Access Manager" vendor="Intel"><vers num="5.0 Solaris"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0517" published="2000-05-26" seq="2000-0517" severity="Medium" type="CVE"><desc><descript source="cve">Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site&apos;s DNS information.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-08.html">CERT Advisory CA-2000-08 Inconsistent Warning Messages in Netscape Navigator</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1260">BID 1260</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4550.php">netscape-ssl-certificate(4550)</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.73"/><vers num="4.72"/><vers num="4.7"/><vers num="4.61"/><vers num="4.6"/><vers num="4.51"/><vers num="4.5"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0518" published="2000-06-05" seq="2000-0518" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 4.x and 5.x does not properly verify all contents of an SSL certificate if a connection is made to the server via an image or a frame, aka one of two different &quot;SSL Certificate Validation&quot; vulnerabilities.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1309">BID 1309</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-039.asp">Patch Available for SSL Certificate Validation Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4624.php">ie-revalidate-certificate(4627)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-10.html">CERT Advisory CA-2000-10 Inconsistent Warning Messages in Internet Explorer</ref><ref source="" url="http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt"></ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows NT 4.0" num="5.0.1"/><vers edition="Windows 98" num="5.0.1"/><vers edition="Windows 95" num="5.0.1"/><vers edition="Windows 2000" num="5.0.1"/><vers edition="Windows NT 4.0" num="50"/><vers edition="Windows 98" num="5.0"/><vers edition="Windows 95" num="5.0"/><vers edition="Windows 2000" num="5.0"/><vers edition="Windows NT" num="4.0.1"/><vers edition="Windows 98" num="4.0.1"/><vers edition="Windows 95" num="4.0.1"/><vers edition="Windows NT" num="4.0"/><vers edition="Windows 98" num="4.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0519" published="2000-06-05" seq="2000-0519" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different &quot;SSL Certificate Validation&quot; vulnerabilities.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1309">BID 1309</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-039.asp">Patch Available for SSL Certificate Validation</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4627.php">ie-revalidate-certificate(4627)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-10.html">CERT Advisory CA-2000-10 Inconsistent Warning Messages in Internet Explorer</ref><ref source="" url="http://www.acrossecurity.com/aspr/ASPR-1999-12-15-1-PUB.txt"></ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers edition="Windows NT 4.0" num="5.0.1"/><vers edition="Windows 98" num="5.0.1"/><vers edition="Windows 95" num="5.0.1"/><vers edition="Windows 2000" num="5.0.1"/><vers edition="Windows NT 4.0" num="5.0"/><vers edition="Windows 98" num="5.0"/><vers edition="Windows 95" num="5.0"/><vers edition="Windows 2000" num="5.0"/><vers edition="Windows NT" num="4.0.1"/><vers edition="Windows 98" num="4.0.1"/><vers edition="Windows 95" num="4.0.1"/><vers edition="Windows NT" num="4.0"/><vers edition="Windows 98" num="4.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0520" published="2000-06-07" seq="2000-0520" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1330">BID 1330</ref><ref adv="1" patch="1" source="RedHat" url="http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11880">Typo in tape.c potential hazard</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000630102252.A19749@conectiva.com.br">MDKSA-2000:018 dump update</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96240393814071&amp;w=2">20000630 CONECTIVA LINUX SECURITY ANNOUNCEMENT - dump</ref></refs><vuln_soft><prod name="POP dump" vendor="Stelian"><vers num="0.4b9.9"/><vers num="0.4b9.0"/><vers num="0.4b17.0"/><vers num="0.4b16.0"/><vers num="0.4b15.30"/><vers num="0.4b15.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0521" published="2000-06-05" seq="2000-0521" severity="Medium" type="CVE"><desc><descript source="cve">Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the HTTP version number.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1313">BID 1313</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4616.php">savant-source-read(4616)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0469.html">Reading of CGI Scripts under Savant Webserver</ref></refs><vuln_soft><prod name="Savant WebServer" vendor="Michael Lamont"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0522" published="2000-06-08" seq="2000-0522" severity="Medium" type="CVE"><desc><descript source="cve">RSA ACE/Server allows remote attackers to cause a denial of service by flooding the server&apos;s authentication request port with UDP packets, which causes the server to crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1332">BID 1332</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0197.html">RSA Aceserver UDP Flood Vulnerability</ref><ref adv="1" patch="1" source="Secure ID" url="ftp://ftp.securid.com/support/outgoing/dos/readme.txt">ACE/Server</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5053.php">aceserver-udp-packet-dos(5053)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=011a01bfd14c$3c206960$050010ac@xtranet.co.uk">20000608 Potential DoS Attack on RSA&apos;s ACE/Server</ref></refs><vuln_soft><prod name="ACE Server" vendor="RSA"><vers num="4.1"/><vers num="4.0"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0523" published="2000-06-06" seq="2000-0523" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1315">bugtraq id 1315</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4614.php">eserv-logging-overflow(4614)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0009.html">MDMA Advisory #6: EServ Logging Heap Overflow Vulnerability</ref></refs><vuln_soft><prod name="Eserv" vendor="Etype"><vers num="2.9.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-0524" published="2000-06-05" seq="2000-0524" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1333">BID 1333</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0045.html">Microsoft Outlook (Express) bug..</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4645.php">outlook-header-dos(4645)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="97"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0525" published="2000-06-08" seq="2000-0525" severity="High" type="CVE"><desc><descript source="cve">OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4646.php">openssh-uselogin-remote-exec(4646)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-06-8%26msg%3D20000609170629.A4933@folly.informatik.uni-erlangen.de">OpenSSH&apos;s UseLogin option allows remote access with root privilege</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-06-08%26msg%3D20000610141156.F3275@conectiva.com.br">CONECTIVA LINUX SECURITY ANNOUNCEMENT</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0065.html">20000609 OpenSSH&apos;s UseLogin option allows remote access with root privilege.</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html#uselogin">20000606 The non-default UseLogin feature in /etc/sshd_config is broken and should not be used.</ref><ref source="BID" url="http://www.securityfocus.com/bid/1334">1334</ref><ref source="OSVDB" url="http://www.osvdb.org/341">341</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="2.1"/><vers num="1.2.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0526" published="2000-06-09" seq="2000-0526" severity="Medium" type="CVE"><desc><descript source="cve">mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1335">BID 1335</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4737.php">mailstudio-view-files(4737)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0081.html">Mailstudio2000 CGI Vulnerabilities [S0ftPj.4]</ref></refs><vuln_soft><prod name="MailStudio 2000" vendor="3R Soft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0527" published="2000-06-09" seq="2000-0527" severity="High" type="CVE"><desc><descript source="cve">userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4740.php">http-cgi-mailstudio-bo(4740)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1335">BID 1335</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-06-15%26msg%3D394223B8.A61C0517@relaygroup.com">Re: Mailstudio2000 CGI Vulnerabilities</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0081.html">20000609 Mailstudio2000 CGI Vulnerabilities [S0ftPj.4]</ref></refs><vuln_soft><prod name="MailStudio 2000" vendor="3R Soft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0528" published="2000-06-19" seq="2000-0528" severity="Medium" type="CVE"><desc><descript source="cve">Net Tools PKI Server does not properly restrict access to remote attackers when the XUDA template files do not contain absolute pathnames for other files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1364">BID 1364</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4743.php">nettools-pki-unauthenticated-access(4743)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0166.html">Net Tools PKI server exploits</ref><ref source="CONFIRM" url="ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt">ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/4353">4353</ref></refs><vuln_soft><prod name="Net Tools PKI Server" vendor="Network Associates"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0529" published="2000-06-19" seq="2000-0529" severity="Medium" type="CVE"><desc><descript source="cve">Net Tools PKI Server allows remote attackers to cause a denial of service via a long HTTP request.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1363">BID 1363</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0166.html">Net Tools PKI server exploits</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4744.php">nettools-pki-http-bo(4744)</ref><ref source="CONFIRM" url="ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt">ftp://ftp.tis.com/gauntlet/hide/pki/hotfix.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/4352">4352</ref></refs><vuln_soft><prod name="Net Tools PKI Server" vendor="Network Associates"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0530" published="2000-05-31" seq="2000-0530" severity="High" type="CVE"><desc><descript source="cve">The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4583.php">kde-configuration-file-creation(4583)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1291">BID 1291</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0387.html">KDE::KApplication feature?</ref><ref source="CALDERA" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-015.0.txt">CSSA-2000-015.0</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-032.html">RHSA-2000:032</ref></refs><vuln_soft><prod name="KDE" vendor="KDE"><vers num="1.1.2"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0531" published="1999-11-23" seq="2000-0531" severity="Low" type="CVE"><desc><descript source="cve">Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1377">BID 1377</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10006201453090.1812-200000@apollo.aci.com.pl">Bug in gpm</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5010.php">linux-gpm-gpmctl-dos(5010)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-045.html">RHSA-2000:045</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0409.html">20000728 MDKSA:2000-025 gpm update</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.1"/><vers edition="i386" num="6.0"/></prod><prod name="OpenLinux Eserver" vendor="Caldera"><vers num="2.3"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0532" published="2000-06-07" seq="2000-0532" severity="High" type="CVE"><desc><descript source="cve">A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1323">BID 1323</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/freebsd/2000-06/0031.html">FreeBSD Security Advisory: FreeBSD-SA-00:21.ssh [REVISED</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4638.php">freebsd-ssh-ports(4638)</ref><ref source="OSVDB" url="http://www.osvdb.org/1387">1387</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0533" published="2000-06-20" seq="2000-0533" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1379">BID 1379</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4725.php">irix-workshop-cvconnect-overwrite(4725)</ref><ref source="SGI" url="ftp://sgigate.sgi.com/security/20000601-01-P">20000601-01-P</ref></refs><vuln_soft><prod name="Workshop Debugger and Performance Tools" vendor="SGI"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0534" published="2000-06-07" seq="2000-0534" severity="Medium" type="CVE"><desc><descript source="cve">The apsfilter software in the FreeBSD ports package does not properly read user filter configurations, which allows local users to execute commands as the lpd user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1325">BID 1325</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4642.php">freebsd-port-apsfilter(4642)</ref><ref adv="1" patch="1" source="FreeBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-06/0030.html">: FreeBSD Security Advisory: FreeBSD-SA-00:22.apsfilter</ref><ref source="XF" url="http://xforce.iss.net/static/4617.php">apsfilter-elevate-privileges</ref><ref source="OSVDB" url="http://www.osvdb.org/1389">1389</ref></refs><vuln_soft><prod name="apsfilter" vendor="APS Filter Development Team"><vers num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-0535" published="2000-06-12" seq="2000-0535" severity="Medium" type="CVE"><desc><descript source="cve">OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1340">BID 1340</ref><ref adv="1" patch="1" source="FreeBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-06/0083.html">FreeBSD Security Advisory: FreeBSD-SA-00:25.alpha-dev-random</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4704.php">freebsd-alpha-weak-encryption(4704)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0 alpha"/><vers num="4.0 alpha"/></prod><prod name="OpenSSL" vendor="OpenSSL Project"><vers num="0.9.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0536" published="2000-06-04" seq="2000-0536" severity="High" type="CVE"><desc><descript source="cve">xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="synack" url="http://www.synack.net/xinetd/">hompepage</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1381">BID 1381</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4986.php">xinetd-improper-restrictions(4986)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20000619">20000619 xinetd: bug in access control mechanism</ref></refs><vuln_soft><prod name="xinetd" vendor="xinetd"><vers num="2.1.89 pre5"/><vers num="2.1.89 pre4"/><vers num="2.1.89 pre3"/><vers num="2.1.89 pre2"/><vers num="2.1.89 pre1"/><vers num="2.1.88 pre2"/><vers num="2.1.88 pre1"/><vers num="2.1.88"/><vers num="2.1.87"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2000-0537" published="2000-06-05" seq="2000-0537" severity="High" type="CVE"><desc><descript source="cve">BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file with the BRUEXECLOG environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4644.php">bru-execlog-env-variable(4644)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1321">BID 1321</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0013.html">BRU Vulnerability</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-018.0.txt">CSSA-2000-018.0</ref></refs><vuln_soft><prod name="BRU" vendor="Tolis Group"><vers num="16.0"/><vers num="15.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0538" published="2000-06-07" seq="2000-0538" severity="Medium" type="CVE"><desc><descript source="cve">ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a long login password.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4611.php">coldfusion-parse-dos(4611)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1314">BID 1314</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=16122&amp;Method=Full">Workaround available for Denial of Service attack against ColdFusion Administrator</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96045469627806&amp;w=2">20000607 New Allaire ColdFusion DoS</ref><ref source="OSVDB" url="http://www.osvdb.org/3399">3399</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.5.1"/><vers num="4.5"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.12"/><vers num="3.11"/><vers num="3.1"/><vers num="3.01"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-0539" published="2000-06-22" seq="2000-0539" severity="Medium" type="CVE"><desc><descript source="cve">Servlet examples in Allaire JRun 2.3.x allow remote attackers to obtain sensitive information, e.g. listing HttpSession ID&apos;s via the SessionServlet servlet.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4774.php">jrun-read-sample-files(4774)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1386">BID 1386</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=16290&amp;Method=Full">Workaround available for vulnerabilities exposed by JRun 2.3.x code sample</ref><ref source="OSVDB" url="http://www.osvdb.org/818">818</ref></refs><vuln_soft><prod name="JRun" vendor="Macromedia"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-0540" published="2000-06-22" seq="2000-0540" severity="Medium" type="CVE"><desc><descript source="cve">JSP sample files in Allaire JRun 2.3.x allow remote attackers to access arbitrary files (e.g. via viewsource.jsp) or obtain configuration information.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4774.php">jrun-read-sample-files(4774)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1386">BID 1386</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=16290&amp;Method=Full">Workaround available for vulnerabilities exposed by JRun 2.3.x code sample</ref><ref source="OSVDB" url="http://www.osvdb.org/2713">2713</ref></refs><vuln_soft><prod name="JRun" vendor="Macromedia"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2000-0541" published="2000-06-17" seq="2000-0541" severity="High" type="CVE"><desc><descript source="cve">The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1359">BID 1359</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4707.php">panda-antivirus-remote-admin(4707)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0164.html">Infosec.20000617.panda.a</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4707">panda-antivirus-remote-admin(4707)</ref></refs><vuln_soft><prod name="Panda AntiVirus" vendor="Panda"><vers edition="NetWare" num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0542" published="2000-06-13" seq="2000-0542" severity="Medium" type="CVE"><desc><descript source="cve">Tigris remote access server before 11.5.4.22 does not properly record Radius accounting information when a user fails the initial login authentication but subsequently succeeds.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1345">bugtraq id 1345</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4705.php">tigris-radius-login-failure</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0104.html">ACC/Ericsson Tigris Accounting Failure</ref></refs><vuln_soft><prod name="AXC Tigris MultiService Access Platform" vendor="Ericsson"><vers num="711.0"/><vers num="627.0"/><vers num="623.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0543" published="2000-06-14" seq="2000-0543" severity="Medium" type="CVE"><desc><descript source="cve">The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not have a reverse DNS entry and they connect to port 4000.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1343">bugtraq id 1343</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4695.php">XF:pgp-cert-server-dos(4695)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0107.html">Remote DoS attack in Networks Associates PGP Certificate Server Version 2.5 Vulnerability</ref></refs><vuln_soft><prod name="PGP Certificate Server" vendor="PGP"><vers num="2.5.1"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0544" published="2000-06-05" seq="2000-0544" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1304">BID 1304</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4600.php">nt-smb-request-dos(4600)</ref><ref adv="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0231.html">anonymous SMBwriteX DoS</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0545" published="2000-08-08" seq="2000-0545" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (carbon copy) parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20000810">mailx</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1371.php">sgi-mailx-bo(1371)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0435.html">/usr/bin/Mail exploit for Slackware 7.0 (mail-slack.c)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20000605">20000605 mailx: mail group exploit in mailx</ref><ref source="BID" url="http://www.securityfocus.com/bid/1305">1305</ref></refs><vuln_soft><prod name="mailx" vendor="SGI"><vers num="3"/><vers num="4"/><vers num="5"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0546" published="2000-06-09" seq="2000-0546" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html">CERT Advisory CA-2000-11 MIT Kerberos Vulnerable to Denial-of-Service Attacks</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4656.php">kerberos-lastrealm-bo</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html">MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref><ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref><ref source="BID" url="http://www.securityfocus.com/bid/1338">1338</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="krb5_1.0"/><vers num="krb5_1.1"/><vers num="krb5_1.1.1"/></prod><prod name="CyGNUs Network Security" vendor="CyGNUs"><vers num=""/></prod><prod name="KerbNet" vendor="CyGNUs"><vers num=""/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0 patch 10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0547" published="2000-06-09" seq="2000-0547" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html">CA-2000-11</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4656.php">kerberos-lastrealm-bo</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref><ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref><ref source="BID" url="http://www.securityfocus.com/bid/1338">1338</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="krb5_1.0"/><vers num="krb5_1.1"/><vers num="krb5_1.1.1"/></prod><prod name="CyGNUs Network Security" vendor="CyGNUs"><vers num=""/></prod><prod name="KerbNet" vendor="CyGNUs"><vers num=""/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0 patch 10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2000-0548" published="2000-06-09" seq="2000-0548" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html">CERT Advisory CA-2000-11 MIT Kerberos Vulnerable to Denial-of-Service Attacks</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4658.php">kerberos-emsg-bo</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html">MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref><ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-031.html">RHSA-2000:031</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref><ref source="OSVDB" url="http://www.osvdb.org/4875">4875</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="krb5_1.0"/><vers num="krb5_1.1"/><vers num="krb5_1.1.1"/></prod><prod name="CyGNUs Network Security" vendor="CyGNUs"><vers num=""/></prod><prod name="KerbNet" vendor="CyGNUs"><vers num=""/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0 patch 10" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2000-0549" published="2000-06-09" seq="2000-0549" severity="Medium" type="CVE"><desc><descript source="cve">Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1464">BID 1464</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html">CERT Advisory CA-2000-11</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html">MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref><ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-031.html">RHSA-2000:031</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="5.0_1.1.1"/><vers num="5.0_1.1"/><vers num="5.0_1.0"/></prod><prod name="CyGNUs Network Security" vendor="CyGNUs"><vers num="4.0"/></prod><prod name="KerbNet" vendor="CyGNUs"><vers num="5.0"/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0 patch 10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0550" published="2000-06-09" seq="2000-0550" severity="Medium" type="CVE"><desc><descript source="cve">Kerberos 4 KDC program improperly frees memory twice (aka &quot;double-free&quot;), which allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1464">BID 1464</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4660.php">kerberos-free-memory</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-11.html">CERT Advisory CA-2000-11</ref><ref source="CONFIRM" url="http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt">http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html">20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-031.html">RHSA-2000:031</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/k-051.shtml">K-051</ref><ref source="BID" url="http://www.securityfocus.com/bid/1465">1465</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="5.0_1.1.1"/><vers num="5.0_1.1"/><vers num="5.0_1.0"/></prod><prod name="CyGNUs Network Security" vendor="CyGNUs"><vers num="4.0"/></prod><prod name="KerbNet" vendor="CyGNUs"><vers num="5.0"/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0 patch 10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0551" published="2000-05-23" seq="2000-0551" severity="High" type="CVE"><desc><descript source="cve">The file transfer mechanism in Danware NetOp 6.0 does not provide authentication, which allows remote attackers to access and modify arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1263">BID 1263</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4569.php">danware-netop-bypass-security(4569)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0339.html">I Think</ref></refs><vuln_soft><prod name="NetOp" vendor="Danware Data"><vers num="6.50"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0552" published="2000-06-06" seq="2000-0552" severity="Low" type="CVE"><desc><descript source="cve">ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allows local users to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1307">BID 1307</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0237.html">ICQwebmail temparary internet link</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4607.php">icq-temp-link(4607)</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="2000.0A"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0553" published="2000-05-26" seq="2000-0553" severity="Low" type="CVE"><desc><descript source="cve">Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping &quot;return-rst&quot; and &quot;keep state&quot; rules, allows remote attackers to bypass access restrictions.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1308">BID 1308</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-05/0326.html">Security Vulnerability in IPFilter 3.3.15 and 3.4.3</ref><ref source="XF" url="http://xforce.iss.net/static/4994.php">ipfilter-firewall-race-condition</ref><ref source="OSVDB" url="http://www.osvdb.org/1377">1377</ref></refs><vuln_soft><prod name="IPFilter" vendor="Darren Reed"><vers num="3.4.3"/><vers num="3.3.15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0554" published="2000-06-08" seq="2000-0554" severity="Medium" type="CVE"><desc><descript source="cve">Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1320">BID 1320</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4620.php">ceilidh-path-disclosure</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0246.html">DoS, Path Revealing &amp; Buffer Overrun Vulnerability in Ceilidh &gt; v2.60a</ref></refs><vuln_soft><prod name="Ceilidh" vendor="Lilikoi"><vers num="2.60"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0555" published="2000-06-09" seq="2000-0555" severity="Medium" type="CVE"><desc><descript source="cve">Ceilidh allows remote attackers to cause a denial of service via a large number of POST requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1320">BID 1320</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4622.php">ceilidh-post-dos(4622)</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0246.html">Title : DoS, Path Revealing &amp; Buffer Overrun Vulnerability in Ceilidh &gt; v2.60a</ref></refs><vuln_soft><prod name="Ceilidh" vendor="Lilikoi"><vers num="2.60"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0556" published="2000-06-05" seq="2000-0556" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to cause a denial of service by sending a large user name to the user dialog running on port 8002.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1319">BID 1319</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4625.php">cmail-long-username-dos(4625)</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0248.html">DoS &amp; BufferOverrun in CMail v2.4.7 WebMail</ref><ref source="CONFIRM" url="http://www.computalynx.net/news/Jun2000/news0806200001.html">http://www.computalynx.net/news/Jun2000/news0806200001.html</ref></refs><vuln_soft><prod name="Cmail" vendor="Computalynx"><vers num="2.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0557" published="2000-06-05" seq="2000-0557" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the web interface for Cmail 2.4.7 allows remote attackers to execute arbitrary commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1318">bugtraq id 1318</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4626.php">:cmail-get-overflow-execute(4626)</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0248.html">DoS &amp; BufferOverrun in CMail v2.4.7 WebMail</ref></refs><vuln_soft><prod name="Cmail" vendor="Computalynx"><vers num="2.4.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0558" published="2000-06-06" seq="2000-0558" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HP Openview Network Node Manager 6.1 allows remote attackers to execute arbitrary commands via the Alarm service (OVALARMSRV) on port 2345.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4619.php">hp-openview-nnm-bo(4619)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1317">BID 1317</ref><ref adv="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0249.html">BufferOverrun in HP Openview Network Node Manager v6.1</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0559" published="2000-06-07" seq="2000-0559" severity="Low" type="CVE"><desc><descript source="cve">eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1341">BID 1341</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5051.php">etrust-weak-password-encryption(5051)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSO.4.21.0006072124320.28062-100000@bearclaw.bogus.net">20000607 SessionWall-3 Paper + (links to) code</ref></refs><vuln_soft><prod name="eTrust Intrusion Detection" vendor="Computer Associates"><vers num="1.4.1.13" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0561" published="2000-06-19" seq="2000-0561" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1365">BID 1365</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4742.php">webbbs-get-request-overflow(4742)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0175.html">Multiple BufferOverruns in WebBBS HTTP Server v1.15</ref><ref source="OSVDB" url="http://www.osvdb.org/3544">3544</ref></refs><vuln_soft><prod name="International TeleCommunications WebBBS" vendor="International TeleCommunications"><vers num="1.17"/><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2000-0562" published="2000-06-22" seq="2000-0562" severity="High" type="CVE"><desc><descript source="cve">BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-6.php">blackice-security-level-nervous(4777)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1389">BID 1389</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0190.html">BlackICE by Network ICE Corp vulnerability against Back Orifice 1.2</ref></refs><vuln_soft><prod name="BlackICE Agent" vendor="Internet Security Systems"><vers num="2.0.23" prev="1"/></prod><prod name="BlackICE Defender" vendor="Internet Security Systems"><vers num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0563" published="2000-10-20" seq="2000-0563" severity="High" type="CVE"><desc><descript source="cve">The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0056.html">Security Holes Found in URLConnection of MRJ and IE of Mac OS (was Re: Reappearance of an old IE security bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/1336">1336</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-05-8&amp;msg=391C95DE2DA.5E3BTAKAGI@java-house.etl.go.jp">20000513 Re: Reappearance of an old IE security bug</ref></refs><vuln_soft><prod name="Mac OS Runtime" vendor="Apple"><vers edition="Java" num="2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0564" published="2000-05-29" seq="2000-0564" severity="Medium" type="CVE"><desc><descript source="cve">The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1463">BID 1463</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4077.php">icq-pws-guestbook-dos(4077</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0218.html">ICQ Web Front Remote DoS Attack Vulnerability</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="98.0a"/><vers num="2000.0A"/><vers num="0.99b v.3.19"/><vers num="0.99b 1.1.1.1"/><vers num="99a 2.21Build1800"/><vers num="99a 2.15Build1701"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0565" published="2000-06-13" seq="2000-0565" severity="Low" type="CVE"><desc><descript source="cve">SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1344">BID 1344</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4706.php">smartftp-directory-traversal(4706)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0100.html">SmartFTP Daemon v0.2 Beta Build 9 - Remote Exploit</ref><ref source="OSVDB" url="http://www.osvdb.org/1394">1394</ref></refs><vuln_soft><prod name="SmartFTP Daemon" vendor="Mindstorm"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0566" published="2000-07-03" seq="2000-0566" severity="High" type="CVE"><desc><descript source="cve">makewhatis in Linux man package allows local users to overwrite files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1434">BID 1434</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4900.php">linux-man-makewhatis-tmp(4900)</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-041-02.html">man package&apos;s &apos;makewhatis&apos; uses insecure handling of files in /tmp</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-041.html">RHSA-2000:041</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-021.0.txt">CSSA-2000-021.0</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:015">MDKSA-2000:015</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0390.html">20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - MAN</ref><ref source="BID" url="http://www.securityfocus.com/bid/1434">1434</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/><vers edition="Sparc" num="6.0"/><vers edition="i386" num="6.0"/><vers edition="Alpha" num="6.0"/><vers edition="Sparc" num="5.2"/><vers edition="i386" num="5.2"/><vers edition="Alpha" num="5.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0567" published="2000-07-18" seq="2000-0567" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a long Date field in an email header, aka the &quot;Malformed E-mail Header&quot; vulnerability.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1481">BID 1481</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise57.php">Buffer Overflow in Microsoft Outlook and Outlook Express Mail Clients</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/fq00-043.asp">Microsoft Security Bulletin (MS00-043):</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-043.mspx">MS00-043</ref><ref source="BID" url="http://www.securityfocus.com/bid/1481">1481</ref><ref source="XF" url="http://xforce.iss.net/static/4953.php">outlook-date-overflow</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="97"/><vers num="98"/><vers num="2000"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="5.0"/><vers num="4.01"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0568" published="2000-06-30" seq="2000-0568" severity="Medium" type="CVE"><desc><descript source="cve">Sybergen Secure Desktop 2.1 does not properly protect against false router advertisements (ICMP type 9), which allows remote attackers to modify default routes.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1417">BID 1417</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4827.php">sybergen-routing-table-modify</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4125690E.00524395.00@guardianit.se">: Multiple vulnerabilities in Sybergen Secure Desktop</ref><ref source="BID" url="http://www.securityfocus.com/bid/1417">1417</ref></refs><vuln_soft><prod name="Secure Desktop" vendor="Sybergen"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0569" published="2000-06-30" seq="2000-0569" severity="Medium" type="CVE"><desc><descript source="cve">Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its internal interface.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1420">BID 1420</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0189.html">Any LAN user can crash Sygate</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5049.php">sygate-udp-packet-dos(5049)</ref></refs><vuln_soft><prod name="SyGate" vendor="Sybergen"><vers num="3.11"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0570" published="2000-06-27" seq="2000-0570" severity="Medium" type="CVE"><desc><descript source="cve">FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1421">BID 1421</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4843.php">firstclass-large-bcc-dos</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0295.html">DoS in FirstClass Internet Services 5.770</ref><ref source="OSVDB" url="http://www.osvdb.org/5718">5718</ref></refs><vuln_soft><prod name="FirstClass Intranet Server" vendor="Centrinity"><vers num="5.770"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0571" published="2000-07-05" seq="2000-0571" severity="Medium" type="CVE"><desc><descript source="cve">LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1423">BID 1423</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4896.php">localweb-get-bo(4896)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-07-8&amp;msg=NCBBKFKDOLAGKIAPMILPCEIHCFAA.labs@ussrback.com">: Remote DoS Attack in LocalWEB HTTP Server 1.2.0 Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1423">1423</ref></refs><vuln_soft><prod name="LocalWEB HTTP Server" vendor="West Street Software"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0572" published="2000-07-05" seq="2000-0572" severity="Medium" type="CVE"><desc><descript source="cve">The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1424">BID 1424</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4875.php">razor-weak-encryption(4875)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-07-8&amp;msg=613309F30B6DD2118C020000F809376C05CABD49@emss03m09.orl.lmco.com">Recovering Passwords in Visible Systems&apos; Razor</ref><ref source="BID" url="http://www.securityfocus.com/bid/1424">1424</ref></refs><vuln_soft><prod name="Razor" vendor="Visible Systems"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0573" published="2000-07-07" seq="2000-0573" severity="High" type="CVE"><desc><descript source="cve">The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1505">BID 1505</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-13.html">CERT Advisory CA-2000-13 Two Input Validation Problems In FTPD</ref><ref adv="1" patch="1" source="Security Focus Advisories" url="http://www.securityfocus.com/templates/advisory.html?id=2404">Vulnerability in ftpd</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96171893218000&amp;w=2">20000622 WuFTPD: Providing *remote* root since at least1994</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96179429114160&amp;w=2">20000623 WUFTPD 2.6.0 remote root exploit</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96299933720862&amp;w=2">20000707 New Released Version of the WuFTPD Sploit</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000623091822.3321.qmail@fiver.freemessage.com">20000623 ftpd: the advisory version</ref><ref source="AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2000.02">AA-2000.02</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-020.0.txt">CSSA-2000-020.0</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-039.html">RHSA-2000:039</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0244.html">20000723 CONECTIVA LINUX SECURITY ANNOUNCEMENT - WU-FTPD (re-release)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0017.html">20000702 [Security Announce] wu-ftpd update</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:29.wu-ftpd.asc.v1.1">FreeBSD-SA-00:29</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-009.txt.asc">NetBSD-SA2000-009</ref><ref source="BID" url="http://www.securityfocus.com/bid/1387">1387</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/4773">wuftp-format-string-stack-overwrite(4773)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-0574" published="2000-07-07" seq="2000-0574" severity="Medium" type="CVE"><desc><descript source="cve">FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4908.php">ftp-setproctitle-format-string(4908)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-13.html">CERT Advisory CA-2000-13 Two Input Validation Problems In FTPD</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/advisory.html?id=2404">Vulnerability in ftpd</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0031.html">20000705 proftp advisory</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0061.html">20000706 ftpd and setproctitle()</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0121.html">20000710 opieftpd setproctitle() patches</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-009.txt.asc">NetBSD-SA2000-009</ref><ref source="BID" url="http://www.securityfocus.com/bid/1425">1425</ref><ref source="BID" url="http://www.securityfocus.com/bid/1438">1438</ref></refs><vuln_soft><prod name="ftpd" vendor="OpenBSD"><vers num="5.51"/><vers num="5.60"/></prod><prod name="wu-ftpd" vendor="Washington University"><vers edition="academ" num="2.4.2 Beta1"/><vers edition="academ" num="2.4.2 Beta18"/><vers num="2.4.2 VR17"/><vers num="2.4.2 VR16"/><vers num="2.4.2 Beta18 VR9"/><vers num="2.4.2 Beta18 VR8"/><vers num="2.4.2 Beta18 VR7"/><vers num="2.4.2 Beta18 VR6"/><vers num="2.4.2 Beta18 VR5"/><vers num="2.4.2 Beta18 VR4"/><vers num="2.4.2 Beta18 VR15"/><vers num="2.4.2 Beta18 VR14"/><vers num="2.4.2 Beta18 VR13"/><vers num="2.4.2 Beta18 VR12"/><vers num="2.4.2 Beta18 VR11"/><vers num="2.4.2 Beta18 VR10"/><vers num="2.6"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0575" published="2000-07-05" seq="2000-0575" severity="High" type="CVE"><desc><descript source="cve">SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who is logging in, which could allow remote attackers to sniff the ticket cache if the home directory is installed on NFS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1426">BID 1426</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4903.php">ssh-kerberos-tickets-disclosure(4903)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200007010511.BAA16944@syrinx.oankali.net">The ftp server (ftpd) on HP-UX allows users root access</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96256265914116&amp;w=2">20000630 Kerberos security vulnerability in SSH-1.2.27</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.27"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0576" published="2000-07-05" seq="2000-0576" severity="Medium" type="CVE"><desc><descript source="cve">Oracle Web Listener for AIX versions 4.0.7.0.0 and 4.0.8.1.0 allows remote attackers to cause a denial of service via a malformed URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1427">BID 1427</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0027.html">Oracle Web Listener for AIX DoS</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4874.php">oracle-web-listener-dos(4874)</ref></refs><vuln_soft><prod name="Web Listener for AIX" vendor="Oracle"><vers num="4.0.8"/><vers num="4.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0577" published="2000-06-21" seq="2000-0577" severity="High" type="CVE"><desc><descript source="cve">Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4760.php">netscape-ftpserver-chroot(4760)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211351280.23780-100000@nimue.tpi.pl">Netscape FTP Server - </ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0345.html">20000629 (forw) Re: Netscape ftp Server (fwd)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1411">1411</ref></refs><vuln_soft><prod name="Professional Services FTPServer" vendor="Netscape"><vers num="1.3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0578" published="2000-06-21" seq="2000-0578" severity="Low" type="CVE"><desc><descript source="cve">SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allow local users to insert malicious contents into these files as they are being compiled by another user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1412">BID 1412</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0204.html">Poor Tempfile Use in IRIX: Compilers and Cron</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5007.php">sgi-mipspro-modify-files(5007)</ref></refs><vuln_soft><prod name="MIPSPro Compilers" vendor="SGI"><vers num="7.2.1"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0579" published="2000-06-21" seq="2000-0579" severity="Low" type="CVE"><desc><descript source="cve">IRIX crontab creates temporary files with predictable file names and with the umask of the user, which could allow local users to modify another user&apos;s crontab file as it is being edited.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1413">BID 1413</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0204.html">Predictability Problems in IRIX Cron and Compilers</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5008.php">irix-cron-modify-crontab(5008)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0580" published="2000-06-30" seq="2000-0580" severity="Medium" type="CVE"><desc><descript source="cve">Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1415">BID 1415</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4824.php">win2k-cpu-overload-dos</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630161935.4619B-100000@fjord.fscinternet.com">SecureXpert Advisory [SX-20000620-2]</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="2000.2072"/><vers num="2000"/><vers num="2000.0.2195"/><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0581" published="2000-06-30" seq="2000-0581" severity="Medium" type="CVE"><desc><descript source="cve">Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros, which causes the server to crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1414">BID 1414</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4823.php">win2k-telnetserver-dos(4823)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630161841.4619A-100000@fjord.fscinternet.com">SecureXpert Advisory [SX-20000620-1]</ref><ref source="BID" url="http://www.securityfocus.com/bid/1414">1414</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="2000.2072"/><vers num="2000.2031"/><vers num="2000.0.2195"/><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0582" published="2000-06-30" seq="2000-0582" severity="Medium" type="CVE"><desc><descript source="cve">Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1416">BID1416</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4825.php">fw1-resource-overload-dos</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.1000630162106.4619C-100000@fjord.fscinternet.com">SecureXpert Advisory [SX-20000620-3</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#SMTP_Security">http://www.checkpoint.com/techsupport/alerts/list_vun.html#SMTP_Security</ref><ref source="BID" url="http://www.securityfocus.com/bid/1416">1416</ref><ref source="OSVDB" url="http://www.osvdb.org/1438">1438</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0583" published="2000-06-30" seq="2000-0583" severity="Medium" type="CVE"><desc><descript source="cve">vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows remote attackers to cause a denial of service via a USER or PASS command that contains arbitrary formatting directives.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1418">BID 1418</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4572.php">inter7-vpopmail-bo(4572)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=395BD2A8.5D3396A7@secureaustin.com">vpopmail-3.4.11 problems</ref><ref source="CONFIRM" url="http://www.vpopmail.cx/vpopmail-ChangeLog">http://www.vpopmail.cx/vpopmail-ChangeLog</ref><ref source="BID" url="http://www.securityfocus.com/bid/1418">1418</ref></refs><vuln_soft><prod name="vpopmail vchkpw" vendor="Inter7"><vers num="4.7"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0584" published="2000-07-02" seq="2000-0584" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="FreeBSD Advisories" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:31.canna.asc.v1.1">FreeBSD-SA-00:31</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4912.php">canna-bin-execute-bo(4912)</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20000702">canna server: buffer overflow</ref><ref source="MISC" url="http://shadowpenguin.backsection.net/advisories/advisory038.html">http://shadowpenguin.backsection.net/advisories/advisory038.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/1445">1445</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.5"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0585" published="2000-06-24" seq="2000-0585" severity="High" type="CVE"><desc><descript source="cve">ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4772.php">openbsd-isc-dhcp-bo(4772)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0247.html">Possible root exploit in ISC DHCP client</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-01%26msg%3D395F5C35.63D61535@mandrakesoft.com">[Security Announce] dhcp update</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20000628">20000628 dhcp client: remote root exploit in dhcp client </ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:34.dhclient.asc">FreeBSD-SA-00:34</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0014.html">20000702 [Security Announce] dhcp update</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_56.html">20000711 Security Hole in dhclient &lt; 2.0</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-008.txt.asc">NetBSD-SA2000-008</ref><ref source="BID" url="http://www.securityfocus.com/bid/1388">1388</ref></refs><vuln_soft><prod name="DHCP Client" vendor="ISC"><vers num="3.0b1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0586" published="2000-06-29" seq="2000-0586" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Dalnet IRC server 4.6.5 allows remote attackers to cause a denial of service or execute arbitrary commands via the SUMMON command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1404">BID 1404</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4826.php">ircd-dalnet-summon-bo(4826)</ref><ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/1092.html">20000628 dalnet 4.6.5 remote vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1404">1404</ref></refs><vuln_soft><prod name="ircd" vendor="Dalnet"><vers num="4.6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0587" published="2000-06-26" seq="2000-0587" severity="High" type="CVE"><desc><descript source="cve">The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4844.php">glftpd-privpath-directive</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.10006261041360.31907-200000@twix.thrijswijk.nl">Glftpd privpath bugs... +fix</ref><ref patch="1" source="GLFTPd" url="http://www.glftpd.org/glftpd.html">Product home page</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0317.html">20000627 Re: Glftpd privpath bugs... +fix</ref><ref source="BID" url="http://www.securityfocus.com/bid/1401">1401</ref></refs><vuln_soft><prod name="GlFtpd" vendor="GlFtpd"><vers num="1.21b8"/><vers num="1.21b7"/><vers num="1.21b6"/><vers num="1.21b5"/><vers num="1.21b4"/><vers num="1.21b3"/><vers num="1.21b2"/><vers num="1.21b1"/><vers num="1.20"/><vers num="1.19"/><vers num="1.18"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0588" published="2000-06-26" seq="2000-0588" severity="High" type="CVE"><desc><descript source="cve">SawMill 5.0.21 CGI program allows remote attackers to read the first line of arbitrary files by listing the file in the rfcf parameter, whose contents SawMill attempts to parse as configuration commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1402">BID 1402</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4836.php">Flowerfire Sawmill File Access Vulnerability</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html">sawmill5.0.21 old path bug &amp; weak hash algorithm</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html">20000706 Patch for Flowerfire Sawmill Vulnerabilities Available</ref><ref source="BID" url="http://www.securityfocus.com/bid/1402">1402</ref></refs><vuln_soft><prod name="Sawmill" vendor="Flowerfire"><vers num="5.0.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0589" published="2000-06-26" seq="2000-0589" severity="High" type="CVE"><desc><descript source="cve">SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1404">BID1404</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4837.php">sawmill-weak-encryption(4837)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html">sawmill5.0.21 old path bug &amp; weak hash algorithm</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html">20000706 Patch for Flowerfire Sawmill Vulnerabilities Available</ref><ref source="BID" url="http://www.securityfocus.com/bid/1403">1403</ref></refs><vuln_soft><prod name="Sawmill" vendor="Flowerfire"><vers num="5.0.21"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0590" published="2000-07-04" seq="2000-0590" severity="High" type="CVE"><desc><descript source="cve">Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1431">BID 1431</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4878.php">http-cgi-pollit-variable-overwrite(4878)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0076.html">Vulnerability in Poll_It cgi v2.0</ref></refs><vuln_soft><prod name="Poll It" vendor="CGI-World"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0591" published="2000-07-05" seq="2000-0591" severity="Medium" type="CVE"><desc><descript source="cve">Novell BorderManager 3.0 and 3.5 allows remote attackers to bypass URL filtering by encoding characters in the requested URL.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1432">BID 1432</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4906.php">bordermanager-bypass-url-restriction(4906)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0038.html">Novell BorderManager 3.0 EE - Encoded URL rule bypass</ref><ref source="BID" url="http://www.securityfocus.com/bid/1432">1432</ref></refs><vuln_soft><prod name="BorderManager" vendor="Novell"><vers num="3.5"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0592" published="2000-06-27" seq="2000-0592" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1400">BID 1400</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4832.php">winproxy-command-bo(4832)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006271417.GFE84146.-BJXON@lac.co.jp">WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/1400">1400</ref></refs><vuln_soft><prod name="SapporoWorks WinProxy" vendor="SapporoWorks"><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0593" published="2000-06-27" seq="2000-0593" severity="Medium" type="CVE"><desc><descript source="cve">WinProxy 2.0 and 2.0.1 allows remote attackers to cause a denial of service by sending an HTTP GET request without listing an HTTP version number.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/bid/1400">BID 1400</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4831.php">winproxy-get-dos(4831)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200006271417.GFE84146.-BJXON@lac.co.jp">WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200006271417.GFE84146.-BJXON@lac.co.jp">20000627 [SPSadvisory #37]WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/1400">1400</ref></refs><vuln_soft><prod name="SapporoWorks WinProxy" vendor="SapporoWorks"><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0594" published="2000-07-04" seq="2000-0594" severity="Medium" type="CVE"><desc><descript source="cve">BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:32.bitchx.asc">bitchx port contains client-side vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4897.php">irc-bitchx-invite-dos(4897)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3DPine.LNX.4.10.10007032354590.985-100000@panasync.canuck.ca">BitchX /ignore bug</ref><ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0018.html">20000704 BitchX /ignore bug</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0026.html">20000704 BitchX exploit possibly waiting to happen, certain DoS</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-042.html">RHSA-2000:042</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-07/0042.html">FreeBSD-SA-00:32</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-022.0.txt">CSSA-2000-022.0</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0105.html">20000707 BitchX update</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0098.html">20000707 CONECTIVA LINUX SECURITY ANNOUNCEMENT - BitchX</ref><ref source="BID" url="http://www.securityfocus.com/bid/1436">1436</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.0"/><vers num="3.5"/></prod><prod name="OpenLinux Desktop" vendor="Caldera"><vers num="2.3"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="2007.0"/></prod><prod name="OpenLinux eDesktop" vendor="Caldera"><vers num="2.4"/></prod><prod name="OpenLinux Eserver" vendor="Caldera"><vers num="2.3"/></prod><prod name="OpenLinux eBuilder" vendor="Caldera"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0595" published="2000-07-05" seq="2000-0595" severity="Medium" type="CVE"><desc><descript source="cve">libedit searches for the .editrc file in the current directory instead of the user&apos;s home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1437">BID 1437</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/freebsd/2000-07/0035.html">libedit reads config file from current directory</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4911.php">bsd-libedit-editrc(4911)</ref><ref source="OSVDB" url="http://www.osvdb.org/1446">1446</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.0"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0596" published="2000-06-27" seq="2000-0596" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 5.x does not warn a user before opening a Microsoft Access database file that is referenced within ActiveX OBJECT tags in an HTML document, which could allow remote attackers to execute arbitrary commands, aka the &quot;IE Script&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4924.php">ie-access-script-vulnerability(4924)</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/MS00-049.asp">Microsoft Security Bulletin (MS00-049)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39589359.762392DB@nat.bg">: IE 5 and Access 2000 vulnerability - executing programs</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=000d01bfe0fb$418f59b0$96217aa8@src.bu.edu">20000627 FW: IE 5 and Access 2000 vulnerability - executing programs</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2000-16.html">CA-2000-16</ref><ref source="BID" url="http://www.securityfocus.com/bid/1398">1398</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.01 SP2"/><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0597" published="2000-06-27" seq="2000-0597" severity="High" type="CVE"><desc><descript source="cve">Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the &quot;Office HTML Script&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><exception/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/MS00-049.asp">MS Security Bulletin MS00-049</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4923.php">office-html-script-vulnerability(4923)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39589349.ED9DBCAB@nat.bg">IE 5 and Excel 2000, PowerPoint 2000 vulnerability - executing programs</ref><ref source="BID" url="http://www.securityfocus.com/bid/1399">1399</ref></refs><vuln_soft><prod name="PowerPoint" vendor="Microsoft"><vers num="2000"/><vers num="97"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0598" published="2000-06-26" seq="2000-0598" severity="Medium" type="CVE"><desc><descript source="cve">Fortech Proxy+ allows remote attackers to bypass access restrictions for to the administration service by redirecting their connections through the telnet proxy.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1395">BID 1395</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4779.php">fortech-proxy-telnet-gateway(4779)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0268.html">Proxy+ Telnet Gateway Problems</ref><ref source="MISC" url="http://www.proxyplus.cz/faq/articles/EN/art01002.htm">http://www.proxyplus.cz/faq/articles/EN/art01002.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/1395">1395</ref></refs><vuln_soft><prod name="Proxy+" vendor="Fortech"><vers num="2.40"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0599" published="2000-06-29" seq="2000-0599" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in iMesh 1.02 allows remote attackers to execute arbitrary commands via a long string to the iMesh port.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1407">BID 1407</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4829.php">imesh-tcp-port-overflow(4829)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0335.html"> iMesh 1.02 vulnerability</ref><ref source="MISC" url="http://www.imesh.com/download/download.html">http://www.imesh.com/download/download.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/1407">1407</ref></refs><vuln_soft><prod name="iMesh" vendor="iMesh.Com"><vers num="1.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0600" published="2000-06-26" seq="2000-0600" severity="High" type="CVE"><desc><descript source="cve">Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1393">BID 1393</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4780.php">netscape-virtual-directory-bo(4780)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0264.html">Netscape Enterprise Server for NetWare Virtual Directory Vulnerab ility</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="5.1"/><vers num="5.0"/></prod><prod name="Enterprise Server Netware" vendor="Netscape"><vers num="5.0"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0601" published="2000-06-25" seq="2000-0601" severity="Medium" type="CVE"><desc><descript source="cve">LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1396">BID 1396</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4778.php">irc-leafchat-dos(4778)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.BSF.4.10.10006252056110.74551-100000@unix.za.net">LeafChat Denial of Service</ref><ref source="CONFIRM" url="http://www.leafdigital.com/Software/leafChat/history.html">http://www.leafdigital.com/Software/leafChat/history.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/1396">1396</ref></refs><vuln_soft><prod name="LeafChat" vendor="LeafDigital"><vers num="1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2000-0602" published="2000-06-21" seq="2000-0602" severity="Medium" type="CVE"><desc><descript source="cve">Secure Locate (slocate) in Red Hat Linux allows local users to gain privileges via a malformed configuration file that is specified in the LOCATE_PATH environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1385">BID 1385</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4726.php">redhat-secure-locate-path(4726)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211209500.22969-100000@nimue.tpi.p">: rh 6.2 - gid compromises, etc</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211209500.22969-100000@nimue.tpi.pl">20000621 rh 6.2 - gid compromises, etc</ref><ref source="BID" url="http://www.securityfocus.com/bid/1385">1385</ref></refs><vuln_soft><prod name="Secure Locate" vendor="Kevin Lindsay"><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-0603" published="2000-07-07" seq="2000-0603" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft SQL Server 7.0 allows a local user to bypass permissions for stored procedures by referencing them via a temporary stored procedure, aka the &quot;Stored Procedure Permissions&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1444">BID 1444</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-048.asp">Microsoft Security Bulletin (MS00-048)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1762.php">mssql-extended-procs(1762)</ref><ref source="XF" url="http://xforce.iss.net/static/4921.php">mssql-procedure-perms</ref></refs><vuln_soft><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0604" published="2000-06-21" seq="2000-0604" severity="Medium" type="CVE"><desc><descript source="cve">gkermit in Red Hat Linux is improperly installed with setgid uucp, which allows local users to modify files owned by uucp.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1383">BID 1383</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4727.php">redhat-gkermit(4727)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006211209500.22969-100000@nimue.tpi.pl">rh 6.2 - gid compromises, etc</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0605" published="2000-07-10" seq="2000-0605" severity="Low" type="CVE"><desc><descript source="cve">Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1460">BID 1460</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4904.php">blackboard-courseinfo-plaintext(4904)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0040.html">Security Fix for Blackboard CourseInfo 4.0</ref><ref source="BID" url="http://www.securityfocus.com/bid/1460">1460</ref><ref source="NTBUGTRAQ" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=NTBUGTRAQ&amp;P=R1647">20000710 Two issues: Blackboard CourseInfo 4.0 stores admin password in clear text; strange settings on the winreg key.</ref></refs><vuln_soft><prod name="CourseInfo" vendor="Blackboard"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0606" published="2000-06-21" seq="2000-0606" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1371">BID 1371</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4763.php">linux-kon-bo(4763)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006192340340.19998-100000@ferret.lmh.ox.ac.uk">Problems with &quot;kon2&quot; package</ref><ref source="BID" url="http://www.securityfocus.com/bid/1371">1371</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/><vers num="6.1"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0607" published="2000-06-21" seq="2000-0607" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1371">BID 1371</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4763.php">linux-kon-bo(4763)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.21.0006192340340.19998-100000@ferret.lmh.ox.ac.uk">Problems with &quot;kon2&quot; package</ref><ref source="BID" url="http://www.securityfocus.com/bid/1371">1371</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/><vers num="6.1"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0608" published="2000-06-21" seq="2000-0608" severity="Medium" type="CVE"><desc><descript source="cve">NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1376">BID 1376</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4759.php">dmailweb-long-pophost-dos(4759)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-15&amp;msg=4.1.20000621113334.00996820@qlink.queensu.ca">NetWin dMailWeb Denial of Service</ref></refs><vuln_soft><prod name="CWMail" vendor="NetWin"><vers num="2.6j"/><vers num="2.6i"/><vers num="2.6g"/><vers num="2.5e"/></prod><prod name="DMailWeb" vendor="NetWin"><vers num="2.6j"/><vers num="2.6i"/><vers num="2.6g"/><vers num="2.5e"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0609" published="2000-06-21" seq="2000-0609" severity="Medium" type="CVE"><desc><descript source="cve">NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1376">BID 1376</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4758.php">dmailweb-long-username-dos(4758</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=2000-06-15&amp;msg=4.1.20000621113334.00996820@qlink.queensu.ca">NetWin dMailWeb Denial of Service</ref><ref source="BID" url="http://www.securityfocus.com/bid/1376">1376</ref></refs><vuln_soft><prod name="CWMail" vendor="NetWin"><vers num="2.6j"/><vers num="2.6i"/><vers num="2.6g"/><vers num="2.5e"/></prod><prod name="DMailWeb" vendor="NetWin"><vers num="2.6j"/><vers num="2.6i"/><vers num="2.6g"/><vers num="2.5e"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0610" published="2000-06-23" seq="2000-0610" severity="Medium" type="CVE"><desc><descript source="cve">NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to bypass authentication and use the server for mail relay via a username that contains a carriage return.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1390">BID 1390</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=4.1.20000623203007.00944760@qlink.queensu.ca"> NetWin dMailWeb Unrestricted Mail Relay</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4770.php">http://xforce.iss.net/static/4770.php</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0243.html">20000623 NetWin dMailWeb Unrestricted Mail Relay</ref></refs><vuln_soft><prod name="CWMail" vendor="NetWin"><vers num="2.6g"/></prod><prod name="DMailWeb" vendor="NetWin"><vers num="2.6g"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0611" published="2000-06-23" seq="2000-0611" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of NetWin dMailWeb and cwMail trusts all POP servers, which allows attackers to bypass normal authentication and cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1391">BID 1391</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4771.php">netwin-dmailweb-auth(4771</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0243.html">NetWin dMailWeb Unrestricted Mail Relay</ref></refs><vuln_soft><prod name="CWMail" vendor="NetWin"><vers num="2.6g"/></prod><prod name="DMailWeb" vendor="NetWin"><vers num="2.6g"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0612" published="2000-06-29" seq="2000-0612" severity="Medium" type="CVE"><desc><descript source="cve">Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1406">BID 1406</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4828.php">win-arp-spoofing(4828)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=395B7E64.9FB3D4DB@starzetz.de">Buggy ARP handling in Windoze</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0613" published="2000-03-20" seq="2000-0613" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=B3D6883199DBD311868100A0C9FC2CDC046B72@protea.citec.net">PIX DMZ Denial of Service - TCP Resets</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-7.php">cisco-pix-firewall-tcp</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/pixtcpreset-pub.shtml">20000711 Cisco Secure PIX Firewall TCP Reset Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1454">1454</ref><ref source="XF" url="http://xforce.iss.net/static/4928.php">cisco-pix-firewall-tcp</ref><ref source="OSVDB" url="http://www.osvdb.org/1457">1457</ref></refs><vuln_soft><prod name="PIX Firewall" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0614" published="2000-07-10" seq="2000-0614" severity="High" type="CVE"><desc><descript source="cve">Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1450">BID 1450</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4915.php">linux-tnef-email-overwrite(4915)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/vendor/2000-q3/0002.html">[suse-security-announce] SuSE Security Announcement: tnef</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-0615" published="2000-07-19" seq="2000-0615" severity="Low" type="CVE"><desc><descript source="cve">LPRng 3.6.x improperly installs lpd as setuid root, which can allow local users to append lpd trace and logging messages to files.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0117.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1447">bid1447</ref><ref source="XF" url="http://xforce.iss.net/static/7361.php">lpd-suid-root(7361)</ref></refs><vuln_soft><prod name="LPRng" vendor="AStArt Technologies"><vers num="3.6.9"/><vers num="3.6.8"/><vers num="3.6.7"/><vers num="3.6.6"/><vers num="3.6.5"/><vers num="3.6.4"/><vers num="3.6.3"/><vers num="3.6.2"/><vers num="3.6.15"/><vers num="3.6.14"/><vers num="3.6.13"/><vers num="3.6.12"/><vers num="3.6.11"/><vers num="3.6.10"/><vers num="3.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0616" published="2000-06-26" seq="2000-0616" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in HP TurboIMAGE DBUTIL allows local users to gain additional privileges via DBUTIL.PUB.SYS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1405">bugtraq id 1405</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4943.php">hp-turboimage-dbutil(4943)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0294.html">HPSBMP0006-007 Sec. Vulnerability in TurboIMAGE DBUTIL</ref></refs><vuln_soft><prod name="MPE iX" vendor="HP"><vers num="6.5"/><vers num="6.0"/><vers num="5.5"/><vers num="5.0"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0617" published="2000-06-22" seq="2000-0617" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1495">BID 1495</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4995.php">xconq-elevate-privileges(4995)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0222.html">RHL 6.2 xconq package - overflows yield gid games</ref></refs><vuln_soft><prod name="Xconq" vendor="Stanley T. Shebs"><vers num="7.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0618" published="2000-06-22" seq="2000-0618" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1495">BID 1495</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4995.php">xconq-elevate-privileges(4995)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0222.html">RHL 6.2 xconq package - overflows yield gid games</ref></refs><vuln_soft><prod name="Xconq" vendor="Stanley T. Shebs"><vers num="7.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0619" published="2000-07-19" seq="2000-0619" severity="Medium" type="CVE"><desc><descript source="cve">Top Layer AppSwitch 2500 allows remote attackers to cause a denial of service via malformed ICMP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0680.html"></ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vuln-dev/2000-q2/0921.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1258">bid1258</ref><ref source="XF" url="http://xforce.iss.net/static/7364.php">toplayer-icmp-dos(7364)</ref></refs><vuln_soft><prod name="AppSwitch" vendor="TopLayer"><vers num="2500.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0620" published="2000-06-19" seq="2000-0620" severity="Medium" type="CVE"><desc><descript source="cve">libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1409">BID 1409</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4996.php">libx11-infinite-loop-dos(4996)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-22%26msg%3DPine.LNX.4.21.0006192251480.9945-100000@ferret.lmh.ox.ac.uk">XFree86: Various nasty libX11 holes</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96146116627474&amp;w=2">20000619 XFree86: Various nasty libX11 holes</ref></refs><vuln_soft><prod name="X" vendor="Open Group"><vers num="11.0R6.4"/><vers num="11.0R6.3"/><vers num="11.0R6.2"/><vers num="11.0R6.1"/><vers num="11.0R6"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="4.0"/><vers num="3.3.6"/><vers num="3.3.5"/><vers num="3.3.4"/><vers num="3.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0621" published="2000-07-20" seq="2000-0621" severity="High" type="CVE"><desc><descript source="cve">Microsoft Outlook 98 and 2000, and Outlook Express 4.0x and 5.0x, allow remote attackers to read files on the client&apos;s system via a malformed HTML message that stores files outside of the cache, aka the &quot;Cache Bypass&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-14.html">CERT Advisory CA-2000-14 Microsoft Outlook and Outlook Express Cache Bypass Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1501">BID 1501</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/MS00-046.asp">Microsoft Security Bulletin (MS00-046)</ref><ref source="XF" url="http://xforce.iss.net/static/5013.php">outlook-cache-bypass</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="97"/><vers num="98"/><vers num="2000"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="5.0.1"/><vers num="5.0"/><vers num="4.01"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0622" published="2000-07-19" seq="2000-0622" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Webfind CGI program in O&apos;Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long &quot;keywords&quot; parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1487">BID 1487</ref><ref adv="1" patch="1" source="O&apos;Reilly" url="http://website.oreilly.com/support/software/wsp2x_updates.cfm">WebSite Professional 2.x Updates</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/advisory.html?id=2424">O&apos;Reilly WebSite Professional version 2.x for Windows 9x/NT/2000</ref><ref source="CONFIRM" url="http://website.oreilly.com/support/software/wspro25_releasenotes.txt">http://website.oreilly.com/support/software/wspro25_releasenotes.txt</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/043.asp">20000719 O&apos;Reilly WebSite Professional Overflow</ref><ref source="XF" url="http://xforce.iss.net/static/4962.php">website-webfind-bo(4962)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1487">1487</ref></refs><vuln_soft><prod name="Website Professional" vendor="OReilly"><vers num="2.4.9"/><vers num="2.4"/><vers num="2.3.18"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0623" published="2000-07-17" seq="2000-0623" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in O&apos;Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1492">BID 1492</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4970.php">O&apos;Reilly WebSite GET Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5946">Alert: Buffer Overrun is O&apos;Reilly WebsitePro httpd32.exe              (CISADV000717</ref></refs><vuln_soft><prod name="Website Professional" vendor="OReilly"><vers num="2.4.9"/><vers num="2.4"/><vers num="2.3.18"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0624" published="2000-07-20" seq="2000-0624" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1496">BID 1496</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4956.php">winamp-playlist-parser-bo(4956)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0289.html">Winamp M3U playlist parser buffer overflow security vulnerability</ref><ref source="CONFIRM" url="http://www.winamp.com/getwinamp/newfeatures.jhtml">http://www.winamp.com/getwinamp/newfeatures.jhtml</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="2.64" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0625" published="2000-07-18" seq="2000-0625" severity="Medium" type="CVE"><desc><descript source="cve">NetZero 3.0 and earlier uses weak encryption for storing a user&apos;s login information, which allows a local user to decrypt the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1483">BID 1483</ref><ref adv="1" patch="1" source="l0pht" url="http://www.l0pht.com/advisories/netzero.txt">NetZero Password Encryption Algorithm</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4461.php">netzero-password-disclosure(4461)</ref></refs><vuln_soft><prod name="ZeroPort" vendor="NetZero"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0626" published="2000-07-18" seq="2000-0626" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1482">BID 1482</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4934.php">alibaba-get-dos(4934)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html">Multiple bugs in Alibaba 2.0</ref></refs><vuln_soft><prod name="Alibaba" vendor="Computer Software Manufaktur"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0627" published="2000-07-18" seq="2000-0627" severity="High" type="CVE"><desc><descript source="cve">BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1486">BID 1486</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4946.php">blackboard-courseinfo-dbase-modification(4946</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0254.html">Blackboard Courseinfo v4.0 User Authentication</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000719151904.I17986@securityfocus.com">20000719 Security Fix for Blackboard CourseInfo 4.0</ref></refs><vuln_soft><prod name="CourseInfo" vendor="Blackboard"><vers num="4.0"/><vers num="Unix"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0628" published="2000-07-11" seq="2000-0628" severity="High" type="CVE"><desc><descript source="cve">The source.asp example script in the Apache ASP module Apache::ASP 1.93 and earlier allows remote attackers to modify files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1457">BID 1457</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4931.php">apache-source-asp-file-write(4931)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0142.html">ANNOUNCE Apache::ASP v1.95 - Security Hole Fixed</ref><ref source="CONFIRM" url="http://www.nodeworks.com/asp/changes.html">http://www.nodeworks.com/asp/changes.html</ref></refs><vuln_soft><prod name="Apache ASP" vendor="Joshua Chamas"><vers num="1.93"/><vers num="0.18"/><vers num="0.17"/><vers num="0.16"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0629" published="2000-07-12" seq="2000-0629" severity="High" type="CVE"><desc><descript source="cve">The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1459">BID 1459</ref><ref adv="1" patch="1" source="Sun Micro" url="http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html">Removing Examples and Unnecessary Servlets Java Web Server 2.0</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0163.html">Sun&apos;s Java Web Server remote command execution vulnerability</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-02.html">CERT Advisory CA-2000-02 Malicious HTML Tags Embedded in Client Web Requests</ref><ref source="BID" url="http://www.securityfocus.com/bid/1459">1459</ref></refs><vuln_soft><prod name="Java Web Server" vendor="Sun"><vers num="2.0"/><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0630" published="2000-07-17" seq="2000-0630" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the &quot;File Fragment Reading via .HTR&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1488">BID 1488</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4448.php">iis-ism-file-access(4448)</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/ms00-044.asp">Microsoft Security Bulletin (MS00-044)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1488">1488</ref><ref source="XF" url="http://xforce.iss.net/static/5104.php">iis-htr-obtain-code</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0631" published="2000-07-14" seq="2000-0631" severity="Medium" type="CVE"><desc><descript source="cve">An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the &quot;Absent Directory Browser Argument&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1476">BID 1476</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4951.php">iis-absent-directory-dos(4951)</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/ms00-044.asp">Microsoft Security Bulletin (MS00-044)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96390444022878&amp;w=2">20000718 ISBASE Security Advisory(SA2000-02)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0632" published="2000-07-17" seq="2000-0632" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1490">BID 1490</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4419.php">http-cgi-listserv-wa-bo(4419)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0222.html">[COVERT-2000-07] LISTSERV Web Archive Remote Overflow</ref><ref source="CONFIRM" url="http://www.lsoft.com/news/default.asp?item=Advisory1">http://www.lsoft.com/news/default.asp?item=Advisory1</ref><ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/43_Advisory.asp">20000717 [COVERT-2000-07] LISTSERV Web Archive Remote Overflow</ref><ref source="BID" url="http://www.securityfocus.com/bid/1490">1490</ref><ref source="XF" url="http://xforce.iss.net/static/4952.php">lsoft-listserv-querystring-bo</ref></refs><vuln_soft><prod name="Listserv" vendor="L-Soft"><vers num="1.8d"/><vers num="1.8c"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0633" published="2000-07-18" seq="2000-0633" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in Mandrake Linux usermode package allows local users to to reboot or halt the system.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1489">BID 1489</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4944.php">linux-usermode-dos(4944)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0251.html">MDKSA-2000:020 usermode update</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-053.html">RHSA-2000:053</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0117.html">20000812 Conectiva Linux security announcement - usermode</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2E"/><vers edition="i386" num="6.2E"/><vers edition="Alpha" num="6.2E"/><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/><vers edition="i386" num="6.0"/><vers edition="Alpha" num="6.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0es"/><vers num="4.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0634" published="2000-04-03" seq="2000-0634" severity="Medium" type="CVE"><desc><descript source="cve">The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1493">BID 1493</ref><ref adv="1" patch="1" source="s21sec" url="http://www.s21sec.com/en/avisos/s21sec-003-en.txt">Vulnerabilities in Stalker&apos;s CommuniGate Pro v3.2.4</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0223.html">Vulnerabilities in CommuniGate Pro v3.2.4</ref><ref source="XF" url="http://xforce.iss.net/static/5105.php">communigate-pro-file-read</ref><ref source="OSVDB" url="http://www.osvdb.org/5774">5774</ref></refs><vuln_soft><prod name="Communigate Pro" vendor="Stalker"><vers num="3.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0635" published="2000-07-10" seq="2000-0635" severity="High" type="CVE"><desc><descript source="cve">The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1449">BID 1449</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4880.php">minivend-viewpage-sample(4880)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0150.html">Akopia MiniVend Piped Command Execution Vulnerability</ref><ref source="CONFIRM" url="http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html">http://www.zdnet.com/zdnn/stories/news/0,4586,2600258,00.html</ref></refs><vuln_soft><prod name="MiniVend" vendor="Akopia"><vers num="4.0.4"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0636" published="2000-07-19" seq="2000-0636" severity="Medium" type="CVE"><desc><descript source="cve">HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1491">BID 1491</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0265.html">HP Jetdirect - Invalid FTP Command DoS</ref><ref source="XF" url="http://xforce.iss.net/static/4947.php">hp-jetdirect-quote-dos</ref></refs><vuln_soft><prod name="JetDirect" vendor="HP"><vers num="rev. H.08.20"/><vers num="rev. H.08.05"/><vers num="rev. G.08.20"/><vers num="rev. G.08.04"/><vers num="J3111A rev. G.08.03"/><vers num="J3111A rev. G.07.17"/><vers num="J3111A rev. G.07.03"/><vers num="J3111A rev. G.07.02"/><vers num="J3111A rev. G.05.35"/><vers num="J3111A rev. A.08.06"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0637" published="2000-07-26" seq="2000-0637" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the &quot;Excel REGISTER.ID Function&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5016.php">excel-register-function(5016)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=396B3F8F.9244D290@nat.bg">Excel 2000 vulnerability - executing programs</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/ms00-051.asp">Microsoft Security Bulletin (MS00-051)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1451">1451</ref></refs><vuln_soft><prod name="Excel" vendor="Microsoft"><vers num="2000"/><vers num="97"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2000-0638" published="2000-07-11" seq="2000-0638" severity="High" type="CVE"><desc><descript source="cve">bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0167.html">Re: BIG BROTHER EXPLOIT</ref><ref source="CONFIRM" url="http://bb4.com/README.CHANGES">http://bb4.com/README.CHANGES</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0146.html">20000711 BIG BROTHER EXPLOIT</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0147.html">20000711 REMOTE EXPLOIT IN ALL CURRENT VERSIONS OF BIG BROTHER</ref><ref source="BID" url="http://www.securityfocus.com/bid/1455">1455</ref><ref source="XF" url="http://xforce.iss.net/static/4879.php">http-cgi-bigbrother-bbhostsvc</ref></refs><vuln_soft><prod name="Big Brother" vendor="Sean MacGuire"><vers num="1.4h1"/><vers num="1.4H"/><vers num="1.4g"/><vers num="1.4"/><vers num="1.3b"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.09d"/><vers num="1.09c"/><vers num="1.09b"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0639" published="2000-06-11" seq="2000-0639" severity="High" type="CVE"><desc><descript source="cve">The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1494">BID 1494</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0171.html">Big Brother filename extension vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4879.php">http-cgi-bigbrother-bbhostsvc(4879</ref><ref source="XF" url="http://xforce.iss.net/static/5103.php">big-brother-filename-extension</ref><ref source="OSVDB" url="http://www.osvdb.org/1472">1472</ref></refs><vuln_soft><prod name="Big Brother" vendor="Sean MacGuire"><vers num="1.4h1"/><vers num="1.4g"/><vers num="1.4H"/><vers num="1.4"/><vers num="1.3b"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="1.09d"/><vers num="1.09c"/><vers num="1.09b"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0640" published="2000-07-08" seq="2000-0640" severity="High" type="CVE"><desc><descript source="cve">Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1452">BID 1452</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4922.php">guild-ftpd-disclosure(4922)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0114.html">Big Brother filename extension vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/573">573</ref></refs><vuln_soft><prod name="GuildFTPd" vendor="Steve Poulsen"><vers num="0.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0641" published="2000-07-08" seq="2000-0641" severity="High" type="CVE"><desc><descript source="cve">Savant web server allows remote attackers to execute arbitrary commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1453">BID 1453</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4901.php">savant-get-bo(4901)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0114.html">gnu-pop3d (FTGate problem), Savant Webserver, Guild FTPd</ref></refs><vuln_soft><prod name="Savant WebServer" vendor="Michael Lamont"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0642" published="2000-07-12" seq="2000-0642" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of WebActive HTTP Server 1.00 stores the web access log active.log in the document root, which allows remote attackers to view the logs by directly requesting the page.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1497">BID 1497</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200007130827.BAA32671@Rage.Resentment.org">Lame DoS in WEBactive win65/NT server</ref><ref source="XF" url="http://xforce.iss.net/static/5184.php">webactive-active-log</ref></refs><vuln_soft><prod name="WEBactive" vendor="ITAfrica"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0643" published="2000-07-12" seq="2000-0643" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in WebActive HTTP Server 1.00 allows remote attackers to cause a denial of service via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1470">BID 1470</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4949.php">webactive-long-get-dos(4949)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200007130827.BAA32671@Rage.Resentment.org">Lame DoS in WEBactive win65/NT serve</ref></refs><vuln_soft><prod name="WEBactive" vendor="ITAfrica"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0644" published="2000-07-21" seq="2000-0644" severity="Medium" type="CVE"><desc><descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1506">BID 1506</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5005.php">wftpd-stat-info(5005)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html">WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/static/5003.php">wftpd-stat-dos</ref><ref source="OSVDB" url="http://www.osvdb.org/1477">1477</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="2.4.1 RC11"/><vers num="2.4.1"/><vers num="2.40"/><vers num="2.34"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0645" published="2000-07-21" seq="2000-0645" severity="Medium" type="CVE"><desc><descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1506">BID 1506</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5004.php">wftpd-rest-dos(5004)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html">WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="2.4.1 RC11"/><vers num="2.4.1"/><vers num="2.40"/><vers num="2.34"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0646" published="2000-07-21" seq="2000-0646" severity="Medium" type="CVE"><desc><descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1506">BID 1506</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5003.php">wftpd-stat-dos(5003)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html">WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="2.4.1 RC11"/><vers num="2.4.1"/><vers num="2.40"/><vers num="2.34"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0647" published="2000-07-21" seq="2000-0647" severity="Medium" type="CVE"><desc><descript source="cve">WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1506">BID 1506</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5006.php">wftpd-mlst-dos(5006)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html">WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="2.4.1 RC11"/><vers num="2.4.1"/><vers num="2.40"/><vers num="2.34"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0648" published="2000-07-11" seq="2000-0648" severity="Medium" type="CVE"><desc><descript source="cve">WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1456">BID 1456</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4511.php">niteserver-rename-file-dos(4511</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=E13BvU6-0007d8-00@dwarf.box.sk">WFTPD/WFTPD Pro 2.41 RC10 denial-of-service</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-05-06" name="CVE-2000-0649" published="2000-07-13" seq="2000-0649" severity="Low" type="CVE"><desc><descript source="cve">IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1499">BID 1499</ref><ref adv="1" patch="1" source="Support Microsoft" url="http://support.microsoft.com/support/kb/articles/Q218/1/80.ASP">Internet Information Server Returns IP Address in HTTP Header (Content-Location)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0025.html"> IIS4 Basic authentication realm issue</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0650" published="2000-07-11" seq="2000-0650" severity="Low" type="CVE"><desc><descript source="cve">The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1458">BID 1458</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0007&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=2753">Potential Vulnerability in McAfee Netshield and VirusScan 4.5</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5177">nai-virusscan-netshield-autoupgrade(5177)</ref><ref source="OSVDB" url="http://www.osvdb.org/1458">1458</ref><ref source="OSVDB" url="http://www.osvdb.org/4200">4200</ref></refs><vuln_soft><prod name="VirusScan" vendor="Network Associates"><vers edition="Windows NT" num="4.5"/></prod><prod name="Netshield" vendor="Network Associates"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0651" published="2000-07-07" seq="2000-0651" severity="High" type="CVE"><desc><descript source="cve">The ClientTrust program in Novell BorderManager does not properly verify the origin of authentication requests, which could allow remote attackers to impersonate another user by replaying the authentication requests and responses from port 3024 of the victim&apos;s machine.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1440">BID 1440</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4906.php">Bypass url restrictions 4906</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D06256915.00591E18.00@uprrsmtp2.notes.up.com">Unauthenticated user can web surf as any authenticated user</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=06256915.00591E18.00@uprrsmtp2.notes.up.com">20000707 Novell Border Manger - Anyone can pose as an authenticated user</ref><ref source="XF" url="http://xforce.iss.net/static/5186.php">novell-bordermanager-verification</ref></refs><vuln_soft><prod name="BorderManager" vendor="Novell"><vers num="3.5"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-21" name="CVE-2000-0652" published="2000-07-24" seq="2000-0652" severity="Medium" type="CVE"><desc><descript source="cve">IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the &quot;/servlet/file&quot; string.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1500">BID 1500</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4697.php">websphere-jsp-source-read(4697)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0342.html"> IBM WebSphere default servlet handler showcode vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/5012.php">websphere-showcode</ref></refs><vuln_soft><prod name="Websphere Application Server" vendor="IBM"><vers num="3.0.21"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0653" published="2000-07-20" seq="2000-0653" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook Express allows remote attackers to monitor a user&apos;s email by creating a persistent browser link to the Outlook Express windows, aka the &quot;Persistent Mail-Browser Link&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1502">BID 1502</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4973.php">outlook-express-mail-browser-link(4973)</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/MS00-045.asp">Microsoft Security Bulletin (MS00-045)</ref></refs><vuln_soft><prod name="Outlook Express" vendor="Microsoft"><vers num="5.0.1"/><vers num="5.0"/><vers num="4.01"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-0654" published="2000-07-11" seq="2000-0654" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Enterprise Manager allows local users to obtain database passwords via the Data Transformation Service (DTS) package Registered Servers Dialog dialog, aka a variant of the &quot;DTS Password&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1466">BID 1466</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4582.php">mssql-dts-reveal-passwords(4582)</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/ms00-041.asp">Microsoft Security Bulletin (MS00-041)</ref></refs><vuln_soft><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-16" name="CVE-2000-0655" published="2000-07-25" seq="2000-0655" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1503">BID 1503</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/frames/?content=/templates/advisory.html%3Fid%3D2524">Incorrect processing of JPEG images</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D200007242356.DAA01274%40false.com">JPEG COM Marker Processing Vulnerability in Netscape Browsers</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-046.html">RHSA-2000:046</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_60.html">20000823 Security Hole in Netscape, Versions 4.x, possibly others</ref><ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000016.html">TLSA2000017-1</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-011.txt.asc">NetBSD-SA2000-011</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:39.netscape.asc">FreeBSD-SA-00:39</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0456.html">20000801 MDKSA-2000:027-1 netscape update</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0116.html">20000810 Conectiva Linux Security Announcement - netscape</ref><ref source="BID" url="http://www.securityfocus.com/bid/1503">1503</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.73"/><vers num="4.72"/><vers num="4.7"/><vers num="4.61"/><vers num="4.6"/><vers num="4.51"/><vers num="4.5 BETA"/><vers num="4.5"/><vers num="4.0"/><vers num="4.08"/><vers num="4.07"/><vers num="4.06"/><vers num="4.05"/></prod><prod name="Mozilla Browser" vendor="Mozilla"><vers num="M15"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-0656" published="2000-07-25" seq="2000-0656" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1504">BID 1504</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-7.php">analogx-proxy-ftp-crash</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html">AnalogX Proxy DoS</ref><ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/proxy.htm">http://www.analogx.com/contents/download/network/proxy.htm</ref></refs><vuln_soft><prod name="AnalogX Proxy" vendor="AnalogX"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-0657" published="2000-07-25" seq="2000-0657" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1504">BID 1504</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html">AnalogX Proxy DoS</ref><ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/proxy.htm">http://www.analogx.com/contents/download/network/proxy.htm</ref></refs><vuln_soft><prod name="AnalogX Proxy" vendor="AnalogX"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-0658" published="2000-07-25" seq="2000-0658" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1504">BID 1504</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-7.php">analogx-proxy-pop3-crash</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html">AnalogX Proxy DoS</ref><ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/proxy.htm">http://www.analogx.com/contents/download/network/proxy.htm</ref></refs><vuln_soft><prod name="AnalogX Proxy" vendor="AnalogX"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-0659" published="2000-07-25" seq="2000-0659" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1504">BID 1504</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-7.php-analogx-proxy-socks4-crash">analogx-proxy-socks4-crashh</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html">AnalogX Proxy DoS</ref></refs><vuln_soft><prod name="AnalogX Proxy" vendor="AnalogX"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0660" published="2000-07-12" seq="2000-0660" severity="Medium" type="CVE"><desc><descript source="cve">The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1462">BID 1462</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4913.php">worldclient-dir-traverse(4913)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0173.html">Infosec.20000712.worldclient.2.1</ref><ref source="CONFIRM" url="http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt">http://www.altn.com/Downloads/WorldClient/Release/RelNotes.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/1459">1459</ref></refs><vuln_soft><prod name="WorldClient" vendor="Alt-N"><vers edition="Standard" num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0661" published="2000-07-10" seq="2000-0661" severity="Medium" type="CVE"><desc><descript source="cve">WircSrv IRC Server 5.07s allows remote attackers to cause a denial of service via a long string to the server port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1448">BID 1448</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4914.php">wircsrv-character-flood-dos(4914)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0120.html">Remote DoS Attack in WircSrv Irc Server v5.07s Vulnerability</ref></refs><vuln_soft><prod name="IRC Server" vendor="WircSrv"><vers num="5.0.7s"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0662" published="2000-07-14" seq="2000-0662" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.x and Microsoft Outlook allows remote attackers to read arbitrary files by redirecting the contents of an IFRAME using the DHTML Edit Control (DHTMLED).</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1474">BID 1474</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2161.php">ie-dhtml-control(2161)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=396EF9D5.62EEC625@nat.bg">IE 5.5 and 5.01 vulnerability - reading at least local and from any host text and parsed html files</ref><ref source="BID" url="http://www.securityfocus.com/bid/1474">1474</ref><ref source="XF" url="http://xforce.iss.net/static/5107.php">ie-dhtmled-file-read(5107)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5"/><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0663" published="2000-07-25" seq="2000-0663" severity="Medium" type="CVE"><desc><descript source="cve">The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the &quot;Relative Shell Path&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1507">BID 1507</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/MS00-052.asp"> Registry-Invoked Programs Use Standard Search Path</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5040.php">explorer-relative-path-name(5040)</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=269049">Q269049</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2000-0664" published="2000-07-26" seq="2000-0664" severity="Medium" type="CVE"><desc><descript source="cve">AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1508">BID 1508</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-5_num-7.php">analogx-simpleserver-directory-path</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0374.html">AnalogX </ref><ref source="CONFIRM" url="http://www.analogx.com/contents/download/network/sswww.htm">http://www.analogx.com/contents/download/network/sswww.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/1508">1508</ref><ref source="XF" url="http://xforce.iss.net/static/4999.php">analogx-simpleserver-directory-path</ref><ref source="OSVDB" url="http://www.osvdb.org/388">388</ref></refs><vuln_soft><prod name="SimpleServer" vendor="AnalogX"><vers num="1.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0665" published="2000-07-17" seq="2000-0665" severity="Medium" type="CVE"><desc><descript source="cve">GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1478">BID 1478</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4945.php">gamsoft-telsrv-dos(4945)</ref><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0031.html">DoS in Gamsoft TelSrv telnet server for MS Windows 95/98/NT/2k.</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0056.html">20000729 TelSrv Reveals Usernames &amp; Passwords After DoS Attack</ref><ref source="OSVDB" url="http://www.osvdb.org/373">373</ref></refs><vuln_soft><prod name="Telsrv" vendor="GAMSoft"><vers num="1.5"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0666" published="2000-07-16" seq="2000-0666" severity="High" type="CVE"><desc><descript source="cve">rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1480">BID 1480</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4939.php">linux-rpcstatd-format-overwrite(4939)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0206.html">Lots and lots of fun with rpc.statd</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-043.html">RHSA-2000:043</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0230.html">20000717 CONECTIVA LINUX SECURITY ANNOUNCEMENT - nfs-utils</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0236.html">20000718 Trustix Security Advisory - nfs-utils</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0260.html">20000718 [Security Announce] MDKSA-2000:021 nfs-utils update</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-025.0.txt">CSSA-2000-025.0</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2000-17.html">CA-2000-17</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/><vers edition="Sparc" num="6.0"/><vers edition="i386" num="6.0"/><vers edition="Alpha" num="6.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0es"/><vers num="4.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers edition="ppc" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/></prod><prod name="Trustix Linux" vendor="Trustix"><vers num="1.1"/><vers num="1.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.3 sparc"/><vers num="2.3 powerpc"/><vers num="2.3 alpha"/><vers num="2.3"/><vers num="2.2 sparc"/><vers num="2.2 powerpc"/><vers num="2.2 alpha"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0667" published="2000-07-27" seq="2000-0667" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1512">bugtraq id 1512</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4998.php">linux-gpm-file-removal(4998)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0273.html">Security Update: DoS on gpm</ref></refs><vuln_soft><prod name="Conectiva Linux" vendor="Conectiva"><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0es"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0668" published="2000-07-27" seq="2000-0668" severity="Medium" type="CVE"><desc><descript source="cve">pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1513">BID 1513</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5001.php">linux-pam-console(5001)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.redhat.com/support/errata/RHSA-2000-044-02.html">Updated PAM packages are available</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-044.html">RHSA-2000:044</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0398.html">20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - PAM</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0455.html">20000801 MDKSA-2000:029 pam update</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/><vers edition="Sparc" num="6.0"/><vers edition="i386" num="6.0"/><vers edition="Alpha" num="6.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0es"/><vers num="4.0"/></prod><prod name="pam_console" vendor="Michael K. Johnson"><vers num="0.72 unpatched"/><vers num="0.66"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0669" published="2000-07-11" seq="2000-0669" severity="Medium" type="CVE"><desc><descript source="cve">Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1467">BID 1467</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4932.php">netware-port40193-dos(4932)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=000501bfeab5$9330c3d0$d801a8c0@dimuthu.baysidegrp.com.au">Remote Denial Of Service -- NetWare 5.0 with SP 5</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="5.0 SP5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0670" published="2000-07-12" seq="2000-0670" severity="High" type="CVE"><desc><descript source="cve">The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1469">BID 1469</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4925.php">cvsweb-shell-access(4925)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0196.html">MDKSA-2000:019 cvsweb update</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0178.html">20000712 cvsweb: remote shell for cvs committers</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:37.cvsweb.asc">FreeBSD-SA-00:37</ref><ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000015.html">TLSA2000016-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1469">1469</ref></refs><vuln_soft><prod name="CVSWeb" vendor="CVSWeb Developer"><vers num="1.80"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-2000-0671" published="2000-07-21" seq="2000-0671" severity="Medium" type="CVE"><desc><descript source="cve">Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory contents, and read source code by inserting a null character (%00) to the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1510">BID 1510</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/4965">roxen-null-char-url</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0321.html">Roxen security alert: Problems with URLs containing null characters</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0307.html">20000721 Roxen Web Server Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1510">1510</ref><ref source="XF" url="http://xforce.iss.net/static/4965.php">roxen-null-char-url</ref></refs><vuln_soft><prod name="WebServer" vendor="Roxen"><vers num="2.0.X"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2000-0672" published="2000-07-20" seq="2000-0672" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1548">BID 1548</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4205.php">apache-tomcat-file-contents(4205)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0309.html">Jakarta-tomcat.../admin</ref><ref source="BID" url="http://www.securityfocus.com/bid/1548">1548</ref><ref source="XF" url="http://xforce.iss.net/static/5160.php">jakarta-tomcat-admin</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="3.1"/></prod><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0673" published="2000-07-27" seq="2000-0673" severity="Medium" type="CVE"><desc><descript source="cve">The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the &quot;NetBIOS Name Server Protocol Spoofing&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1514">BID 1514</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5035.php">netbios-name-server-spoofing(5035)</ref><ref adv="1" patch="1" source="Microsoft Tech Net" url="http://www.microsoft.com/technet/security/bulletin/MS00-047.asp">Microsoft Security Bulletin (MS00-047)</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/044.asp">20000727 Windows NetBIOS Name Conflicts</ref><ref source="BID" url="http://www.securityfocus.com/bid/1515">1515</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="Terminal Server"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0674" published="2000-07-12" seq="2000-0674" severity="Medium" type="CVE"><desc><descript source="cve">ftp.pl CGI program for Virtual Visions FTP browser allows remote attackers to read directories outside of the document root via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1471">bugtraq id 1471</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0177.html">ftp.pl vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/5187.php">virtualvision-ftp-browser</ref></refs><vuln_soft><prod name="FTP Browser" vendor="Virtual Vision"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0675" published="2000-07-13" seq="2000-0675" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1477">BID 1477</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4948.php">gatekeeper-long-string-bo(4948)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=00af01bfece2$a52cbd80$367e1ec4@kungphusion">The MDMA Crew&apos;s GateKeeper Exploit</ref></refs><vuln_soft><prod name="GateKeeper" vendor="Infopulse"><vers num="3.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0676" published="2000-10-20" seq="2000-0676" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the &quot;file&quot;, &quot;http&quot;, &quot;https&quot;, and &quot;ftp&quot; protocols, as demonstrated by Brown Orifice.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1546">BID 1546</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-15.html">CERT:CA-2000-15</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise58.php">Brown Orifice, BOHTTPD, a Platform Independent Java Vulnerability in Netscape</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0019.html">20000804 Dangerous Java/Netscape Security Hole</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-054.html">RHSA-2000:054</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-027.1.txt">CSSA-2000-027.1</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:39.netscape.asc">FreeBSD-SA-00:39</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_60.html">20000823 Security Hole in Netscape, Versions 4.x, possibly others</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0115.html">20000810 MDKSA-2000:033 Netscape Java vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0265.html">20000821 MDKSA-2000:036 - netscape update</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0236.html">20000818 Conectiva Linux Security Announcement - netscape</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.74"/><vers num="4.73"/><vers num="4.72"/><vers num="4.61"/><vers num="4.6"/><vers num="4.51"/><vers num="4.5 BETA"/><vers num="4.5"/><vers num="4.0"/><vers num="4.08"/><vers num="4.07"/><vers num="4.06"/><vers num="4.05"/><vers num="4.04"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0677" published="2000-10-20" seq="2000-0677" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IBM Net.Data db2www CGI program allows remote attackers to execute arbitrary commands via a long PATH_INFO environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise60.php">Internet Security Systems Security Advisory</ref><ref source="XF" url="http://xforce.iss.net/static/4976.php">ibm-netdata-db2www-bo</ref></refs><vuln_soft><prod name="Net.Data" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0678" published="2000-10-20" seq="2000-0678" severity="Medium" type="CVE"><desc><descript source="cve">PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim&apos;s public certificate to decrypt any data that has been encrypted with the modified certificate.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-18.html">CERT:CA-2000-18</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1606">BID 1606</ref><ref adv="1" source="Cryptome" url="http://cryptome.org/pgp-badbug.htm">Serious bug in PGP - versions 5 and 6</ref><ref source="OSVDB" url="http://www.osvdb.org/4354">4354</ref></refs><vuln_soft><prod name="PGP" vendor="PGP"><vers num="6.5.3i"/><vers num="6.5.1i"/><vers num="5.5.3i"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0679" published="2000-10-20" seq="2000-0679" severity="Low" type="CVE"><desc><descript source="cve">The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dhvou2daoebb.fsf%40serein.m17n.org">cvs security problem</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1523">BID 1523</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0680" published="2000-10-20" seq="2000-0680" severity="High" type="CVE"><desc><descript source="cve">The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dhvou2daoebb.fsf%40serein.m17n.org">cvs security problem</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1524">BID 1524</ref></refs><vuln_soft><prod name="CVS" vendor="CVS"><vers num="1.10.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2000-0681" published="2000-10-20" seq="2000-0681" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in BEA WebLogic server proxy plugin allows remote attackers to execute arbitrary commands via a long URL with a .JSP extension.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0186.html">CORE-081300</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1570">BID 1570</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="4.5.2 SP2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-19" name="CVE-2000-0682" published="2000-10-20" seq="2000-0682" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /ConsoleHelp/ into the URL, which invokes the FileServlet.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html">FS-072800-9-BEA</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1518">BID 1518</ref><ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000731.html">http://developer.bea.com/alerts/security_000731.html</ref><ref source="OSVDB" url="http://www.osvdb.org/1481">1481</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="5.1"/></prod><prod name="WebLogic Enterprise" vendor="BEA Systems"><vers num="5.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="5.1"/><vers num="5.1 SP1"/><vers num="5.1 SP10"/><vers num="5.1 SP11"/><vers num="5.1 SP12"/><vers num="5.1 SP2"/><vers num="5.1 SP3"/><vers num="5.1 SP4"/><vers num="5.1 SP5"/><vers num="5.1 SP6"/><vers num="5.1 SP7"/><vers num="5.1 SP8"/><vers num="5.1 SP9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-06-18" name="CVE-2000-0683" published="2000-10-20" seq="2000-0683" severity="Medium" type="CVE"><desc><descript source="cve">BEA WebLogic 5.1.x allows remote attackers to read source code for parsed pages by inserting /*.shtml/ into the URL, which invokes the SSIServlet.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0410.html">20000728 BEA&apos;s WebLogic force handlers show code vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1517">BID 1517</ref><ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000728.html">http://developer.bea.com/alerts/security_000728.html</ref><ref source="OSVDB" url="http://www.osvdb.org/1480">1480</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="5.1"/></prod><prod name="WebLogic Enterprise" vendor="BEA Systems"><vers num="5.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="5.1 SP1"/><vers num="5.1 SP10"/><vers num="5.1 SP11"/><vers num="5.1 SP12"/><vers num="5.1 SP2"/><vers num="5.1 SP3"/><vers num="5.1 SP4"/><vers num="5.1 SP5"/><vers num="5.1 SP6"/><vers num="5.1 SP7"/><vers num="5.1 SP8"/><vers num="5.1 SP9"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0684" published="2000-10-20" seq="2000-0684" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html">20000731 BEA&apos;s WebLogic *.jsp/*.jhtml remote command execution</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1525">BID 1525</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-02.html">CA-2000-02</ref><ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000731.html">http://developer.bea.com/alerts/security_000731.html</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="4.5.1"/><vers num="4.0.4"/><vers num="3.1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2000-0685" published="2000-10-20" seq="2000-0685" severity="High" type="CVE"><desc><descript source="cve">BEA WebLogic 5.1.x does not properly restrict access to the PageCompileServlet, which could allow remote attackers to compile and execute Java JHTML code by directly invoking the servlet on any source file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0434.html">FS-073100-10-BEA</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1525">BID 1525</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-02.html">CA-2000-02</ref><ref source="CONFIRM" url="http://developer.bea.com/alerts/security_000731.html">http://developer.bea.com/alerts/security_000731.html</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="4.5.1"/><vers num="4.0.4"/><vers num="3.1.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0686" published="2000-10-20" seq="2000-0686" severity="Medium" type="CVE"><desc><descript source="cve">Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0310.html">20000823 Auction WeaverT LITE 1.0</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1630">BID 1630</ref></refs><vuln_soft><prod name="Auction Weaver" vendor="CGI Script Center"><vers num="1.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0687" published="2000-10-20" seq="2000-0687" severity="High" type="CVE"><desc><descript source="cve">Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0310.html">20000823 Auction WeaverT LITE 1.0</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1630">BID 1630</ref></refs><vuln_soft><prod name="Auction Weaver" vendor="CGI Script Center"><vers num="1.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0688" published="2000-10-20" seq="2000-0688" severity="High" type="CVE"><desc><descript source="cve">Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0292.html">20000823 Subscribe Me Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1607">BID 1607</ref><ref source="CONFIRM" url="http://www.cgiscriptcenter.com/subscribe/">http://www.cgiscriptcenter.com/subscribe/</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96722957421029&amp;w=2">20000823 Re: Subscribe Me CGI Vulnerability</ref></refs><vuln_soft><prod name="Subscribe Me Lite" vendor="CGI Script Center"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0689" published="2000-10-20" seq="2000-0689" severity="High" type="CVE"><desc><descript source="cve">Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0291.html">20000823 Account Manager CGI Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1604">BID 1604</ref><ref source="CONFIRM" url="http://www.cgiscriptcenter.com/acctlite/">http://www.cgiscriptcenter.com/acctlite/</ref><ref source="OSVDB" url="http://www.osvdb.org/13341">13341</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5125">account-manager-overwrite-password(5125)</ref></refs><vuln_soft><prod name="Account Manager" vendor="CGI Script Center"><vers num="PRO 1.0"/><vers num="LITE 1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0690" published="2000-10-20" seq="2000-0690" severity="High" type="CVE"><desc><descript source="cve">Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0370.html">20000830 More problems with Auction Weaver &amp; CGI Script Center.</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0452.html">20000830 More problems with Auction Weaver &amp; CGI Script Center.</ref><ref adv="1" patch="1" source="CGI Script Center" url="http://www.cgiscriptcenter.com/awl/awl10.zip"></ref></refs><vuln_soft><prod name="Auction Weaver" vendor="CGI Script Center"><vers num="1.0"/><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0691" published="2000-10-20" seq="2000-0691" severity="Low" type="CVE"><desc><descript source="cve">The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0329.html">20000826 Advisory: mgetty local compromise</ref><ref adv="1" patch="1" source="Caldera Systems" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-029.0.txt">CSSA-2000-029.0</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1612">BID 1612</ref><ref source="CONFIRM" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0330.html">http://archives.neohapsis.com/archives/bugtraq/2000-08/0330.html</ref></refs><vuln_soft><prod name="mgetty" vendor="Gert Doering"><vers num="1.1.21"/><vers num="1.1.20"/><vers num="1.1.19"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0692" published="2000-10-20" seq="2000-0692" severity="Medium" type="CVE"><desc><descript source="cve">ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0267.html">20000822 DOS on RealSecure 3.2</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1597">BID 1597</ref></refs><vuln_soft><prod name="RealSecure" vendor="Internet Security Systems"><vers num="3.2.1"/><vers num="3.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0693" published="2000-10-20" seq="2000-0693" severity="High" type="CVE"><desc><descript source="cve">pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the &quot;cp&quot; program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate &quot;cp&quot; program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1563">BID 1563</ref><ref source="OSVDB" url="http://www.osvdb.org/1501">1501</ref></refs><vuln_soft><prod name="Raptor GFX PGX32" vendor="Tech-Source"><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0694" published="2000-10-20" seq="2000-0694" severity="High" type="CVE"><desc><descript source="cve">pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref><ref source="OSVDB" url="http://www.osvdb.org/5740">5740</ref></refs><vuln_soft><prod name="Raptor GFX PGX32" vendor="Tech-Source"><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0695" published="2000-10-20" seq="2000-0695" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html">20000802 Local root compromise in PGX Config Sun Sparc Solaris</ref></refs><vuln_soft><prod name="Raptor GFX PGX32" vendor="Tech-Source"><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0696" published="2000-10-20" seq="2000-0696" severity="High" type="CVE"><desc><descript source="cve">The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/sun/2000-q3/0001.html">SUN:00196</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1554">BID 1554</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/74382">20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server</ref><ref source="XF" url="http://xforce.iss.net/static/5069.php">solaris-answerbook2-admin-interface(5069)</ref></refs><vuln_soft><prod name="AnswerBook2" vendor="Sun"><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0697" published="2000-10-20" seq="2000-0697" severity="High" type="CVE"><desc><descript source="cve">The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/sun/2000-q3/0001.html">SUN:00196</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1556">BID 1556</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/74382">20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server</ref><ref source="XF" url="http://www.iss.net/security_center/static/5058.php">solaris-answerbook2-remote-execution(5058)</ref></refs><vuln_soft><prod name="AnswerBook2" vendor="Sun"><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-0698" published="2000-10-20" seq="2000-0698" severity="Medium" type="CVE"><desc><descript source="cve">Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/77361">BUGTRAQ:20000819 RH 6.1 / 6.2 minicom vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1599">BID 1599</ref><ref source="XF" url="http://xforce.iss.net/static/5151.php">minicom-capture-groupown</ref></refs><vuln_soft><prod name="minicom" vendor="minicom"><vers num="1.83.1"/><vers num="1.83.0"/><vers num="1.82.1"/><vers num="1.82.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0699" published="2000-10-20" seq="2000-0699" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0028.html">BUGTRAQ:20000806 HPUX FTPd vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1560">BID 1560</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0700" published="2000-10-20" seq="2000-0700" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/gsraclbypassdos-pub.shtml">20000803 Possible Access Control Bypass and Denial of Service in Gigabit Switch Routers Using Gigabit Ethernet or Fast Ethernet Cards</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1541">BID 1541</ref><ref source="OSVDB" url="http://www.osvdb.org/793">793</ref><ref source="OSVDB" url="http://www.osvdb.org/798">798</ref></refs><vuln_soft><prod name="Gigabit Switch Router" vendor="Cisco"><vers num="12016"/><vers num="12012"/><vers num="12008"/></prod><prod name="IOS" vendor="Cisco"><vers num="12.1"/><vers num="12.0.7"/><vers num="12.0.6"/><vers num="12.0.5"/><vers num="12.0.4"/><vers num="12.0.3"/><vers num="12.0.2"/><vers num="12.0.1"/><vers num="12.0"/><vers num="11.3.1"/><vers num="11.3"/><vers num="11.2.8"/><vers num="11.2.10"/><vers num="11.2P"/><vers num="11.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0701" published="2000-10-20" seq="2000-0701" severity="Medium" type="CVE"><desc><descript source="cve">The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/73220">20000801 Advisory: mailman local compromise</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0474.html">20000802 CONECTIVA LINUX SECURITY ANNOUNCEMENT - mailman</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0479.html">20000802 MDKSA-2000:030 - Linux-Mandrake not affected by mailman problem</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/secureserver/RHSA-2000-030-03.html">RHSA-2000:030-03</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1539">BID 1539</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-030.html">RHSA-2000:030</ref><ref source="" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000802105050.A11733@rak.isternet.sk"></ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num=""/></prod><prod name="Mailman" vendor="GNU"><vers num="2.0 beta4"/><vers num="2.0 beta3"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0702" published="2000-10-20" seq="2000-0702" severity="High" type="CVE"><desc><descript source="cve">The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attack that points from /tmp/stcp.conf to the targeted file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0261.html">BUGTRAQ:20000821 [HackersLab bugpaper] HP-UX net.init rc script</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1602">BID 1602</ref><ref source="XF" url="http://xforce.iss.net/static/5131.php">hp-netinit-symlink</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0703" published="2000-10-20" seq="2000-0703" severity="High" type="CVE"><desc><descript source="cve">suidperl (aka sperl) does not properly cleanse the escape sequence &quot;~!&quot; before calling /bin/mail to send an error report, which allows local users to gain privileges by setting the &quot;interactive&quot; environmental variable and calling suidperl with a filename that contains the escape sequence.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0022.html">BUGTRAQ:20000805 sperl 5.00503 (and newer ;) exploit</ref><ref adv="1" patch="1" source="S.u.S.E." url="http://www.suse.de/de/support/security/suse_security_announce_59.txt">SUSE:20000810 Security Hole in perl, all versions</ref><ref adv="1" patch="1" source="Caldera Systems" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-026.0.txt">CALDERA:CSSA-2000-026.0</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1547">BID 1547</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_59.html">20000810 Security Hole in perl, all versions</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-048.html">RHSA-2000:048</ref><ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-August/000017.html">TLSA2000018-1</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0153.html">20000814 Trustix Security Advisory - perl and mailx</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0086.html">20000808 MDKSA-2000:031 perl update</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0113.html">20000810 Conectiva Linux security announcemente - PERL</ref></refs><vuln_soft><prod name="Perl" vendor="Larry Wall"><vers num="5.6"/><vers num="5.5.3"/><vers num="5.5"/><vers num="5.4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0704" published="2000-10-20" seq="2000-0704" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1603">BID 1603</ref><ref source="SGI" url="ftp://sgigate.sgi.com/security/20000803-01-A">20000803-01-A</ref><ref source="OSVDB" url="http://www.osvdb.org/11080">11080</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5163">irix-worldview-wnn-bo(5163)</ref></refs><vuln_soft><prod name="Wnn4" vendor="Wnn"><vers num="4.2.8"/><vers num="4.2.5TL"/><vers num="4.2.2TL"/></prod><prod name="WorldView" vendor="Omron"><vers num="6.5"/></prod><prod name="FreeWnn" vendor="FreeWnn"><vers num="1.1.1 aXXX"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0705" published="2000-10-20" seq="2000-0705" severity="Medium" type="CVE"><desc><descript source="cve">ntop running in web mode allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0459.html">20000802 [ Hackerslab bug_paper ] ntop web mode vulnerability</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0065.html">REDHAT:RHSA-2000:049-02</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1550">BID 1550</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-049.html">RHSA-2000:049</ref><ref source="OSVDB" url="http://www.osvdb.org/1496">1496</ref></refs><vuln_soft><prod name="ntop" vendor="Luca Deri"><vers num="1.2a7_9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0706" published="2000-10-20" seq="2000-0706" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0095.html">FREEBSD:FreeBSD-SA-00:36</ref><ref adv="1" source="Debian" url="http://www.debian.org/security/2000/20000830">DEBIAN:20000830 ntop: Still remotely exploitable using buffer</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1576">BID 1576</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:36.ntop.asc">FreeBSD-SA-00:36</ref><ref source="OSVDB" url="http://www.osvdb.org/1513">1513</ref></refs><vuln_soft><prod name="ntop" vendor="Luca Deri"><vers num="1.3.1"/><vers num="1.2a7_9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0707" published="2000-10-20" seq="2000-0707" severity="High" type="CVE"><desc><descript source="cve">PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0015.html">BUGTRAQ:20000804 PCCS MySQL DB Admin Tool v1.2.3- Advisory</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1557">BID:1557</ref><ref source="" url="http://pccs-linux.com/public/view.php3?bn=agora_pccslinux&amp;key=965951324"></ref></refs><vuln_soft><prod name="MySQLDatabase Admin Tool" vendor="PCCS-Linux"><vers num="1.2.4"/><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0708" published="2000-10-20" seq="2000-0708" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via a long series of null characters to the rexec port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=NTBUGTRAQ&amp;P=R4247">NTBUGTRAQ:20000824 Remote DoS Attack in Pragma TelnetServer 2000</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1605">BID 1605</ref><ref source="CONFIRM" url="http://www.pragmasys.com/TelnetServer/">http://www.pragmasys.com/TelnetServer/</ref></refs><vuln_soft><prod name="TelnetServer" vendor="Pragma Systems"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0709" published="2000-10-20" seq="2000-0709" severity="Medium" type="CVE"><desc><descript source="cve">The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html">20000823 Xato Advisory: FrontPage DOS Device DoS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1608">BID 1608</ref><ref source="CONFIRM" url="http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp">http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp</ref></refs><vuln_soft><prod name="FrontPage" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0710" published="2000-10-20" seq="2000-0710" severity="Medium" type="CVE"><desc><descript source="cve">The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html">20000823 Xato Advisory: FrontPage DOS Device DoS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1608">BID 1608</ref><ref source="CONFIRM" url="http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp">http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp</ref></refs><vuln_soft><prod name="FrontPage" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0711" published="2000-10-20" seq="2000-0711" severity="High" type="CVE"><desc><descript source="cve">Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim&apos;s system via a malicious applet, as demonstrated by Brown Orifice.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=3999922128E.EE84TAKAGI@java-house.etl.go.jp">20000816 JDK 1.1.x Listening Socket Vulnerability (was Re: BrownOrifice can break firewalls!)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000805020429.11774.qmail@securityfocus.com">20000805 Dangerous Java/Netscape Security Hole</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-15.html">CA-2000-15</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1545">BID 1545</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.74"/><vers num="4.73"/><vers num="4.72"/><vers num="4.7"/><vers num="4.61"/><vers num="4.6"/><vers num="4.51"/><vers num="4.5"/><vers num="4.0"/><vers num="4.08"/><vers num="4.07"/><vers num="4.06"/><vers num="4.05"/><vers num="4.04"/></prod><prod name="Virtual Machine" vendor="Microsoft"><vers num="2000"/><vers num="3300"/><vers num="3200"/><vers num="3100"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0712" published="2000-10-20" seq="2000-0712" severity="High" type="CVE"><desc><descript source="cve">Linux Intrusion Detection System (LIDS) 0.9.7 allows local users to gain root privileges when LIDS is disabled via the security=0 boot option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0486.html">BUGTRAQ:2000803 LIDS severe bug</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1549">BID 1549</ref><ref source="MISC" url="http://www.egroups.com/message/lids/1038">http://www.egroups.com/message/lids/1038</ref><ref source="CONFIRM" url="http://www.lids.org/changelog.html">http://www.lids.org/changelog.html</ref><ref source="OSVDB" url="http://www.osvdb.org/1495">1495</ref></refs><vuln_soft><prod name="LIDS" vendor="LIDS"><vers num="0.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0713" published="2000-10-20" seq="2000-0713" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0382.html">20000726 [SPSadvisory#39]Adobe Acrobat Series PDF File Buffer Overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1509">BID 1509</ref><ref source="CONFIRM" url="http://www.adobe.com/misc/pdfsecurity.html">http://www.adobe.com/misc/pdfsecurity.html</ref></refs><vuln_soft><prod name="Acrobat" vendor="Adobe"><vers num="4.0.5"/><vers num="4.0"/><vers num="3.0"/></prod><prod name="Acrobat Business Tools" vendor="Adobe"><vers num="4.05"/><vers num="4.0"/></prod><prod name="Acrobat Reader" vendor="Adobe"><vers num="4.0.5"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0714" published="2000-10-20" seq="2000-0714" severity="High" type="CVE"><desc><descript source="cve">umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2000-047-03.html">REDHAT:RHSA-2000:047-03</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1551">BID 1551</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-047.html">RHSA-2000:047</ref></refs><vuln_soft><prod name="scheme" vendor="University of Massachusetts"><vers num="3.2.11"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-02-28" name="CVE-2000-0715" published="2000-10-20" seq="2000-0715" severity="Low" type="CVE"><desc><descript source="cve">DiskCheck script diskcheck.pl in Red Hat Linux 6.2 allows local users to create or overwrite arbitrary files via a symlink attack on a temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1552">BID 1552</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=398BD1FD.BAEE3B70@chonnam.chonnam.ac.kr">20000805 Diskcheck 3.1.1 Symlink Vulnerability</ref><ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2000/Jun/0298.html">20000622 Re: rh 6.2 - gid compromises, etc [+ MORE!!!]</ref><ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2000/Aug/0082.html">20000805 Diskcheck 3.1.1 Symlink Vulnerability</ref><ref source="BUGTRAQ" url="http://seclists.org/bugtraq/2000/Aug/0096.html">20000807 Re: Diskcheck 3.1.1 Symlink Vulnerability</ref></refs><vuln_soft><prod name="Conectiva Linux" vendor="Conectiva"><vers num="5.1"/><vers num="5.0"/></prod><prod name="DiskCheck" vendor="Kirk Bauer"><vers num="3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0716" published="2000-10-20" seq="2000-0716" severity="Low" type="CVE"><desc><descript source="cve">WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijcak the session ID and read the user&apos;s email.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=459">20000809</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1553">BID 1553</ref><ref source="XF" url="http://xforce.iss.net/static/5070.php">mdaemon-session-id-hijack</ref></refs><vuln_soft><prod name="MDaemon" vendor="Alt-N"><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0717" published="2000-10-20" seq="2000-0717" severity="Medium" type="CVE"><desc><descript source="cve">GoodTech FTP server allows remote attackers to cause a denial of service via a large number of RNTO commands.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=02ff01c0124c$e9387660$0201a8c0@aviram">20000830 [EXPL] GoodTech&apos;s FTP Server vulnerable to a DoS (RNTO)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1619">BID 1619</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5166">ftp-goodtech-rnto-dos(5166)</ref></refs><vuln_soft><prod name="FTP Server 95_98" vendor="GoodTech"><vers num="3.0.1"/><vers num="3.0"/></prod><prod name="FTP Server NT_2000" vendor="GoodTech"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0718" published="2000-10-20" seq="2000-0718" severity="Low" type="CVE"><desc><descript source="cve">A race condition in MandrakeUpdate allows local users to modify RPM files while they are in the /tmp directory before they are installed.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0146.html">NTBUGTRAQ:20000809 Session hijacking in Alt-N&apos;s MDaemon 2.8</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1567">BID 1567</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0719" published="2000-10-20" seq="2000-0719" severity="Medium" type="CVE"><desc><descript source="cve">VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/><user_init/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0126.html">20000810 VariCAD 7.0 premission vulnerability</ref></refs><vuln_soft><prod name="VariCAD" vendor="VariCAD"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-2000-0720" published="2000-10-20" seq="2000-0720" severity="Medium" type="CVE"><desc><descript source="cve">news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=003301c0123b$18f8c1a0$953b29d4@e8s9s4">BUGTRAQ:20000929 News Publisher CGI Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1621">BID 1621</ref><ref source="XF" url="http://xforce.iss.net/static/5169.php">news-publisher-add-author(5169)</ref></refs><vuln_soft><prod name="GWScripts News Publisher" vendor="GWScripts"><vers num="1.06"/><vers num="1.05b"/><vers num="1.05a"/><vers num="1.05"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0721" published="2000-10-20" seq="2000-0721" severity="Medium" type="CVE"><desc><descript source="cve">The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/><user_init/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0114.html">20000810 FlagShip v4.48.7449 premission vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1586">BID 1586</ref></refs><vuln_soft><prod name="FlagShip" vendor="Multisoft"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0722" published="2000-10-20" seq="2000-0722" severity="Medium" type="CVE"><desc><descript source="cve">Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0240.html">20000820 Helix Code Security Advisory - Helix GNOME Update</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0251.html">20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1593">BID 1593</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=E13QAYl-0007il-00@the-village.bc.nu">20000819 Multiple Local Vulnerabilities in Helix Gnome Installer</ref></refs><vuln_soft><prod name="GNOME Updater" vendor="Helix Code"><vers num="0.5"/><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0723" published="2000-10-20" seq="2000-0723" severity="Low" type="CVE"><desc><descript source="cve">Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0251.html">20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1596">BID 1596</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=E13QAYl-0007il-00@the-village.bc.nu">20000819 Multiple Local Vulnerabilities in Helix Gnome Installer</ref></refs><vuln_soft><prod name="GNOME Installer" vendor="Helix Code"><vers num="0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0724" published="2000-10-20" seq="2000-0724" severity="Medium" type="CVE"><desc><descript source="cve">The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/><user_init/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0351.html">20000829 More Helix Code installation problems (go-gnome)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0356.html">20000829 Helix Code Security Advisory - go-gnome pre-installer</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1622">BID 1622</ref></refs><vuln_soft><prod name="Go-Gnome Pre-Installer" vendor="Helix Code"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0725" published="2000-10-20" seq="2000-0725" severity="High" type="CVE"><desc><descript source="cve">Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0131.html">REDHAT:RHSA-2000:052-02</ref><ref adv="1" source="Debian" url="http://www.debian.org/security/2000/20000821">DEBIAN:20000821 zope: unauthorized escalation of privilege (update)</ref><ref patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0259.html">BUGTRAQ:20000821 Conectiva Linux Security Announcement - Zope</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0198.html">BUGTRAQ:20000816 MDKSA-2000:035 Zope update</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1577">BID 1577</ref><ref source="CONFIRM" url="http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert">http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-052.html">RHSA-2000:052</ref></refs><vuln_soft><prod name="Zope" vendor="Zope"><vers num="2.2 beta1"/><vers num="2.1.7"/><vers num="2.1.1"/><vers num="1.10.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0726" published="2000-10-20" seq="2000-0726" severity="Low" type="CVE"><desc><descript source="cve">CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000829194618.H7744@thathost.com">20000829 Stalker&apos;s CGImail Gives Read Access to All Server Files</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1623">BID 1623</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5165">mailers-cgimail-spoof(5165)</ref></refs><vuln_soft><prod name="Mailers" vendor="Stalkerlab"><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0727" published="2000-10-20" seq="2000-0727" severity="High" type="CVE"><desc><descript source="cve">xpdf PDF viewer client earlier than 0.91 does not properly launch a web browser for embedded URL&apos;s, which allows an attacker to execute arbitrary commands via a URL that contains shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="The AIMS Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96766355023239&amp;w=2">BUGTRAQ:20000829 MDKSA-2000:041 - xpdf update</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20000910a">DEBIAN:20000910 xpdf: local exploit</ref><ref adv="1" patch="1" source="Caldera Systems" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt">CALDERA:CSSA-2000-031.0</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1624">BID 1624</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96886599829687&amp;w=2">20000913 Conectiva Linux Security Announcement - xpdf</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-060.html">RHSA-2000:060</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num="0.90"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0728" published="2000-10-20" seq="2000-0728" severity="High" type="CVE"><desc><descript source="cve">xpdf PDF viewer client earlier than 0.91 allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="The AIMS Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96766355023239&amp;w=2">BUGTRAQ:20000829 MDKSA-2000:041 - xpdf update</ref><ref adv="1" patch="1" source="The AIMS Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96886599829687&amp;w=2">BUGTRAQ:20000913 Conectiva Linux Security Announcement - xpdf</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20000910a">DEBIAN:20000910 xpdf: local exploit</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-060-03.html">REDHAT:RHSA-2000:060-03</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1624">BID 1624</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-060.html">RHSA-2000:060</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-031.0.txt">CSSA-2000-031.0</ref></refs><vuln_soft><prod name="Xpdf" vendor="Xpdf"><vers num="0.90"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0729" published="2000-10-20" seq="2000-0729" severity="Low" type="CVE"><desc><descript source="cve">FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0337.html">FreeBSD-SA-00:41</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1625">BID 1625</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5967">freebsd-elf-dos(5967)</ref><ref source="OSVDB" url="http://www.osvdb.org/1534">1534</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.1"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0730" published="2000-10-20" seq="2000-0730" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html">HPSBUX0008-118</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1580">BID 1580</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0731" published="2000-10-20" seq="2000-0731" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Worm HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0111.html">20000825 DST2K0023</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1626">BID 1626</ref><ref source="XF" url="http://xforce.iss.net/static/5148.php">wormhttp-dir-traverse(5148)</ref><ref source="OSVDB" url="http://www.osvdb.org/1535">1535</ref></refs><vuln_soft><prod name="Worm Webserver" vendor="Jeremy Arnold"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0732" published="2000-10-20" seq="2000-0732" severity="Medium" type="CVE"><desc><descript source="cve">Worm HTTP server allows remote attackers to cause a denial of service via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0111.html">20000825 DST2K0023: Directory Traversal Possible &amp; Denial of Service in Wo rm HTTP Server</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1626">BID 1626</ref><ref source="XF" url="http://xforce.iss.net/static/5149.php">wormhttp-filename-dos</ref></refs><vuln_soft><prod name="Worm Webserver" vendor="Jeremy Arnold"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0733" published="2000-10-20" seq="2000-0733" severity="High" type="CVE"><desc><descript source="cve">Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote attackers to execute arbitrary commands via a long RLD variable in the IAC-SB-TELOPT_ENVIRON request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0154.html">20000814</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1572">BID 1572</ref><ref source="SGI" url="ftp://sgigate.sgi.com/security/20000801-02-P">20000801-02-P</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.8"/><vers num="6.5.7"/><vers num="6.5.6"/><vers num="6.5.4"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.2m"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0734" published="2000-10-20" seq="2000-0734" severity="Medium" type="CVE"><desc><descript source="cve">eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1627">BID 1627</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96774637326591&amp;w=2">20000831 Remote DoS Attack in Eeye Iris 1.01 and SpyNet CaptureNet v3.12</ref></refs><vuln_soft><prod name="CaptureNet" vendor="SpyNet"><vers num="3.0.12"/></prod><prod name="IRIS" vendor="eEye Digital Security"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0735" published="2000-10-20" seq="2000-0735" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0234.html">20000818 Becky! Internet Mail Buffer overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1588">BID 1588</ref><ref source="CONFIRM" url="http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt">http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt</ref></refs><vuln_soft><prod name="Becky Internet Mail" vendor="RimArts Inc."><vers num="1.26.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0736" published="2000-10-20" seq="2000-0736" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0234.html">20000818 Becky! Internet Mail Buffer overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1588">BID 1588</ref><ref source="CONFIRM" url="http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt">http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt</ref></refs><vuln_soft><prod name="Becky Internet Mail" vendor="RimArts Inc."><vers num="1.26.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0737" published="2000-10-20" seq="2000-0737" severity="Medium" type="CVE"><desc><descript source="cve">The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the &quot;Service Control Manager Named Pipe Impersonation&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-053.asp">MS:MS00-053</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1535">BID 1535</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0738" published="2000-10-20" seq="2000-0738" severity="Medium" type="CVE"><desc><descript source="cve">WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0101.html">NTBUGTRAQ:20000818 WebShield SMTP infinite loop DoS Attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1589">BID 1589</ref><ref source="XF" url="http://xforce.iss.net/static/5100.php">webshield-smtp-dos</ref></refs><vuln_soft><prod name="WebShield SMTP" vendor="Network Associates"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0739" published="2000-10-20" seq="2000-0739" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html">BUGTRAQ:20000802 NAI Net Tools PKI Server vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1537">BID 1537</ref><ref source="CONFIRM" url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref><ref source="XF" url="http://xforce.iss.net/static/5066.php">nettools-pki-dir-traverse(5066)</ref><ref source="OSVDB" url="http://www.osvdb.org/1489">1489</ref></refs><vuln_soft><prod name="Net Tools PKI Server" vendor="Network Associates"><vers num="1.0Hotfix2"/><vers num="1.0Hotfix1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0740" published="2000-10-20" seq="2000-0740" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html">BUGTRAQ:20000802 NAI Net Tools PKI Server vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1536">BID 1536</ref><ref source="CONFIRM" url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref><ref source="XF" url="http://xforce.iss.net/static/5026.php">nai-nettools-strong-bo(5026)</ref><ref source="OSVDB" url="http://www.osvdb.org/1488">1488</ref></refs><vuln_soft><prod name="Net Tools PKI Server" vendor="Network Associates"><vers num="1.0Hotfix2"/><vers num="1.0Hotfix1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0741" published="2000-10-20" seq="2000-0741" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html">BUGTRAQ:20000802 NAI Net Tools PKI Server vulnerabilities</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1538">BID 1538</ref><ref source="CONFIRM" url="http://download.nai.com/products/licensed/pgp/hf3pki10.txt">http://download.nai.com/products/licensed/pgp/hf3pki10.txt</ref><ref source="OSVDB" url="http://www.osvdb.org/1490">1490</ref></refs><vuln_soft><prod name="Net Tools PKI Server" vendor="Network Associates"><vers num="1.0Hotfix2"/><vers num="1.0Hotfix1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0742" published="2000-10-20" seq="2000-0742" severity="Medium" type="CVE"><desc><descript source="cve">The IPX protocol implementation in Microsoft Windows 95 and 98 allows remote attackers to cause a denial of service by sending a ping packet with a source IP address that is a broadcast address, aka the &quot;Malformed IPX Ping Packet&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;mid=63120">BUGTRAQ:20000602 ipx storm</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-054.asp">MS:MS00-054</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1544">BID 1544</ref><ref source="XF" url="http://xforce.iss.net/static/5079.php">win-ipx-ping-packet(5079)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0743" published="2000-10-20" seq="2000-0743" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0112.html">BUGTRAQ:20000810 Remote vulnerability in Gopherd 2.x</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1569">BID 1569</ref></refs><vuln_soft><prod name="gopherd" vendor="University of Minnesota"><vers num="2.3.1"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0744" published="2000-10-20" seq="2000-0744" severity="High" type="CVE"><desc><descript source="cve">DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-2000-0743.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0112.html">BUGTRAQ:20000810 Remote vulnerability in Gopherd 2.x</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1569">BID 1569</ref></refs><vuln_soft><prod name="gopherd" vendor="University of Minnesota"><vers num="2.3.1"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0745" published="2000-10-20" seq="2000-0745" severity="High" type="CVE"><desc><descript source="cve">admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to gain privileges by requesting a URL that does not specify the aid or pwd parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0243.html">20000821 Vuln. in all sites using PHP-Nuke, versions less than 3</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1592">BID 1592</ref><ref source="OSVDB" url="http://www.osvdb.org/1521">1521</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="2.5"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0746" published="2000-10-20" seq="2000-0746" severity="High" type="CVE"><desc><descript source="cve">Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks.  They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client.  The client then executes those scripts in the same context as the trusted site, aka the &quot;IIS Cross-Site Scripting&quot; vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-060.asp">MS:MS00-060</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1594">BID 1594</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1595">BID 1595</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=39A12BD6.E811BF4F@nat.bg">20000821 IIS 5.0 cross site scripting vulnerability - using .shtml files or /_vti_bin/shtml.dll</ref></refs><vuln_soft><prod name="Frontpage" vendor="Microsoft"><vers num=""/></prod><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2000-0747" published="2000-10-20" seq="2000-0747" severity="High" type="CVE"><desc><descript source="cve">The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0379.html">BUGTRAQ:20000726 CONECTIVA LINUX SECURITY ANNOUNCEMENT - OPENLDAP</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/5036">OpenLDAP logrotate script denial of service</ref></refs><vuln_soft><prod name="Conectiva Linux" vendor="Conectiva"><vers num="4.1"/><vers num="4.2"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0748" published="2000-10-20" seq="2000-0748" severity="Medium" type="CVE"><desc><descript source="cve">OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0375.html">20000726 Group-writable executable in OpenLDAP</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1511">BID 1511</ref></refs><vuln_soft><prod name="OpenLDAP" vendor="OpenLDAP"><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.11"/><vers num="1.2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0749" published="2000-10-20" seq="2000-0749" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0338.html">FREEBSD:FreeBSD-SA-00:42</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1628">BID 1628</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5968">freebsd-linux-module-bo(5968)</ref><ref source="OSVDB" url="http://www.osvdb.org/1536">1536</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0"/><vers num="4.1"/><vers num="4.0"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0750" published="2000-10-20" seq="2000-0750" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/powertools/RHSA-2000-050-01.html">REDHAT:RHSA-2000-050-01</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0064.html">BUGTRAQ:20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0336.html">FREEBSD:FreeBSD-SA-00:40</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata.html">OPENBSD:20000705 Mopd contained a buffer overflow.</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1558">BID 1558</ref><ref source="" url="http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h"></ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html#mopd">20000705 Mopd contained a buffer overflow.</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-050.html">RHSA-2000:050</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.2"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0751" published="2000-10-20" seq="2000-0751" severity="High" type="CVE"><desc><descript source="cve">mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0064.html">BUGTRAQ:20000808 OpenBSD 2.7 / NetBSD 1.4.2 mopd buffer overflow</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0336.html">FREEBSD:FreeBSD-SA-00:40</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1559">BID 1559</ref><ref source="" url="http://cvsweb.netbsd.org/bsdweb.cgi/basesrc/usr.sbin/mopd/mopd/process.c.diff?r1=1.7&amp;r2=1.8&amp;f=h"></ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html#mopd">20000705 Mopd contained a buffer overflow.</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-050.html">RHSA-2000:050</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.2"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0752" published="2000-10-20" seq="2000-0752" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0339.html">FREEBSD:FreeBSD-SA-00:43</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1629">BID 1629</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.1"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0753" published="2000-10-20" seq="2000-0753" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft Outlook mail client identifies the physical path of the sender&apos;s machine within a winmail.dat attachment to Rich Text Format (RTF) files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=LAW2-F305bYiMCIqtQv0000069d@hotmail.com">BUGTRAQ:20000824 Outlook winmail.dat</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1631">BID 1631</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/78240">20000824 Outlook winmail.dat</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/201422">20010802 Outlook 2000 Rich Text information disclosure</ref><ref source="XF" url="http://xforce.iss.net/static/5508.php">outlook-reveal-path(5508)</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="97"/><vers num="98"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0754" published="2000-10-20" seq="2000-0754" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in HP OpenView Network Node Manager (NMM) version 6.1 related to passwords.</descript></desc><loss_types><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html">HP:HPSBUX0008-119</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1581">BID 1581</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0755" published="2000-10-20" seq="2000-0755" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html">HP:HPSBUX0008-118</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1581">BID 1581</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0756" published="2000-10-20" seq="2000-0756" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1633">BID 1633</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Springmail.105.967737080.0.16997300@www.springmail.com">20000831 vCard DoS on Outlook 2000</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="98"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0757" published="2000-10-20" seq="2000-0757" severity="High" type="CVE"><desc><descript source="cve">The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapssis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0074.html">20000808 Exploit for Totalbill...</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1555">BID 1555</ref></refs><vuln_soft><prod name="TotalBill" vendor="Aptis Software"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0758" published="2000-10-20" seq="2000-0758" severity="Medium" type="CVE"><desc><descript source="cve">The web interface for Lyris List Manager 3 and 4 allows list subscribers to obtain administrative access by modifying the value of the list_admin hidden form field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0149.html">BUGTRAQ:20000811 Lyris List Manager Administration Hole</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1584">BID 1584</ref><ref source="CONFIRM" url="http://www.lyris.com/lm/lm_updates.html">http://www.lyris.com/lm/lm_updates.html</ref></refs><vuln_soft><prod name="List Manager" vendor="Lyris"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2000-0759" published="2000-10-20" seq="2000-0759" severity="Medium" type="CVE"><desc><descript source="cve">Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719184401.17782A-100000@grex.cyberspace.org">20000719 [LoWNOISE] Tomcat 3.1 Path Revealing Problem.</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1531">BID 1531</ref><ref source="XF" url="http://www.iss.net/security_center/static/4967.php">tomcat-error-path-reveal(4967)</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2000-0760" published="2000-10-20" seq="2000-0760" severity="Medium" type="CVE"><desc><descript source="cve">The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719235404.24004A-100000@grex.cyberspace.org">20000719 [LoWNOISE] Snoop Servlet (Tomcat 3.1 and 3.0)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1532">BID 1532</ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0761" published="2000-10-20" seq="2000-0761" severity="Medium" type="CVE"><desc><descript source="cve">OS2/Warp 4.5 FTP server allows remote attackers to cause a denial of service via a long username.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0166.html">BUGTRAQ:20000815 OS/2 Warp 4.5 FTP Server DoS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1582">BID 1582</ref><ref source="CONFIRM" url="ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/README">ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/README</ref></refs><vuln_soft><prod name="OS_2 FTP Server" vendor="IBM"><vers num="4.3"/><vers num="4.2"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0762" published="2000-10-20" seq="2000-0762" severity="High" type="CVE"><desc><descript source="cve">The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=004601c003a1$ba473260$ddeaa2cd@itradefair.net">20000811 eTrust Access Control - Root compromise for default install</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1583">BID 1583</ref><ref source="CONFIRM" url="http://support.ca.com/techbases/eTrust/etrust_access_control-response.html">http://support.ca.com/techbases/eTrust/etrust_access_control-response.html</ref><ref source="XF" url="http://xforce.iss.net/static/5076.php">etrust-access-control-default</ref><ref source="OSVDB" url="http://www.osvdb.org/1517">1517</ref></refs><vuln_soft><prod name="eTrust Access Control" vendor="Computer Associates"><vers num="5.0 SP1"/><vers num="5.0"/><vers num="4.1 SP1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0763" published="2000-10-20" seq="2000-0763" severity="High" type="CVE"><desc><descript source="cve">xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privileges via the -d option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000815231724.A14694@subterrain.net">BUGTRAQ:20000816 xlock vulnerability</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20000816">DEBIAN:20000816 xlockmore: possible shadow file compromise</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0340.html">FREEBSD:FreeBSD-SA-00:44.xlockmore</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1585">BID 1585</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0212.html">20000817 Conectiva Linux Security Announcement - xlockmore</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0294.html">20000823 MDKSA-2000:038 - xlockmore update</ref></refs><vuln_soft><prod name="xlock" vendor="David Bagley"><vers num="4.16.1"/><vers num="4.16"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0764" published="2000-10-20" seq="2000-0764" severity="Medium" type="CVE"><desc><descript source="cve">Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0338.html">BUGTRAQ:20000828 Intel Express Switch 500 series DoS</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1609">BID 1609</ref><ref source="XF" url="http://xforce.iss.net/static/5154.php">intel-express-switch-dos</ref></refs><vuln_soft><prod name="Intel Express" vendor="Intel"><vers num="8100"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0765" published="2000-10-20" seq="2000-0765" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the &quot;Microsoft Office HTML Object Tag&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-056.asp">MS:MS00-056</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1561">BID 1561</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="2000"/></prod><prod name="PowerPoint" vendor="Microsoft"><vers num="2000"/></prod><prod name="Excel" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0766" published="2000-10-20" seq="2000-0766" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileges via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008270354.UAA10952@user4.hushmail.com">BUGTRAQ:20000819 D.o.S Vulnerability in vqServer</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1610">BID 1610</ref><ref source="XF" url="http://xforce.iss.net/static/5152.php">vqserver-get-dos</ref></refs><vuln_soft><prod name="vqServer" vendor="vqSoft"><vers num="1.4.49"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0767" published="2000-10-20" seq="2000-0767" severity="Low" type="CVE"><desc><descript source="cve">The ActiveX control for invoking a scriptlet in Internet Explorer 4.x and 5.x renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka the &quot;Scriptlet Rendering&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-055.asp">MS:MS00-055</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1564">BID 1564</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5"/><vers num="5.01"/><vers num="5.0"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0768" published="2000-10-20" seq="2000-0768" severity="Low" type="CVE"><desc><descript source="cve">A function in Internet Explorer 4.x and 5.x does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a variant of the &quot;Frame Domain Verification&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-055.asp">MS:MS00-055</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1564">BID 1564</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5"/><vers num="5.01"/><vers edition="Windows" num="5.0"/><vers edition="Windows 98" num="5.0"/><vers edition="Windows 95" num="5.0"/><vers edition="Windows 2000" num="5.0"/><vers edition="Windows NT" num="4.0"/><vers edition="Windows 98" num="4.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0769" published="2000-10-20" seq="2000-0769" severity="High" type="CVE"><desc><descript source="cve">O&apos;Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1611">BID 1611</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/294.php">http-website-uploader(294)</ref><ref adv="1" source="The AIMS Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602880019759&amp;w=2">[Alert] Website&apos;s uploader.exe (from demo) vulnerable</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96715834610888&amp;w=2">20000824 WebServer Pro 2.3.7 Vulnerability</ref></refs><vuln_soft><prod name="WebSite Pro" vendor="OReilly"><vers num="2.3.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0770" published="2000-10-20" seq="2000-0770" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the &quot;File Permission Canonicalization&quot; vulnerability.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-057.asp">MS:MS00-057</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1565">BID 1565</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-057.asp">MS00-057</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0771" published="2000-10-20" seq="2000-0771" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Windows 2000 allows local users to cause a denial of service by corrupting the local security policy via malformed RPC traffic, aka the &quot;Local Security Policy Corruption&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-062.asp">MS:MS00-062</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1613">BID 1613</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0772" published="2000-10-20" seq="2000-0772" severity="High" type="CVE"><desc><descript source="cve">The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account &quot;sa&quot; with no password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0098.html">20000810 Tumbleweed Worldsecure (MMS) BLANK &apos;sa&apos; account password vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1562">BID 1562</ref><ref source="CONFIRM" url="http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm">http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm</ref><ref source="XF" url="http://xforce.iss.net/static/5072.php">tumbleweed-mms-blank-password</ref></refs><vuln_soft><prod name="Messaging Management System" vendor="Tumbleweed"><vers num="4.6"/><vers num="4.5"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0773" published="2000-10-20" seq="2000-0773" severity="Medium" type="CVE"><desc><descript source="cve">Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a &quot;....&quot;, a variant of the dot dot directory traversal attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html">BUGTRAQ:20000731 Two security flaws in Bajie Webserver</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1522">BID 1522</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/5021">Bajie HTTP server allows attacker to view arbitrary files</ref></refs><vuln_soft><prod name="Java HTTP Server" vendor="Bajie"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0774" published="2000-10-20" seq="2000-0774" severity="Medium" type="CVE"><desc><descript source="cve">The sample Java servlet &quot;test&quot; in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html">20000731 Two security flaws in Bajie Webserver</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1521">BID 1521</ref></refs><vuln_soft><prod name="Java HTTP Server" vendor="Bajie"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0775" published="2000-10-20" seq="2000-0775" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a long HTTP GET request, or long Unless-Modified-Since, If-Range, or If-Modified-Since headers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1614">BID 1614</ref><ref source="CONFIRM" url="http://www.robtex.com/viking/bugs.htm">http://www.robtex.com/viking/bugs.htm</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=399a01c01122$0d7f2310$0201a8c0@aviram">20000828 [NT] Viking security vulnerabilities enable remote code execution (long URL, date parsing)</ref></refs><vuln_soft><prod name="Viking Server" vendor="RobTex"><vers num="1.0.6 build355" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0776" published="2000-10-20" seq="2000-0776" severity="High" type="CVE"><desc><descript source="cve">Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0118.html">20000810 [DeepZone Advisory] Statistics Server 5.02x stack overflow (Win2k remote exploit)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1568">BID 1568</ref><ref source="XF" url="http://xforce.iss.net/static/5113.php">mediahouse-stats-livestats-bo(5113)</ref></refs><vuln_soft><prod name="Statistics Server LiveStats" vendor="Mediahouse Software"><vers num="5.02"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0777" published="2000-10-20" seq="2000-0777" severity="High" type="CVE"><desc><descript source="cve">The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the &quot;Money Password&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-061.asp">MS:MS00-061</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1615">BID 1615</ref></refs><vuln_soft><prod name="Money" vendor="Microsoft"><vers num="2001"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0778" published="2000-10-20" seq="2000-0778" severity="Medium" type="CVE"><desc><descript source="cve">IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a &quot;Translate: f&quot; header, aka the &quot;Specialized Header&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-058.asp">MS:MS00-058</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=080D5336D882D211B56B0060080F2CD696A7C9@beta.mia.cz">BUGTRAQ:20000815 Translate:f summary, history and thoughts</ref><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind0008&amp;L=ntbugtraq&amp;F=&amp;S=&amp;P=5212">NTBUGTRAQ:20000816 Translate: f</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1578">BID 1578</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:927">oval:org.mitre.oval:def:927</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0779" published="2000-10-20" seq="2000-0779" severity="High" type="CVE"><desc><descript source="cve">Checkpoint Firewall-1 with the RSH/REXEC setting enabled allows remote attackers to bypass access restrictions and connect to a RSH/REXEC client via malformed connection requests.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1534">BID 1534</ref><ref adv="1" source="Check Point" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html">Potential Security Issues in VPN-1/FireWall-1</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Improper_stderr">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Improper_stderr</ref><ref source="OSVDB" url="http://www.osvdb.org/1487">1487</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0780" published="2000-10-20" seq="2000-0780" severity="Medium" type="CVE"><desc><descript source="cve">The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="The AIMS Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96767207207553&amp;w=2">BUGTRAQ:20000830 Vulnerability Report On IPSWITCH&apos;s IMail</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1617">BID 1617</ref><ref source="CONFIRM" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref></refs><vuln_soft><prod name="Imail" vendor="Ipswitch"><vers num="5.0"/><vers num="6.0"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2000-0781" published="2000-10-20" seq="2000-0781" severity="High" type="CVE"><desc><descript source="cve">uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary file before it is moved.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=20000728034420.A19824@sdf.freeshell.org">BUGTRAQ:20000728 Client Agent 6.62 for Unix Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1519">BID 1519</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/5023">ARCServeIT Client Agent uagent temp file</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0431.html">20000728 Client Agent 6.62 for Unix Vulnerability</ref></refs><vuln_soft><prod name="ARCServeIT" vendor="Computer Associates"><vers num="6.63 Linux"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0782" published="2000-10-20" seq="2000-0782" severity="Medium" type="CVE"><desc><descript source="cve">netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=NEBBJCLKGNOGCOIOBJNAGEHLCPAA.marc@eeye.com">BUGTRAQ:20000817 Netauth: Web Based Email Management System</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1587">BID 1587</ref><ref source="CONFIRM" url="http://netwinsite.com/netauth/updates.htm">http://netwinsite.com/netauth/updates.htm</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5090">netwin-netauth-dir-traverse(5090)</ref></refs><vuln_soft><prod name="Netauth" vendor="NetWin"><vers num="4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0783" published="2000-10-20" seq="2000-0783" severity="Medium" type="CVE"><desc><descript source="cve">Watchguard Firebox II allows remote attackers to cause a denial of service by sending a malformed URL to the authentication service on port 4100.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0162.html">BUGTRAQ:20000815 Watchguard Firebox Authentication DoS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1573">BID 1573</ref><ref source="XF" url="http://xforce.iss.net/static/5098.php">firebox-url-dos</ref></refs><vuln_soft><prod name="Firebox" vendor="WatchGuard"><vers num="II"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0784" published="2000-10-20" seq="2000-0784" severity="High" type="CVE"><desc><descript source="cve">sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded &quot;rsadmin&quot; account with a null password, which allows remote attackers to execute arbitrary commands via ssh.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0216.html">20000816 Remote Root Compromise On All RapidStream VPN</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1574">BID 1574</ref></refs><vuln_soft><prod name="RapidStream" vendor="RapidStream"><vers num="8000"/><vers num="6000"/><vers num="4000"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0785" published="2000-10-20" seq="2000-0785" severity="Medium" type="CVE"><desc><descript source="cve">WircSrv IRC Server 5.07s allows IRC operators to read arbitrary files via the importmotd command, which sets the Message of the Day (MOTD) to the specified file.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1448">BID 1448</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96353027909756&amp;w=2">20000713 More wIRCSrv stupidity</ref></refs><vuln_soft><prod name="IRC Server" vendor="WircSrv"><vers num="5.0.7s"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0786" published="2000-10-20" seq="2000-0786" severity="Medium" type="CVE"><desc><descript source="cve">GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0389.html">BUGTRAQ:20000726 userv security boundary tool 1.0.1 (SECURITY FIX)</ref><ref adv="1" source="Debian" url="http://www.debian.org/security/2000/20000727">DEBIAN:20000727 userv: local exploit</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1516">BID 1516</ref><ref source="" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96473640717095&amp;w=2"></ref></refs><vuln_soft><prod name="userv" vendor="Gnu"><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-16" name="CVE-2000-0787" published="2000-10-20" seq="2000-0787" severity="High" type="CVE"><desc><descript source="cve">IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0215.html">BUGTRAQ: 20000817 XChat URL handler vulnerabilty</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1601">BID 1601</ref><ref adv="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-055-03.html">REDHAT:RHSA-2000:055-03</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0301.html">BUGTRAQ:20000824 MDKSA-2000:039 - xchat update</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0305.html">BUGTRAQ:20000825 Conectiva Linux Security Announcement - xchat</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-055.html">RHSA-2000:055</ref></refs><vuln_soft><prod name="XChat" vendor="XChat"><vers num="1.5.xdev"/><vers num="1.5.6"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3.9"/><vers num="1.3.13"/><vers num="1.3.12"/><vers num="1.3.11"/><vers num="1.3.10"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0788" published="2000-10-20" seq="2000-0788" severity="High" type="CVE"><desc><descript source="cve">The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=398EB9CA.27E03A9C@nat.bg">MS Word and MS Access vulnerability - executing arbitrary programs, may be exploited by IE/Outlook</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1566">BID 1566</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-071.asp">MS00-071</ref><ref source="XF" url="http://xforce.iss.net/static/5322.php">word-mail-merge(5322)</ref></refs><vuln_soft><prod name="Access" vendor="Microsoft"><vers num="2000"/></prod><prod name="Word" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0789" published="2000-10-20" seq="2000-0789" severity="Medium" type="CVE"><desc><descript source="cve">WinU 5.x and earlier uses weak encryption to store its configuration password, which allows local users to decrypt the password and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0201.html">20000816 WinU 4/5 weak password vulnerability</ref></refs><vuln_soft><prod name="WinU" vendor="Bardon Data Systems"><vers num="4.X"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2000-0790" published="2000-10-20" seq="2000-0790" severity="Medium" type="CVE"><desc><descript source="cve">The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=3998370D.732A03F1@nat.bg">20000828 IE 5.5/5.x for Win98 may execute arbitrary files that can be accessed thru Microsoft Networking. Also local Administrator compromise at least on default Windows 2000.</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1571">BID 1571</ref><ref source="XF" url="http://xforce.iss.net/static/5097.php">ie-folder-remote-exe(5097)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="a"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0791" published="2000-10-20" seq="2000-0791" severity="Medium" type="CVE"><desc><descript source="cve">Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0179.html">20000815 Trustix security advisory - apache-ssl</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1575">BID 1575</ref></refs><vuln_soft><prod name="Trustix Linux" vendor="Trustix"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0792" published="2000-10-20" seq="2000-0792" severity="High" type="CVE"><desc><descript source="cve">Gnome Lokkit firewall package before 0.41 does not properly restrict access to some ports, even if a user does not make any services available.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0252.html">BUGTRAQ:20000819 Security update for Gnome-Lokkit</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1590">BID 1590</ref><ref source="OSVDB" url="http://www.osvdb.org/1520">1520</ref></refs><vuln_soft><prod name="Gnome-Lokkit" vendor="Alan Cox"><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0793" published="2000-10-20" seq="2000-0793" severity="High" type="CVE"><desc><descript source="cve">Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1533">BID 1533</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=398222C5@zathras.cc.vt.edu">20000728 Norton Antivirus Protection Disabled under Novell Netware</ref></refs><vuln_soft><prod name="Novell client" vendor="Novell"><vers num="3.1"/></prod><prod name="Norton AntiVirus" vendor="Symantec"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0794" published="2000-10-20" seq="2000-0794" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1527">BID 1527</ref><ref source="XF" url="http://www.iss.net/security_center/static/5063.php">irix-libgl-bo(5063)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">20000802 [LSD] some unpublished LSD exploit codes</ref><ref source="OSVDB" url="http://www.osvdb.org/8568">8568</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0795" published="2000-10-20" seq="2000-0795" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">BUGTRAQ:20000802 [LSD] some unpublished LSD exploit codes</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1529">BID 1529</ref><ref source="OSVDB" url="http://www.osvdb.org/1485">1485</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0796" published="2000-10-20" seq="2000-0796" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in dmplay in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long command line option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">BUGTRAQ:20000802 [LSD] some unpublished LSD exploit codes</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1528">BID 1528</ref><ref source="OSVDB" url="http://www.osvdb.org/1484">1484</ref><ref source="XF" url="http://xforce.iss.net/static/5064.php">irix-dmplay-bo(5064)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2000-0797" published="2000-10-20" seq="2000-0797" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">BUGTRAQ:20000802 [LSD] some unpublished LSD exploit codes</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1526">BID 1526</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/5062">IRIX gr_osview buffer overflow</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20040104-01-P.asc">20040104-01-P</ref><ref source="OSVDB" url="http://www.osvdb.org/3815">3815</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0798" published="2000-10-20" seq="2000-0798" severity="High" type="CVE"><desc><descript source="cve">The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1540">BID 1540</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">20000802 [LSD] some unpublished LSD exploit codes</ref><ref source="OSVDB" url="http://www.osvdb.org/8569">8569</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0799" published="2000-10-20" seq="2000-0799" severity="Low" type="CVE"><desc><descript source="cve">inpview in InPerson in SGI IRIX 5.3 through IRIX 6.5.10 allows local users to gain privileges via a symlink attack on the .ilmpAAA temporary file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=200008021924.e72JOVs12558@ix.put.poznan.pl">BUGTRAQ:20000802 [LSD] some unpublished LSD exploit codes</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1530">BID 1530</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I">20001101-01-I</ref><ref source="XF" url="http://xforce.iss.net/static/5065.php">irix-inpview-symlink(5065)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.8"/><vers num="6.5.7"/><vers num="6.5.6"/><vers num="6.5.4"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.2m"/><vers num="6.5.1"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0800" published="2000-10-20" seq="2000-0800" severity="High" type="CVE"><desc><descript source="cve">String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="SuSE" url="http://www.suse.de/de/support/security/suse_security_announce_58.txt">SUSE:20000810 Security Hole in knfsd, all versions</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/suse_security_announce_58.html">20000810 Security Hole in knfsd, all versions</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.1"/><vers num="6.1 alpha"/><vers num="6.2"/><vers num="6.3"/><vers num="6.3 alpha"/><vers edition="ppc" num="6.3"/><vers num="6.4"/><vers num="6.4 alpha"/><vers edition="ppc" num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0801" published="2000-10-20" seq="2000-0801" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0388.html">20000727 [ Hackerslab bug_paper ] HP-UX bdf -t option buffer overflow vul.</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1520">BID 1520</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0802" published="2000-10-20" seq="2000-0802" severity="Low" type="CVE"><desc><descript source="cve">The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96430372326912&amp;w=2">20000722 More bad censorware</ref></refs><vuln_soft><prod name="Personal Privacy" vendor="PGP"><vers num="6.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0803" published="2000-12-19" seq="2000-0803" severity="High" type="CVE"><desc><descript source="cve">GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5280">gnu-groff-utilities(5280)</ref></refs><vuln_soft><prod name="groff" vendor="Gnu"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0804" published="2000-11-14" seq="2000-0804" severity="High" type="CVE"><desc><descript source="cve">Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka &quot;One-way Connection Enforcement Bypass.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Checkpoint" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html">One-way_Connection</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-way_Connection">http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-way_Connection</ref><ref source="XF" url="http://xforce.iss.net/static/5468.php">fw1-remote-bypass</ref><ref source="OSVDB" url="http://www.osvdb.org/4419">4419</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0805" published="2000-11-14" seq="2000-0805" severity="High" type="CVE"><desc><descript source="cve">Check Point VPN-1/FireWall-1 4.1 and earlier improperly retransmits encapsulated FWS packets, even if they do not come from a valid FWZ client, aka &quot;Retransmission of Encapsulated Packets.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Checkpoint" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html">Retransmission of Encapsulated Packets</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Retransmission_of">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Retransmission_of</ref><ref source="XF" url="http://xforce.iss.net/static/5469.php">fw1-client-spoof</ref><ref source="OSVDB" url="http://www.osvdb.org/4415">4415</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0806" published="2000-11-14" seq="2000-0806" severity="Medium" type="CVE"><desc><descript source="cve">The inter-module authentication mechanism (fwa1) in Check Point VPN-1/FireWall-1 4.1 and earlier may allow remote attackers to conduct a denial of service, aka &quot;Inter-module Communications Bypass.&quot;</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Checkpoint" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html">Inter-module Communications Bypass</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Inter-module_Communications">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Inter-module_Communications</ref><ref source="XF" url="http://xforce.iss.net/static/5162.php">fw1-fwa1-auth-replay</ref><ref source="OSVDB" url="http://www.osvdb.org/4413">4413</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0807" published="2000-11-14" seq="2000-0807" severity="High" type="CVE"><desc><descript source="cve">The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the &quot;OPSEC Authentication Vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Checkpoint" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html">OPSEC_Authentication</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#OPSEC_Authentication">http://www.checkpoint.com/techsupport/alerts/list_vun.html#OPSEC_Authentication</ref><ref source="XF" url="http://xforce.iss.net/static/5471.php">fw1-opsec-auth-spoof</ref><ref source="OSVDB" url="http://www.osvdb.org/4420">4420</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0808" published="2000-11-14" seq="2000-0808" severity="High" type="CVE"><desc><descript source="cve">The seed generation mechanism in the inter-module S/Key authentication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass authentication via a brute force attack, aka &quot;One-time (s/key) Password Authentication.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Checkpoint" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html">One-time (s/key) Password Authentication</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-time_Password">http://www.checkpoint.com/techsupport/alerts/list_vun.html#One-time_Password</ref><ref source="XF" url="http://xforce.iss.net/static/5137.php">fw1-localhost-auth</ref><ref source="OSVDB" url="http://www.osvdb.org/4421">4421</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0809" published="2000-11-14" seq="2000-0809" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Getkey in the protocol checker in the inter-module communication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Checkpoint" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html">Getkey_Buffer</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#Getkey_Buffer">http://www.checkpoint.com/techsupport/alerts/list_vun.html#Getkey_Buffer</ref><ref source="XF" url="http://xforce.iss.net/static/5139.php">fw1-getkey-bo</ref><ref source="OSVDB" url="http://www.osvdb.org/4422">4422</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0810" published="2000-12-19" seq="2000-0810" severity="High" type="CVE"><desc><descript source="cve">Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1782">1782</ref><ref source="BID" url="http://www.securityfocus.com/bid/1782">1782</ref><ref source="XF" url="http://xforce.iss.net/static/5371.php">auction-weaver-delete-files</ref><ref source="OSVDB" url="http://www.osvdb.org/1600">1600</ref></refs><vuln_soft><prod name="Auction Weaver" vendor="CGI Script Center"><vers num="1.0"/><vers num="1.04"/><vers num="1.03"/><vers num="1.02"/><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0811" published="2000-12-19" seq="2000-0811" severity="Medium" type="CVE"><desc><descript source="cve">Auction Weaver 1.0 through 1.04 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the username or bidfile form fields.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1783">1783</ref><ref source="BID" url="http://www.securityfocus.com/bid/1783">1783</ref><ref source="XF" url="http://xforce.iss.net/static/5372.php">auction-weaver-username-bidfile</ref><ref source="OSVDB" url="http://www.osvdb.org/4053">4053</ref></refs><vuln_soft><prod name="Auction Weaver" vendor="CGI Script Center"><vers num="1.0"/><vers num="1.04"/><vers num="1.03"/><vers num="1.02"/><vers num="1.01"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0812" published="2000-11-14" seq="2000-0812" severity="High" type="CVE"><desc><descript source="cve">The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/templates/advisory.html?id=2542"></ref><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/197&amp;type=0&amp;nav=sec.sba">SUN:00197</ref><ref source="BID" url="http://www.securityfocus.com/bid/1600">1600</ref><ref source="XF" url="http://xforce.iss.net/static/5135.php">sunjava-webadmin-bbs</ref></refs><vuln_soft><prod name="Java Web Server" vendor="Sun"><vers num="1.1 Beta"/><vers num="1.1.2"/><vers num="1.1.3"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-0813" published="2000-11-14" seq="2000-0813" severity="Medium" type="CVE"><desc><descript source="cve">Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to redirect FTP connections to other servers (&quot;FTP Bounce&quot;) via invalid FTP commands that are processed improperly by FireWall-1, aka &quot;FTP Connection Enforcement Bypass.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Checkpoint" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html">FTP_Connection</ref><ref source="CONFIRM" url="http://www.checkpoint.com/techsupport/alerts/list_vun.html#FTP_Connection">http://www.checkpoint.com/techsupport/alerts/list_vun.html#FTP_Connection</ref><ref source="XF" url="http://xforce.iss.net/static/5474.php">fw1-ftp-redirect</ref><ref source="OSVDB" url="http://www.osvdb.org/4434">4434</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0816" published="2000-10-06" seq="2000-0816" severity="Low" type="CVE"><desc><descript source="cve">Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain shell metacharacters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise64.php">ISS:20001006 Insecure call of external programs in Red Hat Linux tmpwatch</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1785">BID 1785</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-080.html">RHSA-2000:080</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-056.php3?dis=7.1">MDKSA-2000:056</ref><ref source="BID" url="http://www.securityfocus.com/bid/1785">1785</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5320">linux-tmpwatch-fuser(5320)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0817" published="2000-12-19" seq="2000-0817" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the &quot;Netmon Protocol Parsing&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/index.php"></ref><ref adv="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-083.asp"></ref></refs><vuln_soft><prod name="Netmon" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0818" published="2000-12-19" seq="2000-0818" severity="High" type="CVE"><desc><descript source="cve">The default installation for the Oracle listener program 7.3.4, 8.0.6, and 8.1.6 allows an attacker to cause logging information to be appended to arbitrary files and execute commands via the SET TRC_FILE or SET LOG_FILE commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise66.php"></ref><ref adv="1" patch="1" source="Oracle" url="http://otn.oracle.com/deploy/security/pdf/listener_alert.pdf"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5380">oracle-listener-connect-statements(5380)</ref></refs><vuln_soft><prod name="listener" vendor="Oracle"><vers num="7.3.4"/><vers num="8.0.6"/><vers num="8.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0824" published="2000-11-14" seq="2000-0824" severity="High" type="CVE"><desc><descript source="cve">The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/79537">BUGTRAQ:20000831 glibc unsetenv bug</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/648">BID 648</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=93760201002154&amp;w=2">19990917 A few bugs...</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-028.0.txt">CSSA-2000-028.0</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20000902">20000902 glibc: local root exploit</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-040.php3">MDKSA-2000:040</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-045.php3">MDKSA-2000:045</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-057.html">RHSA-2000:057</ref><ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000020.html">TLSA2000020-1</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html">20000924 glibc locale security problem</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html">20000902 Conectiva Linux Security Announcement - glibc</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0509.html">20000905 Conectiva Linux Security Announcement - glibc</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0525.html">20000906 [slackware-security]: glibc 2.1.3 vulnerabilities patched</ref><ref source="BID" url="http://www.securityfocus.com/bid/648">648</ref><ref source="BID" url="http://www.securityfocus.com/bid/1639">1639</ref><ref source="XF" url="http://xforce.iss.net/static/5173.php">glibc-ld-unsetenv</ref></refs><vuln_soft><prod name="glibc" vendor="Gnu"><vers num="2.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0825" published="2000-11-14" seq="2000-0825" severity="Medium" type="CVE"><desc><descript source="cve">Ipswitch Imail 6.0 allows remote attackers to cause a denial of service via a large number of connections in which a long Host: header is sent, which causes a thread to crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0071.html">WIN2KSEC:20000817 Imail Web Service Remote DoS Attack v.2</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96659012127444&amp;w=2">20000817 Imail Web Service Remote DoS Attack v.2</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=96654521004571&amp;w=2">20000817 Imail Web Service Remote DoS Attack v.2</ref><ref source="XF" url="http://xforce.iss.net/static/5475.php">ipswitch-imail-remote-dos(5475)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2011">2011</ref></refs><vuln_soft><prod name="IMail" vendor="Ipswitch"><vers num="6.00"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0826" published="2000-11-14" seq="2000-0826" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ddicgi.exe program in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5210.php">XF:documentdirect-get-bo</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1657">BID 1657</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090800-1.txt">A090800-1</ref></refs><vuln_soft><prod name="DocumentDirect for the Internet" vendor="Mobius"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0827" published="2000-11-14" seq="2000-0827" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the web authorization form of Mobius DocumentDirect for the Internet 1.2 allows remote attackers to cause a denial of service or execute arbitrary commands via a long username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1657">BID 1657</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5211.php">XF:documentdirect-username-bo</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090800-1.txt">A090800-1</ref></refs><vuln_soft><prod name="DocumentDirect for the Internet" vendor="Mobius"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0828" published="2000-11-14" seq="2000-0828" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5212.php">XF:documentdirect-user-agent-bo</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1657">BID 1657</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a090800-1.txt">A090800-1</ref></refs><vuln_soft><prod name="DocumentDirect for the Internet" vendor="Mobius"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0829" published="2000-11-14" seq="2000-0829" severity="Low" type="CVE"><desc><descript source="cve">The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a denial of service by creating deeply nested directories in /tmp or /var/tmp/.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1664">BID 1664</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5217.php">XF:linux-tmpwatch-fork-dos</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/81364">20000909 tmpwatch: local DoS : fork()bomb as root</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-080.html">RHSA-2000:080</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.1"/><vers num="6.2 tmpwatch 2.2"/><vers num="6.0 tmpwatch 2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0830" published="2000-11-14" seq="2000-0830" severity="Medium" type="CVE"><desc><descript source="cve">annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP packet to ports 22701 through 22705.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5216.php">XF:webtv-udp-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1671">BID 1671</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/81852">20000913 trivial DoS in webTV</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-074.asp">MS00-074</ref></refs><vuln_soft><prod name="WebTV" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0831" published="2000-11-14" seq="2000-0831" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0109.html">WIN2KSEC:20000912 DST2K0027: DoS in Faststream FTP++ 2.0</ref></refs><vuln_soft><prod name="FTP++ Server" vendor="Fastream"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0832" published="2000-11-14" seq="2000-0832" severity="Medium" type="CVE"><desc><descript source="cve">Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0208.html">20000817 Htgrep CGI Arbitrary File Viewing Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/5476.php">htgrep-cgi-view-files(5476)</ref></refs><vuln_soft><prod name="Htgrep" vendor="Oscar Nierstrasz"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0833" published="2000-11-14" seq="2000-0833" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5255.php">XF:winsmtp-helo-bo</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1680">BID:1680</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/81693">2000911 WinSMTPD remote exploit/DoS problem</ref></refs><vuln_soft><prod name="WinSMTP" vendor="Jack De Winter"><vers num="1.6f"/><vers num="2.x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0834" published="2000-11-14" seq="2000-0834" severity="High" type="CVE"><desc><descript source="cve">The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the &quot;Windows 2000 Telnet Client NTLM Authentication&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1683">BID 1683</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-067.asp">MS:MS00-067</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a091400-1.txt">A091400-1</ref><ref source="XF" url="http://xforce.iss.net/static/5242.php">win2k-telnet-ntlm-authentication</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2000-0835" published="2000-11-14" seq="2000-0835" severity="Medium" type="CVE"><desc><descript source="cve">search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query paraeater.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1684">BID 1684</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0175.html">20000915 Sambar Server search CGI vulnerability</ref></refs><vuln_soft><prod name="Sambar Server" vendor="Sambar"><vers num="4.4 Beta3"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0836" published="2000-11-14" seq="2000-0836" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1685">BID 1685</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0176.html">BUGTRAQ:20000915 [NEWS] Vulnerability in CamShot server (Authorization)</ref><ref source="XF" url="http://xforce.iss.net/static/5246.php">camshot-password-bo</ref></refs><vuln_soft><prod name="CamShot WebCam" vendor="BroadGun Software"><vers num="2.6Trial Version"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0837" published="2000-11-14" seq="2000-0837" severity="Medium" type="CVE"><desc><descript source="cve">FTP Serv-U 2.5e allows remote attackers to cause a denial of service by sending a large number of null bytes.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/73843">BUGTRAQ:20000804 FTP Serv-U 2.5e vulnerability.</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5029.php">XF:servu-null-character-dos</ref><ref source="BID" url="http://www.securityfocus.com/bid/1543">1543</ref></refs><vuln_soft><prod name="FTP Serv-U" vendor="Deerfield"><vers num="2.5e"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0838" published="2000-11-14" seq="2000-0838" severity="Medium" type="CVE"><desc><descript source="cve">Fastream FUR HTTP server 1.0b allows remote attackers to cause a denial of service via a long GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5237.php">XF:fur-get-dos</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0111.html">WIN2KSEC:DST2K0028: DoS in FUR HTTP Server v1.0b</ref></refs><vuln_soft><prod name="FUR HTTP Server" vendor="Fastream"><vers num="1.0b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0839" published="2000-11-14" seq="2000-0839" severity="Medium" type="CVE"><desc><descript source="cve">WinCOM LPD 1.00.90 allows remote attackers to cause a denial of service via a large number of LPD options to the LPD port (515).</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5258.php">XF:wincom-lpd-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1701">BID 1701</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0212.html">20000919 VIGILANTE-2000013: WinCOM LPD DoS</ref></refs><vuln_soft><prod name="WinCOM LPD" vendor="Ipswitch"><vers num="1.00.90"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0840" published="2000-11-14" seq="2000-0840" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long USER command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1652">BID 1652</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0001.html">BUGTRAQ:20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER)</ref><ref source="XF" url="http://xforce.iss.net/static/5192.php">xmail-long-user-bo</ref></refs><vuln_soft><prod name="Xmail" vendor="Davide Libenzi"><vers num="0.58"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0841" published="2000-11-14" seq="2000-0841" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long APOP command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1652b">BID 1652</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0001.html">BUGTRAQ:20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5191.php">XF:xmail-long-apop-bo</ref><ref source="BID" url="http://www.securityfocus.com/bid/1652">1652</ref></refs><vuln_soft><prod name="Xmail" vendor="Davide Libenzi"><vers num="0.58"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0842" published="2000-11-14" seq="2000-0842" severity="Medium" type="CVE"><desc><descript source="cve">The search97cgi/vtopic&quot; in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1663">BID 1663</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0086.html">BUGTRAQ:20000911 SCO scohelhttp documentation webserver exposes local files</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0843" published="2000-11-14" seq="2000-0843" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1666">BID 1666</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20000911">DEBIAN:20000911 libpam-smb: remote root exploit</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0073.html">20000910 (SRADV00002) Remote root compromise through pam_smb and pam_ntdom</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv8_draht_pam_smb_txt.html">20000913 pam_smb remotely exploitable buffer overflow</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-047.php3">MDKSA-2000:047</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0114.html">20000911 Conectiva Linux Security Announcement - pam_smb</ref></refs><vuln_soft><prod name="pam_ntdom" vendor="Samba"><vers num="0.23"/></prod><prod name="pam_smb" vendor="Samba"><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2000-0844" published="2000-11-14" seq="2000-0844" severity="High" type="CVE"><desc><descript source="cve">Some functions that implement the locale subsystem on Unix do not  properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1634">BID 1634</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0457.html">BUGTRAQ:20000904 UNIX locale format string vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20000902">20000902 glibc: local root exploit</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-030.0.txt">CSSA-2000-030.0</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-057.html">RHSA-2000:057</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv5_draht_glibc_txt.html">20000906 glibc locale security problem</ref><ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000020.html">TLSA2000020-1</ref><ref source="AIXAPAR" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0427.html">IY13753</ref><ref source="COMPAQ" url="http://archives.neohapsis.com/archives/tru64/2000-q4/0000.html">SSRT0689U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20000901-01-P">20000901-01-P</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0436.html">20000902 Conectiva Linux Security Announcement - glibc</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5176">unix-locale-format-string(5176)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.8"/><vers num="6.5.7"/><vers num="6.5.6"/><vers num="6.5.4"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.2m"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/></prod><prod name="OpenLinux eBuilder" vendor="Caldera"><vers num="3.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.0"/></prod><prod name="Trustix Linux" vendor="Trustix"><vers num="1.1"/><vers num="1.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="7.1"/><vers num="7.0"/></prod><prod name="OpenLinux Eserver" vendor="Caldera"><vers num="2.3"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="Immunix" vendor="Immunix"><vers num="6.2"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num="6.0.4"/><vers num="6.0.3"/><vers num="6.0.2"/><vers num="6.0.1"/><vers num="6.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0es"/><vers num="4.0"/></prod><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers num="7.0"/><vers num="2.6"/><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/></prod><prod name="Linux" vendor="Red Hat"><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0845" published="2000-11-14" seq="2000-0845" severity="Medium" type="CVE"><desc><descript source="cve">kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0204.html">BUGTRAQ:20000918 [ENIGMA] Digital UNIX/Tru64 UNIX remote kdebug Vulnerability</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num="4.0F"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0846" published="2000-11-14" seq="2000-0846" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1598">BID 1598</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0256.html">BUGTRAQ:20000821 Darxite daemon remote exploit/DoS problem</ref><ref source="XF" url="http://xforce.iss.net/static/5134.php">darxite-login-bo</ref></refs><vuln_soft><prod name="Darxite" vendor="Ashley Montanaro"><vers num="0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0847" published="2000-11-14" seq="2000-0847" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1646">BID 1646</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0437.html">BUGTRAQ:20000901 More about UW c-client library</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0425.html">20000901 UW c-client library vulnerability</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0108.html">FreeBSD-SA-00:47.pine</ref><ref source="BID" url="http://www.securityfocus.com/bid/1687">1687</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5223">c-client-dos(5223)</ref></refs><vuln_soft><prod name="IMAP" vendor="University of Washington"><vers num="4.7c"/><vers num="4.7b"/></prod><prod name="Pine" vendor="University of Washington"><vers num="4.21"/><vers num="4.20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-21" name="CVE-2000-0848" published="2000-11-14" seq="2000-0848" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host:  request header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1691">BID 1691</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0192.html">BUGTRAQ:20000915 WebSphere application server plugin issue &amp; vendor fix</ref><ref source="MISC" url="http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security">http://www-4.ibm.com/software/webservers/appserv/doc/v3022/fxpklst.htm#Security</ref><ref source="XF" url="http://xforce.iss.net/static/5252.php">websphere-header-dos</ref></refs><vuln_soft><prod name="Websphere Application Server" vendor="IBM"><vers num="3.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0849" published="2000-11-14" seq="2000-0849" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the &quot;Unicast Service Race Condition&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1655">BID 1655</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-064.asp">MS:MS00-064</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5193">unicast-service-dos(5193)</ref></refs><vuln_soft><prod name="Windows Media Services" vendor="Microsoft"><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0850" published="2000-11-14" seq="2000-0850" severity="High" type="CVE"><desc><descript source="cve">Netegrity SiteMinder before 4.11 allows remote attackers to bypass its authentication mechanism by appending &quot;$/FILENAME.ext&quot; (where ext is .ccc, .class, or .jpg) to the requested URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5230.php"> XF:siteminder-bypass-authentication</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1681">BID:1681</ref><ref adv="1" source="@stake" url="http://www.atstake.com/research/advisories/2000/a091100-1.txt">ATSTAKE:A091100-1</ref></refs><vuln_soft><prod name="SiteMinder" vendor="Netegrity"><vers num="4.0"/><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0851" published="2000-11-14" seq="2000-0851" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the &quot;Still Image Service Privilege Escalation&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1651">BID 1651</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-065.asp">MS:MS00-065</ref><ref source="@stake" url="http://www.atstake.com/research/advisories/2000/a090700-1.txt">ATSTAKE:A090700-1</ref><ref source="XF" url="http://xforce.iss.net/static/5203.php">w2k-still-image-service</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0852" published="2000-11-14" seq="2000-0852" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1686">BID 1686</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5248.php">XF:freebsd-eject-port</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0110.html">FreeBSD-SA-00:49</ref><ref source="OSVDB" url="http://www.osvdb.org/1559">1559</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0 alpha"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2000-0853" published="2000-11-14" seq="2000-0853" severity="Medium" type="CVE"><desc><descript source="cve">YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1668">BID 1668</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0072.html">BUGTRAQ:20000909 YaBB 1.9.2000 Vulnerabilitie</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5254.php">XF:yabb-file-access</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers num="2000-09-01"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0854" published="2000-11-14" seq="2000-0854" severity="High" type="CVE"><desc><descript source="cve">When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL&apos;s such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0117.html">WIN2KSEC:20000918 Double clicking on MS Office documents from Windows Explorer may execute arbitrary programs in some cases</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1699">BID 1699</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0277.html">20000922 Eudora + riched20.dll affects WinZip v8.0 as well</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0155.html">20000921 Mitigators for possible exploit of Eudora via Guninski #21,2000</ref><ref source="XF" url="http://xforce.iss.net/static/5263.php">office-dll-execution(5263)</ref></refs><vuln_soft><prod name="Office" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0855" published="2000-11-14" seq="2000-0855" severity="Medium" type="CVE"><desc><descript source="cve">SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1637">BID 1637</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0408.html">BUGTRAQ:20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open)</ref></refs><vuln_soft><prod name="XS4ALL Data SunFTP" vendor="XS4ALL Data"><vers num="1.0 Build 9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0856" published="2000-11-14" seq="2000-0856" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SunFTP build 9(1) allows remote attackers to cause a denial of service or possibly execute arbitrary commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1638">BID 1638</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0408.html">BUGTRAQ:20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open)</ref></refs><vuln_soft><prod name="XS4ALL Data SunFTP" vendor="XS4ALL Data"><vers num="1.0 Build 9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0857" published="2000-11-14" seq="2000-0857" severity="High" type="CVE"><desc><descript source="cve">The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0068.html">BUGTRAQ:20000909 Re: format string bug in muh</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0067.html">BUGTRAQ:20000909 format string bug in muh</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1665">BID 1665</ref><ref source="XF" url="http://xforce.iss.net/static/5215.php">muh-log-dos</ref></refs><vuln_soft><prod name="muh" vendor="Sebastian Kienzl"><vers num="2.05d"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0858" published="2000-11-14" seq="2000-0858" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Microsoft Windows NT 4.0 allows remote attackers to cause a denial of service in IIS by sending it a series of malformed requests which cause INETINFO.EXE to fail, aka the &quot;Invalid URL&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1642">BID 1642</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vendor/2000-q3/0065.html">MS:MS00-063</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/80413">BUGTRAQ:20000906 VIGILANTE-2000009: &quot;Invalid URL&quot; DoS</ref><ref source="XF" url="http://xforce.iss.net/static/5202.php">iis-invald-url-dos</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0859" published="2000-11-14" seq="2000-0859" severity="Medium" type="CVE"><desc><descript source="cve">The web configuration server for NTMail V5 and V6 allows remote attackers to cause a denial of service via a series of partial HTTP requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1640">BID 1640</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0471.html">BUGTRAQ:20000904 VIGILANTE-2000008: NTMail Configuration Service DoS</ref><ref source="XF" url="http://xforce.iss.net/static/5182.php">ntmail-incomplete-http-requests</ref></refs><vuln_soft><prod name="NTMail" vendor="Gordano"><vers num="6.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0860" published="2000-11-14" seq="2000-0860" severity="Medium" type="CVE"><desc><descript source="cve">The file upload capability in PHP versions 3 and 4 allows remote attackers to read arbitrary files by setting hidden form fields whose names match the names of internal PHP script variables.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0455.html">BUGTRAQ:20000903 (SRADV00001) Arbitrary file disclosure through PHP file upload</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1649">BID 1649</ref><ref source="" url="http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&amp;tr1=1.1&amp;r2=text&amp;tr2=1.45&amp;diff_format=u"></ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0477.html">20000904 Re: [PHP-DEV] RE: (SRADV00001) Arbitrary file disclosure through PHP file upload</ref><ref source="MANDRAKE" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0150.html">MDKSA-2000:048</ref><ref source="XF" url="http://xforce.iss.net/static/5190.php">php-file-upload</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="3.0.9"/><vers num="3.0.8"/><vers num="3.0.7"/><vers num="3.0.6"/><vers num="3.0.5"/><vers num="3.0.4"/><vers num="3.0.3"/><vers num="3.0.2"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.1"/><vers num="3.0"/></prod><prod name="PHP_FI" vendor="PHP"><vers num="2.0b10"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0861" published="2000-11-14" seq="2000-0861" severity="High" type="CVE"><desc><descript source="cve">Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0112.html">FREEBSD:FreeBSD-SA-00:51</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0040.html">BUGTRAQ:20000907 Mailman 1.1 + external archiver vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1667">BID 1667</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5493">mailman-execute-external-commands(5493)</ref></refs><vuln_soft><prod name="Mailman" vendor="Gnu"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0862" published="2000-11-14" seq="2000-0862" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in an administrative interface utility for Allaire Spectra 1.0.1 allows remote attackers to read and modify sensitive configuration information.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vendor/2000-q3/0059.html">ALLAIRE:ASB00-23</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=17372&amp;Method=Full">ALLAIRE:ASB00-23</ref><ref source="XF" url="http://xforce.iss.net/static/5466.php">allaire-spectra-admin-access</ref></refs><vuln_soft><prod name="Spectra" vendor="Allaire"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0863" published="2000-11-14" seq="2000-0863" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in listmanager earlier than 2.105.1 allows local users to gain additional privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-09/0111.html">FREEBSD:FreeBSD-SA-00:50</ref><ref source="XF" url="http://xforce.iss.net/static/5503.php">listmanager-port-bo</ref></refs><vuln_soft><prod name="Linux" vendor="Listmanager"><vers num="2.105.1"/><vers num="2.104"/><vers num="2.103"/><vers num="2.102"/><vers num="2.101"/><vers num="2.100"/><vers num="2.99"/><vers num="2.98"/><vers num="2.97"/><vers num="2.96" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0864" published="2000-11-14" seq="2000-0864" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a  symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2000-08/0365.html">FREEBSD:FreeBSD-SA-00:45</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1659">BID 1659</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0095.html">20000911 Patch for esound-0.2.19</ref><ref source="MANDRAKE" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0328.htm">MDKSA-2000:051</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-077.html">RHSA-2000:077</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001008">20001008 esound: race condition</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0118.html">20001006 Immunix OS Security Update for esound</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/esound_daemon_race_condition.html">20001012 esound daemon race condition</ref><ref source="XF" url="http://xforce.iss.net/static/5213.php">gnome-esound-symlink</ref></refs><vuln_soft><prod name="esound" vendor="GNOME"><vers num="0.2.19"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0865" published="2000-11-14" seq="2000-0865" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in dvtermtype in Tridia Double Vision 3.07.00 allows local users to gain root privileges via a long terminal type argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1697">BID 1697</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0185.html">BUGTRAQ:20000916 Advisory: Tridia DoubleVision / SCO UnixWare</ref><ref source="XF" url="http://xforce.iss.net/static/5261.php">doublevision-dvtermtype-bo</ref></refs><vuln_soft><prod name="DoubleVision" vendor="Tridia"><vers num="3.07.00"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-0866" published="2000-11-14" seq="2000-0866" severity="Low" type="CVE"><desc><descript source="cve">Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1654">BID 1654</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0027.html">20000907 SEGFAULTING Interbase 6 SS Linux</ref><ref source="XF" url="http://xforce.iss.net/static/5205.php">interbase-query-dos</ref></refs><vuln_soft><prod name="InterBase SuperServer" vendor="Borland Software"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0867" published="2000-11-14" seq="2000-0867" severity="High" type="CVE"><desc><descript source="cve">Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0193.html">BUGTRAQ:20000917 klogd format bug</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5259.php">XF:klogd-format-string</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/83641"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-061.html">RHSA-2000:061</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:050">MDKSA-2000:050</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-032.0.txt">CSSA-2000-032.0</ref><ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-September/000023.html">TLSA2000022-2</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv9_draht_syslogd_txt.html">20000920 syslogd + klogd format string parsing error</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97726239017741&amp;w=2">20000918 Conectiva Linux Security Announcement - sysklogd</ref><ref source="OSVDB" url="http://www.osvdb.org/5824">5824</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.2"/><vers num="6.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="6.0"/><vers num="6.1"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="Trustix Linux" vendor="Trustix"><vers num="1.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers edition="slink" num="2.1"/><vers edition="potato" num="2.2"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2000-0868" published="2000-11-14" seq="2000-0868" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1658">BID 1658</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html">SUSE:20000907</ref><ref adv="1" patch="1" source="@stake" url="http://www.atstake.com/research/advisories/2000/a090700-2.txt">ATSTAKE:A090700-2</ref><ref source="XF" url="http://xforce.iss.net/static/5197.php">suse-apache-cgi-source-code</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.12"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.4"/><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2000-0869" published="2000-11-14" seq="2000-0869" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary diretories via the PROPFIND HTTP request method.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1656">BID 1656</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/suse/2000-q3/0906.html">SUSE:20000907</ref><ref adv="1" source="@stake" url="http://www.atstake.com/research/advisories/2000/a090700-3.txt">ATSTAKE:A090700-3</ref><ref source="XF" url="http://xforce.iss.net/static/5204.php">apache-webdav-directory-listings</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.12"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers edition="ppc" num="6.4"/><vers num="6.4 alpha"/><vers num="6.4"/><vers edition="ppc" num="6.3"/><vers num="6.3 alpha"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1 alpha"/><vers num="6.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0870" published="2000-11-14" seq="2000-0870" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1675">BID 1675</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0089.html">BUGTRAQ:20000911[EXPL] EFTP vulnerable to two DoS attacks</ref><ref source="XF" url="http://xforce.iss.net/static/5219.php">eftp-bo</ref><ref source="OSVDB" url="http://www.osvdb.org/1555">1555</ref></refs><vuln_soft><prod name="EFTP" vendor="Khamil Landross and Zack Jones"><vers num="2.0.4.281"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0871" published="2000-11-14" seq="2000-0871" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1677">BID 1677</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0089.html">BUGTRAQ:20000911[EXPL] EFTP vulnerable to two DoS attacks</ref><ref source="XF" url="http://xforce.iss.net/static/5220.php">eftp-newline-dos</ref><ref source="OSVDB" url="http://www.osvdb.org/409">409</ref></refs><vuln_soft><prod name="EFTP" vendor="Khamil Landross and Zack Jones"><vers num="2.0.4.281"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0872" published="2000-11-14" seq="2000-0872" severity="Medium" type="CVE"><desc><descript source="cve">explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1650">BID 1650</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0015.html">BUGTRAQ:20000906 PhotoAlbum 0.9.9 explorer.php Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/5198.php">phpphoto-dir-traverse</ref></refs><vuln_soft><prod name="phpPhotoAlbum" vendor="Nathan Purciful"><vers num="0.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0873" published="2000-11-14" seq="2000-0873" severity="Low" type="CVE"><desc><descript source="cve">netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network interface statistics and possibly hide evidence of unusual network activities.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/1660">BID 1660</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0454.html">BUGTRAQ:20000903 aix allows clearing the interface stats</ref><ref source="XF" url="http://xforce.iss.net/static/5214.php">aix-clear-netstat</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0874" published="2000-11-14" seq="2000-0874" severity="Medium" type="CVE"><desc><descript source="cve">Eudora mail client includes the absolute path of the sender&apos;s host within a virtual card (VCF).</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1653">BID 1653</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/80888">BUGTRAQ:20000907 Eudora disclosure</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5206.php">XF:eudora-path-disclosure</ref><ref source="OSVDB" url="http://www.osvdb.org/1545">1545</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num="4.3"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0875" published="2000-11-14" seq="2000-0875" severity="Medium" type="CVE"><desc><descript source="cve">WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.html">BUGTRAQ:20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5194.php">XF:wftpd-long-string-dos</ref><ref source="CONFIRM" url="http://www.wftpd.com/bug_gpf.htm">http://www.wftpd.com/bug_gpf.htm</ref></refs><vuln_soft><prod name="WFTPD Pro" vendor="Texas Imperial Software"><vers num="2.41 RC12"/></prod><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="2.40"/><vers num="2.34"/><vers num="2.4.1 RC12"/><vers num="2.4.1 RC11"/><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0876" published="2000-11-14" seq="2000-0876" severity="Medium" type="CVE"><desc><descript source="cve">WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the  full pathname of the server via a &quot;%C&quot; command, which generates an error message that includes the pathname.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0488.html">BUGTRAQ:20000905 WFTPD/WFTPD Pro 2.41 RC12 vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5196.php">XF:wftpd-path-disclosure</ref><ref source="OSVDB" url="http://www.osvdb.org/5829">5829</ref></refs><vuln_soft><prod name="WFTPD Pro" vendor="Texas Imperial Software"><vers num="2.41 RC12"/></prod><prod name="WFTPD" vendor="Texas Imperial Software"><vers num="2.40"/><vers num="2.34"/><vers num="2.4.1 RC12"/><vers num="2.4.1 RC11"/><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0877" published="2000-11-14" seq="2000-0877" severity="Medium" type="CVE"><desc><descript source="cve">mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1670">BID 1670</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0092.html">BUGTRAQ:20000911 Unsafe passing of variables to mailform.pl in MailForm V2.0</ref><ref source="XF" url="http://xforce.iss.net/static/5224.php">mailform-attach-file</ref></refs><vuln_soft><prod name="MailForm" vendor="Ranson Johnson"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0878" published="2000-11-14" seq="2000-0878" severity="High" type="CVE"><desc><descript source="cve">The mailto CGI script allows remote attacker to execute arbitrary commands via shell metacharacters in the emailadd form field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1669">BID 1669</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0088.html">BUGTRAQ:20000911 Fwd: Poor variable checking in mailto.cgi</ref><ref source="XF" url="http://xforce.iss.net/static/5241.php">mailto-piped-address</ref></refs><vuln_soft><prod name="Mailto CGI script" vendor="Ranson Johnson"><vers num="1.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0879" published="2000-11-14" seq="2000-0879" severity="Low" type="CVE"><desc><descript source="cve">LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html">BUGTRAQ:20000906 Multiple Security Holes in LPPlus</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1643">BID 1643</ref><ref source="XF" url="http://xforce.iss.net/static/5199.php">lpplus-permissions-dos</ref></refs><vuln_soft><prod name="LPPlus" vendor="Plus Technologies"><vers num="3.3"/><vers num="3.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0880" published="2000-11-14" seq="2000-0880" severity="Low" type="CVE"><desc><descript source="cve">LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1643">BID 1643</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html">BUGTRAQ:20000906 Multiple Security Holes in LPPlus</ref><ref source="XF" url="http://xforce.iss.net/static/5200.php">lpplus-process-perms-dos</ref></refs><vuln_soft><prod name="LPPlus" vendor="Plus Technologies"><vers num="3.3"/><vers num="3.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0881" published="2000-11-14" seq="2000-0881" severity="Low" type="CVE"><desc><descript source="cve">The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1644">BID 1644</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html">BUGTRAQ:20000906 Multiple Security Holes in LPPlus</ref><ref source="XF" url="http://xforce.iss.net/static/5201.php">lpplus-dccscan-file-read</ref></refs><vuln_soft><prod name="LPPlus" vendor="Plus Technologies"><vers num="3.3"/><vers num="3.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-09" name="CVE-2000-0882" published="2000-11-14" seq="2000-0882" severity="Medium" type="CVE"><desc><descript source="cve">Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1647">BID 1647</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0533.html">BUGTRAQ:20000906 VIGILANTE-2000010: Intel Express Switch series 500 DoS #2</ref></refs><vuln_soft><prod name="Intel Express 550F" vendor="Intel"><vers num="Firmware 2.64"/><vers num="Firmware 2.63"/></prod><prod name="Intel Express 520T" vendor="Intel"><vers num="Firmware 2.64"/><vers num="Firmware 2.63"/></prod><prod name="Intel Express 510T" vendor="Intel"><vers num="Firmware 2.64"/><vers num="Firmware 2.63"/></prod><prod name="Intel Express 550T" vendor="Intel"><vers num="Firmware 2.64"/><vers num="Firmware 2.63"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0883" published="2000-11-14" seq="2000-0883" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ directory to be browseable, which allows remote attackers to list the contents of that directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1678">BID 1678</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5257.php">XF:linux-mod-perl</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0111.html">MANDRAKE:MDKSA-2000:046</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0884" published="2000-12-19" seq="2000-0884" severity="High" type="CVE"><desc><descript source="cve">IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the &quot;Web Server Folder Traversal&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/1806">bugtraq id 1806</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-078.asp">MS00-078</ref><ref source="BID" url="http://www.securityfocus.com/bid/1806">1806</ref><ref source="XF" url="http://xforce.iss.net/static/5377.php">iis-unicode-translation</ref><ref source="OSVDB" url="http://www.osvdb.org/436">436</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:44">oval:org.mitre.oval:def:44</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2000-0885" published="2000-12-19" seq="2000-0885" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the &quot;Netmon Protocol Parsing&quot; vulnerability.  NOTE: It is highly likely that this candidate will be split into multiple candidates.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-083.asp">MS:MS00-083</ref></refs><vuln_soft><prod name="Systems Management Server" vendor="Microsoft"><vers num="1.2"/><vers num="2.0"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="Terminal Server 4.0"/><vers num="Enterprise 4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server"/><vers num="Advanced Server"/><vers num="Datacenter Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0886" published="2000-12-19" seq="2000-0886" severity="High" type="CVE"><desc><descript source="cve">IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the &quot;Web Server File Request Parsing&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=1912">BID 1912</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-086.asp">MS:MS00-086</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?mid=143604&amp;list=1&amp;fromthread=0&amp;end=2000-11-11&amp;threads=0&amp;start=2000-11-05&amp;">BUGTRAQ:20001107 NSFOCUS SA2000-07 : Microsoft IIS 4.0/5.0 CGI File Name Inspection Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/1912">1912</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5470">iis-invalid-filename-passing(5470)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:191">oval:org.mitre.oval:def:191</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0887" published="2000-12-19" seq="2000-0887" severity="Medium" type="CVE"><desc><descript source="cve">named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the &quot;zxfr bug.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1923">BID 1923</ref><ref adv="1" patch="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000339">CONECTIVA:CLSA-2000:339</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/143843">20001107 BIND 8.2.2-P5 Possible DOS</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2000-20.html">CA-2000-20</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-107.html">RHSA-2000:107</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001112">20001112 bind: remote Denial of Service</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0217.html">20001115 Trustix Security Advisory - bind and openssh (and modutils)</ref><ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0657.html">SuSE-SA:2000:45</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:067">MDKSA-2000:067</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000338">CLSA-2000:338</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5540">bind-zxfr-dos(5540)</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.2.2 p5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0888" published="2000-12-19" seq="2000-0888" severity="Medium" type="CVE"><desc><descript source="cve">named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by sending an SRV record to the server, aka the &quot;srv bug.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-20.html">CERT:CA-2000-20</ref><ref adv="1" patch="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000339">CONECTIVA:CLSA-2000:339</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-107.html">RHSA-2000:107</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:067">MDKSA-2000:067</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000338">CLSA-2000:338</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001112">20001112 bind: remote Denial of Service</ref><ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0657.html">SuSE-SA:2000:45</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5814">bind-srv-dos(5814)</ref></refs></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0889" published="2001-02-12" seq="2000-0889" severity="Medium" type="CVE"><desc><descript source="cve">Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-19.html">CA-2000-19</ref><ref adv="1" source="Sun" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/198&amp;type=0&amp;nav=sec.sba">#00198</ref></refs></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0890" published="2001-02-16" seq="2000-0890" severity="Low" type="CVE"><desc><descript source="cve">periodic in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/626919">VU#626919</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6047">periodic-temp-file-symlink(6047)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2325">2325</ref><ref source="OSVDB" url="http://www.osvdb.org/1754">1754</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-0891" published="2001-07-21" seq="2000-0891" severity="High" type="CVE"><desc><descript source="cve">A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/5962">VU:5962</ref><ref adv="1" source="Notes.net" url="http://www.notes.net/R5FixList.nsf/Search!SearchView&amp;Query=CBAT45TU9S">SPR#CBAT45TU9S</ref><ref source="XF" url="http://xforce.iss.net/static/5045.php">lotus-notes-bypass-ecl(5045)</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="5.02" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-2000-0892" published="2001-07-21" seq="2000-0892" severity="Low" type="CVE"><desc><descript source="cve">Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/22404">VU:#22404</ref><ref source="XF" url="http://xforce.iss.net/static/6644.php">telnet-obtain-env-variable(6644)</ref></refs><vuln_soft><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod><prod name="U_Win" vendor="U_Win"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0893" published="2001-02-16" seq="2000-0893" severity="Medium" type="CVE"><desc><descript source="cve">The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/28027">VU#28027</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2000-0894" published="2001-02-12" seq="2000-0894" severity="High" type="CVE"><desc><descript source="cve">HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise70.php">ISS:20001214 Multiple vulnerabilities in the WatchGuard SOHO 
Firewall</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2119">Watchguard SOHO Firewall HTTP Request Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5554">watchguard-soho-web-auth(5554)</ref><ref source="OSVDB" url="http://www.osvdb.org/4404">4404</ref></refs><vuln_soft><prod name="SOHO Firewall" vendor="WatchGuard"><vers num="1.6"/><vers num="2.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-01-18" name="CVE-2000-0895" published="2001-02-12" seq="2000-0895" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise70.php">ISS:20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2114">bid 2114</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/5218">WatchGuard SOHO configuration server can be remotely crashed</ref><ref source="OSVDB" url="http://www.osvdb.org/4403">4403</ref></refs><vuln_soft><prod name="SOHO Firewall" vendor="WatchGuard"><vers num="2.1.3"/><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0896" published="2001-02-12" seq="2000-0896" severity="Medium" type="CVE"><desc><descript source="cve">WatchGuard SOHO firewall allows remote attackers to cause a denial of service via a flood of fragmented IP packets, which causes the firewall to drop connections and stop forwarding packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2113">bid 2113</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5749.php">watchguard-soho-fragmented-packets</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise70.php">ISS:20001214 Multiple vulnerabilities in the WatchGuard SOHO</ref><ref source="OSVDB" url="http://www.osvdb.org/1690">1690</ref></refs><vuln_soft><prod name="SOHO Firewall" vendor="WatchGuard"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0897" published="2001-01-09" seq="2000-0897" severity="Medium" type="CVE"><desc><descript source="cve">Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1941">BID 1941</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97421834001092&amp;w=2">BUGTRAQ:20001114 Vulnerabilites in SmallHTTP Server</ref><ref source="CONFIRM" url="http://home.lanck.net/mf/srv/index.htm">http://home.lanck.net/mf/srv/index.htm</ref><ref source="XF" url="http://xforce.iss.net/static/5524.php">small-http-nofile-dos(5524)</ref></refs><vuln_soft><prod name="Small HTTP server" vendor="Max Feoktistov"><vers num="2.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0898" published="2001-01-09" seq="2000-0898" severity="Medium" type="CVE"><desc><descript source="cve">Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97421834001092&amp;w=2">BUGTRAQ:20001114 Vulnerabilites in SmallHTTP Server</ref></refs><vuln_soft><prod name="Small HTTP server" vendor="Max Feoktistov"><vers num="2.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0899" published="2001-01-09" seq="2000-0899" severity="Medium" type="CVE"><desc><descript source="cve">Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1942">BID 1942</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97421834001092&amp;w=2">BUGTRAQ:20001114 Vulnerabilites in SmallHTTP Server</ref></refs><vuln_soft><prod name="Small HTTP server" vendor="Max Feoktistov"><vers num="2.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2000-0900" published="2000-12-19" seq="2000-0900" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a &quot;%2e%2e&quot; string, a variation of the .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1737">BID 1737</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5313.php">XF:acme-thttpd-ssi</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0025.html">BUGTRAQ:20001002 thttpd ssi: retrieval of arbitrary world-readable files</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:73.thttpd.asc">FreeBSD-SA-00:73</ref></refs><vuln_soft><prod name="thttpd" vendor="Acme Labs"><vers num="2.19"/><vers num="2.18"/><vers num="2.17"/><vers num="2.16"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0901" published="2000-12-19" seq="2000-0901" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters in the vbell_msg initialization variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5188.php">XF:screen-format-string</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1641">BID 1641</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-08/0530.html">20000906 Screen-3.7.6 local compromise</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/80178">20000905 screen 3.9.5 root vulnerability</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/MDKSA-2000-044.php3">MDKSA-2000:044</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv6_draht_screen_txt.html">20000906 screen format string parsing security problem</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-058.html">RHSA-2000:058</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:46.screen.asc">FreeBSD-SA-00:46</ref></refs><vuln_soft><prod name="Weigert screen" vendor="Juergen"><vers num="3.9.5"/><vers num="3.9.4"/><vers num="3.9.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0902" published="2000-12-19" seq="2000-0902" severity="Medium" type="CVE"><desc><descript source="cve">getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5209.php">XF:phpphotoalbum-getalbum-directory-traversal</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1650">BID 1650</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/80858">20000907 Re: PhotoAlbum 0.9.9 explorer.php Vulnerability</ref></refs><vuln_soft><prod name="phpPhotoAlbum" vendor="Nathan Purciful"><vers num="0.9.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-0903" published="2000-12-19" seq="2000-0903" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1648">BID 1648</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/79956">BUGTRAQ:20000901 Multiple QNX Voyager Issues</ref></refs><vuln_soft><prod name="Voyager" vendor="QNX"><vers num="2.01B"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-0904" published="2000-12-19" seq="2000-0904" severity="Medium" type="CVE"><desc><descript source="cve">Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1648">BID 1648</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/79956">BUGTRAQ:20000901 Multiple QNX Voyager Issues</ref></refs><vuln_soft><prod name="Voyager" vendor="QNX"><vers num="2.01B"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-0905" published="2000-12-19" seq="2000-0905" severity="Medium" type="CVE"><desc><descript source="cve">QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1648">BID 1648</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/79956">BUGTRAQ:20000901 Multiple QNX Voyager Issues</ref></refs><vuln_soft><prod name="Voyager" vendor="QNX"><vers num="2.01B"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0906" published="2000-12-19" seq="2000-0906" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1762">BID 1762</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5334.php">XF:moreover-cgi-dir-traverse</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0013.html">BUGTRAQ:20001002 Moreover Cached_Feed CGI Vulnerability</ref></refs><vuln_soft><prod name="cached_feed.cgi script" vendor="Moreover.com"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0907" published="2000-12-19" seq="2000-0907" severity="High" type="CVE"><desc><descript source="cve">EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0131.html">WIN2KSEC:20000925 DST2K0030: DoS in EServ 2.92 Build 2982</ref></refs><vuln_soft><prod name="Eserv" vendor="Etype"><vers num="2.92"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0908" published="2000-12-19" seq="2000-0908" severity="Medium" type="CVE"><desc><descript source="cve">BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Authorization or Referer MIME headers in the HTTP request.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1702">BID 1702</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5270.php">XF:browsegate-http-dos</ref><ref source="CONFIRM" url="http://www.netcplus.com/browsegate.htm#BGLatest">http://www.netcplus.com/browsegate.htm#BGLatest</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96956211605302&amp;w=2">20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H)</ref><ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0128.html">20000921 DST2K0031: DoS in BrowseGate(Home) v2.80(H)</ref></refs><vuln_soft><prod name="BrowseGate" vendor="NetcPlus"><vers num="2.80"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0909" published="2000-12-19" seq="2000-0909" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arbitrary commands via a long From: header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5283.php">XF:pine-check-mail-bo</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1709">BID 1709</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/84901">20000922  [ no subject ]</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0441.html">20001031 FW: Pine 4.30 now available</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:59.pine.asc">FreeBSD-SA-00:59</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-102.html">RHSA-2000:102</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-073.php3">MDKSA-2000:073</ref></refs><vuln_soft><prod name="Pine" vendor="University of Washington"><vers num="4.21"/><vers num="4.10"/><vers num="4.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0910" published="2000-12-19" seq="2000-0910" severity="Medium" type="CVE"><desc><descript source="cve">Horde library 1.02 allows attackers to execute arbitrary commands via shell metacharacters in the &quot;from&quot; address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5278.php">XF:horde-imp-sendmail-command</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1674">BID 1674</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20000910">DEBIAN:20000910 imp: remote compromise</ref><ref source="CONFIRM" url="http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch">http://ssl.coc-ag.de/sec/hordelib-1.2.0.frombug.patch</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0051.html">20000908 horde library bug - unchecked from-address</ref></refs><vuln_soft><prod name="Horde" vendor="Horde"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0911" published="2000-12-19" seq="2000-0911" severity="Medium" type="CVE"><desc><descript source="cve">IMP 2.2 and earlier allows attackers to read and delete arbitrary files by modifying the attachment_name hidden form variable, which causes IMP to send the file to the attacker as an attachment.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5227.php">XF:imp-attach-file</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1679">BID 1679</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/82088">BUGTRAQ:20000912  (SRADV00003) Arbitrary file disclosure through IMP</ref></refs><vuln_soft><prod name="IMP" vendor="Horde"><vers num="2.2"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0912" published="2000-12-19" seq="2000-0912" severity="Medium" type="CVE"><desc><descript source="cve">MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the &quot;multi&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5285.php">XF:http-cgi-multihtml</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0146.html">BUGTRAQ:20000913 MultiHTML vulnerability</ref></refs><vuln_soft><prod name="MultiHTML" vendor="JCS Web Works"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2000-0913" published="2000-12-19" seq="2000-0913" severity="Medium" type="CVE"><desc><descript source="cve">mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1728">BID 1728</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5310.php">XF:apache-rewrite-view-files</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0352.html">20000929 Security vulnerability in Apache mod_rewrite</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-060-2.php3?dis=7.1">MDKSA-2000:060</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-088.html">RHSA-2000:088</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-095.html">RHSA-2000:095</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-035.0.txt">CSSA-2000-035.0</ref><ref source="HP" url="http://archives.neohapsis.com/archives/hp/2000-q4/0021.html">HPSBUX0010-126</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0174.html">20001011 Conectiva Linux Security Announcement - apache</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.12"/><vers edition="Win32" num="1.3.11"/><vers num="1.1.1"/><vers num="1.1"/><vers num="1.0.5"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0"/><vers num="0.8.14"/><vers num="0.8.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0914" published="2000-12-19" seq="2000-0914" severity="Medium" type="CVE"><desc><descript source="cve">OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5340.php">XF:bsd-arp-request-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1759">BID 1759</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0078.html">BUGTRAQ:20001005 obsd_fun.c</ref><ref source="OSVDB" url="http://www.osvdb.org/1592">1592</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0915" published="2000-12-19" seq="2000-0915" severity="Medium" type="CVE"><desc><descript source="cve">fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5385.php">XF:freebsd-fingerd-files</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1803">BID 1803</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0017.html">20001002 [sa2c@and.or.jp: bin/21704: enabling fingerd makes files world readable]</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:54.fingerd.asc">FreeBSD-SA-00:54</ref><ref source="OSVDB" url="http://www.osvdb.org/433">433</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1.1 Release"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0916" published="2000-12-19" seq="2000-0916" severity="High" type="CVE"><desc><descript source="cve">FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1766">BID 1766</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:52.tcp-iss.asc">FREEBSD:FreeBSD-SA-00:52</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0917" published="2000-12-19" seq="2000-0917" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1712">BID 1712</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5287.php">XF:lprng-format-string</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0293.html">20000925 Format strings: bug #2: LPRng</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2000-22.html">CA-2000-22</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-033.0.txt">CSSA-2000-033.0</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-065.html">RHSA-2000:065</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:56.lprng.asc">FreeBSD-SA-00:56</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="OpenLinux eDesktop" vendor="Caldera"><vers num="2.4"/></prod><prod name="OpenLinux Eserver" vendor="Caldera"><vers num="2.3"/></prod><prod name="Trustix Linux" vendor="Trustix"><vers num="1.1"/><vers num="1.0"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod><prod name="OpenLinux eBuilder" vendor="Caldera"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0918" published="2000-12-19" seq="2000-0918" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/83914">BUGTRAQ:20000919 kvt format bug</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1700">BID 1700</ref></refs><vuln_soft><prod name="kvt" vendor="KDE"><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0919" published="2000-12-19" seq="2000-0919" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5331.php">XF:phpix-dir-traversal</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1773">BID 1773</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0117.html">20001007 PHPix advisory</ref><ref source="OSVDB" url="http://www.osvdb.org/472">472</ref></refs><vuln_soft><prod name="PHPix" vendor="PHPix"><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0920" published="2000-12-19" seq="2000-0920" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a &quot;%2E&quot; instead of a &quot;.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1770">BID 1770</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5330.php">XF:boa-webserver-get-dir-traversal</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0092.html">20001006 Vulnerability in BOA web server v0.94.8.2</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:60.boa.asc">FreeBSD-SA-00:60</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001009">20001009 boa: exposes contents of local files</ref></refs><vuln_soft><prod name="Boa Webserver" vendor="Boa"><vers num="0.94.8.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0921" published="2000-12-19" seq="2000-0921" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5342.php">XF:hassan-shopping-cart-dir-traversal</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1777">BID 1777</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0115.html">20001007 Security Advisory: Hassan Consulting&apos;s shop.cgi Directory Traversal Vulnerability.</ref><ref source="OSVDB" url="http://www.osvdb.org/1596">1596</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="Hassan Consulting"><vers num="1.18" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0922" published="2000-12-19" seq="2000-0922" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the newpage parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5351.php">XF:web-shopper-directory-traversal</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1776">BID 1776</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0120.html">20001008 Security Advisory: Bytes Interactive&apos;s Web Shopper (shopper.cgi) Directory Traversal Vulnerability</ref></refs><vuln_soft><prod name="Web Shopper" vendor="Bytes Interactive"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-01" name="CVE-2000-0923" published="2000-12-19" seq="2000-0923" severity="High" type="CVE"><desc><descript source="cve">authenticate.cgi CGI program in Aplio PRO allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1784">BID 1784</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5333.php">XF:uclinux-apliophone-bin-execute</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0107.html">BUGTRAQ:20001006 Fwd: APlio PRO web shell</ref></refs><vuln_soft><prod name="Aplio_Phone" vendor="Aplio"><vers num="2.0.33 build1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0924" published="2000-12-19" seq="2000-0924" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitrary files via a .. (dot dot) attack in the &quot;catigory&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1772">BID 1772</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0141.html">BUGTRAQ:20001009 Master Index traverse advisory</ref><ref source="XF" url="http://xforce.iss.net/static/5355.php">master-index-directory-traversal</ref><ref source="OSVDB" url="http://www.osvdb.org/461">461</ref></refs><vuln_soft><prod name="Master Index" vendor="Armada Design"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0925" published="2000-12-19" seq="2000-0925" severity="Medium" type="CVE"><desc><descript source="cve">The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with world readable permissions, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1734">BID 1734</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0001.html">WIN2KSEC:20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97050819812055&amp;w=2">20001002 DST2K0035: Credit card (customer) details exposed within CyberOff ice Shopping Cart v2</ref><ref source="XF" url="http://xforce.iss.net/static/5318.php">cyberoffice-world-readable-directory</ref></refs><vuln_soft><prod name="CyberOffice Shopping Cart" vendor="SmartWin Technology"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0926" published="2000-12-19" seq="2000-0926" severity="High" type="CVE"><desc><descript source="cve">SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the &quot;Price&quot; hidden form variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1733">BID 1733</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0000.html">WIN2KSEC:20001002 DST2K0036: Price modification possible in CyberOffice Shopping Cart</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97050627707128&amp;w=2">20001002 DST2K0036: Price modification possible in CyberOffice Shopping Cart</ref><ref source="XF" url="http://xforce.iss.net/static/5319.php">cyberoffice-price-modification</ref></refs><vuln_soft><prod name="CyberOffice Shopping Cart" vendor="SmartWin Technology"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0927" published="2000-12-19" seq="2000-0927" severity="Medium" type="CVE"><desc><descript source="cve">WQuinn QuotaAdvisor 4.1 does not properly record file sizes if they are stored in alternative data streams, which allows users to bypass quota restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1724">BID 1724</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5302.php">XF:quotaadvisor-quota-bypass</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0173.html">20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas.</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09//0331.html">20000928 DST2K0037: QuotaAdvisor 4.1 by WQuinn is susceptible to alternati ve datastreams to bypass quotas.</ref></refs><vuln_soft><prod name="QuotaAdvisor" vendor="Wquinn"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0928" published="2000-12-19" seq="2000-0928" severity="Low" type="CVE"><desc><descript source="cve">WQuinn QuotaAdvisor 4.1 allows users to list directories and files by running a report on the targeted shares.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1765">BID:1765</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0091.html">BUGTRAQ:20001006 DST2K0040: QuotaAdvisor 4.1 by WQuinn susceptible to any user bei ng able to list (not read) all files on any server running QuotaAdvisor.</ref><ref source="XF" url="http://xforce.iss.net/static/5327.php">quotaadvisor-list-files</ref></refs><vuln_soft><prod name="DiskAdvisor" vendor="Wquinn"><vers edition="Build 455" num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0929" published="2000-12-19" seq="2000-0929" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embedded OCX control that is not closed properly, aka the &quot;OCX Attachment&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5309.php">XF:mediaplayer-outlook-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1714">BID 1714</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-068.asp">MS:MS00-068</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97024839222747&amp;w=2">20000929 Malformed Embedded Windows Media Player 7 &quot;OCX Attachment&quot;</ref></refs><vuln_soft><prod name="Media Player" vendor="Microsoft"><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0930" published="2000-12-19" seq="2000-0930" severity="Medium" type="CVE"><desc><descript source="cve">Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol with a -F switch.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5326.php">XF:pegasus-file-forwarding</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1738">BID 1738</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0436.html">BUGTRAQ:20001030 Pegasus Mail file reading vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0039.html">20001003 Pegasus mail file reading vulnerability</ref></refs><vuln_soft><prod name="Pegasus Mail" vendor="David Harris"><vers num="3.12"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0931" published="2000-12-19" seq="2000-0931" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1750">BID 1750</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/137518">BUGTRAQ:20001004 Another Pegasus Mail vulnerability</ref></refs><vuln_soft><prod name="Pegasus Mail" vendor="David Harris"><vers num="3.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-12" name="CVE-2000-0932" published="2000-12-19" seq="2000-0932" severity="Medium" type="CVE"><desc><descript source="cve">MAILsweeper for SMTP 3.x does not properly handle corrupt CDA documents in a ZIP file and hangs, which allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Neohapsis" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0181.html">NTBUGTRAQ:20000926 FW: DOS for Content Technologies&apos; MAILsweeper for SMTP.</ref><ref source="XF" url="http://xforce.iss.net/static/5641.php">mailsweeper-smtp-dos</ref></refs><vuln_soft><prod name="MAILsweeper for SMTP" vendor="Clearswift"><vers num="3.x"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0933" published="2000-12-19" seq="2000-0933" severity="Medium" type="CVE"><desc><descript source="cve">The Input Method Editor (IME) in the Simplified Chinese version of Windows 2000 does not disable access to privileged functionality that should normally be restricted, which allows local users to gain privileges, aka the &quot;Simplified Chinese IME State Recognition&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5301.php">XF:win2k-simplified-chinese-ime</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1729">BID 1729</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-069.asp">MS:MS00-069</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0934" published="2000-12-19" seq="2000-0934" severity="High" type="CVE"><desc><descript source="cve">Glint in Red Hat Linux 5.2 allows local users to overwrite arbitrary files and cause a denial of service via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5271.php">XF:glint-symlink</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1703">BID 1703</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0250.html">REDHAT:RHSA-2000:062-03</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-062.html">RHSA-2000:062</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0935" published="2000-12-19" seq="2000-0935" severity="High" type="CVE"><desc><descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack on the cgi.log file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5443.php">XF:samba-swat-logging-sym-link</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1872">BID:1872</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html">BUGTRAQ:20001030 Samba 2.0.7 SWAT vulnerabilities</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0936" published="2000-12-19" seq="2000-0936" severity="Low" type="CVE"><desc><descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, which allows local users to read sensitive information such as user names and passwords.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5445.php">XF:samba-swat-logfile-info</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1874">BID:1874</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html">BUGTRAQ:20001030 Samba 2.0.7 SWAT vulnerabilities</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0937" published="2000-12-19" seq="2000-0937" severity="High" type="CVE"><desc><descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the password is wrong, which allows remote attackers to conduct brute force password guessing attacks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5442.php">XF:samba-swat-brute-force</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1873">BID 1873</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html">BUGTRAQ:20001030 Samba 2.0.7 SWAT vulnerabilities</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0938" published="2000-12-19" seq="2000-0938" severity="Medium" type="CVE"><desc><descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 supplies a different error message when a valid username is provided versus an invalid name, which allows remote attackers to identify valid users on the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html">BUGTRAQ:20001030 Samba 2.0.7 SWAT vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5442">samba-swat-brute-force(5442)</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0939" published="2000-12-19" seq="2000-0939" severity="Medium" type="CVE"><desc><descript source="cve">Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5444.php">XF:samba-swat-url-filename-dos</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html">BUGTRAQ:20001030 Samba 2.0.7 SWAT vulnerabilities</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0940" published="2000-12-19" seq="2000-0940" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the &quot;name&quot; or &quot;display&quot; parameter.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5451.php">XF:pagelog-cgi-dir-traverse</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1864">BID 1864</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0422.html">BUGTRAQ:20001029 Minor bug in Pagelog.cgi</ref></refs><vuln_soft><prod name="pagelog.cgi" vendor="Metertek"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0941" published="2000-12-19" seq="2000-0941" severity="High" type="CVE"><desc><descript source="cve">Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the &quot;whois&quot; parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1883">BID 1883</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5438.php">XF:kw-whois-meta</ref><ref adv="1" patch="1" source="Neoahapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0420.html">BUGTRAQ:20001029 Re: Remote command execution via KW Whois 1.0 (addition)</ref><ref source="MISC" url="http://www.kootenayweb.bc.ca/scripts/whois.txt">http://www.kootenayweb.bc.ca/scripts/whois.txt</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0419.html">20001029 Remote command execution via KW Whois 1.0</ref></refs><vuln_soft><prod name="Kootenay Web Inc whois" vendor="Kootenay Web Inc"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-0942" published="2000-12-19" seq="2000-0942" severity="Medium" type="CVE"><desc><descript source="cve">The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross site scripting (CSS) attack via a CiRestriction parameter in a .htw request, aka the &quot;Indexing Services Cross Site Scripting&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5441.php"> XF:iis-htw-cross-scripting</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1861">BID 1861</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-084.asp">MS:MS00-084</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141903">20001028 IIS 5.0 cross site scripting vulnerability - using .htw</ref></refs><vuln_soft><prod name="Indexing Service" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-2000-0943" published="2000-12-19" seq="2000-0943" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/static/5426.php">XF:bftpd-user-bo</ref><ref adv="1" patch="1" source="Neoahapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0397.html">BUGTRAQ:20001027 Potential Security Problem in bftpd-1.0.11</ref><ref source="BID" url="http://www.securityfocus.com/bid/1858">1858</ref></refs><vuln_soft><prod name="bftpd" vendor="Max-Wilhelm Bruker"><vers num="1.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0944" published="2000-12-19" seq="2000-0944" severity="High" type="CVE"><desc><descript source="cve">CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5433.php">XF:news-update-bypass-password</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1881">BID 1881</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0402.html">BUGTRAQ:20001027 CGI-Bug: News Update 1.1 administration password bug</ref></refs><vuln_soft><prod name="News Update" vendor="CGI Script Center"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0945" published="2000-12-19" seq="2000-0945" severity="High" type="CVE"><desc><descript source="cve">The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5415.php">XF:cisco-catalyst-remote-commands</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0380.html">BUGTRAQ:20001026 Advisory def-2000-02: Cisco Catalyst remote command execution</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1846">BID 1846</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0194.html">20001113 Re: 3500XL</ref><ref source="OSVDB" url="http://www.osvdb.org/444">444</ref></refs><vuln_soft><prod name="Catalyst 3500" vendor="Cisco"><vers num="XL"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0946" published="2000-12-19" seq="2000-0946" severity="Medium" type="CVE"><desc><descript source="cve">Compaq Easy Access Keyboard software 1.3 does not properly disable access to custom buttons when the screen is locked, which could allow an attacker to gain privileges or execute programs without authorization.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0023.html">NTBUGTRAQ:20001012 Security issue with Compaq Easy Access Keyboard software</ref><ref source="CONFIRM" url="http://www5.compaq.com/support/files/desktops/us/revision/1723.html">http://www5.compaq.com/support/files/desktops/us/revision/1723.html</ref><ref source="XF" url="http://xforce.iss.net/static/5718.php">compaq-ea-elevate-privileges</ref><ref source="OSVDB" url="http://www.osvdb.org/5831">5831</ref></refs><vuln_soft><prod name="Easy Access Keyboard software" vendor="Compaq"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0947" published="2000-12-19" seq="2000-0947" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1757">BID 1757</ref><ref adv="1" patch="1" source="Linux Mandrake" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-061.php3?dis=7.1">MANDRAKE:MDKSA-2000:061</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0004.html">20001002 Very probable remote root vulnerability in cfengine</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-013.txt.asc">NetBSD-SA2000-013</ref><ref source="XF" url="http://xforce.iss.net/static/5630.php">cfengine-cfd-format-string</ref></refs><vuln_soft><prod name="Cfengine" vendor="Gnu"><vers num="1.6a10"/><vers num="1.5.3_4"/><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0948" published="2000-12-19" seq="2000-0948" severity="High" type="CVE"><desc><descript source="cve">GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1761">BID 1761</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5317.php">XF:gnorpm-temp-symlink</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/136866">20001002 GnoRPM local /tmp vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0043.html">20001003 Conectiva Linux Security Announcement - gnorpm</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-055.php3?dis=7.0">MDKSA-2000:055</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-072.html">RHSA-2000:072</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0184.html">20001011 Immunix OS Security Update for gnorpm package</ref></refs><vuln_soft><prod name="GnoRPM" vendor="GNOME"><vers num="0.94" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-0949" published="2000-12-19" seq="2000-0949" severity="High" type="CVE"><desc><descript source="cve">Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1739">BID 1739</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5311.php">XF:traceroute-heap-overflow</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0344.html">20000928 Very interesting traceroute flaw</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-034.0.txt">CSSA-2000-034.0</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-053.php3?dis=7.1">MDKSA-2000:053</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-078.html">RHSA-2000:078</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001013">20001013 traceroute: local root exploit</ref><ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-October/000025.html">TLSA2000023-1</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0357.html">20000930 Conectiva Linux Security Announcement - traceroute</ref></refs><vuln_soft><prod name="LBL traceroute" vendor="LBL"><vers num="1.4a5"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0950" published="2000-12-19" seq="2000-0950" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5420.php">XF:tisfwtk-xgw-execute-code</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0376.html">BUGTRAQ:20001026 FWTK x-gw Security Advisory [GSA2000-01]</ref></refs><vuln_soft><prod name="Internet Firewall Toolkit" vendor="TIS"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0951" published="2000-12-19" seq="2000-0951" severity="Medium" type="CVE"><desc><descript source="cve">A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5335.php">XF:iis-index-dir-traverse</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1756">BID 1756</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a100400-1.txt">A100400-1</ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=272079">Q272079</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0952" published="2000-12-19" seq="2000-0952" severity="High" type="CVE"><desc><descript source="cve">global.cgi CGI program in Global 3.55 and earlier on NetBSD allows remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5424.php">XF:global-execute-remote-commands</ref><ref adv="1" patch="1" source="NetBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-014.txt.asc">NETBSD:NetBSD-SA2000-014</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1854">BID 1854</ref><ref source="OSVDB" url="http://www.osvdb.org/6486">6486</ref></refs><vuln_soft><prod name="Global" vendor="Shigio Yamaguchi"><vers num="3.55"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2000-0953" published="2000-12-19" seq="2000-0953" severity="Medium" type="CVE"><desc><descript source="cve">Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5345.php">XF:shambala-connection-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1778">BID 1778</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0134.html">BUGTRAQ:20001009 Shambala 4.5 vulnerability</ref></refs><vuln_soft><prod name="Shambala Server" vendor="Evolvable Corporation"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2000-0954" published="2000-12-19" seq="2000-0954" severity="High" type="CVE"><desc><descript source="cve">Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5346.php">XF:shambala-password-plaintext</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1771">BID 1771</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0134.html">BUGTRAQ:20001009 Shambala 4.5 vulnerability</ref></refs><vuln_soft><prod name="Shambala Server" vendor="Evolvable Corporation"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0955" published="2000-12-19" seq="2000-0955" severity="High" type="CVE"><desc><descript source="cve">Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5425.php"> XF:cisco-vco-snmp-passwords</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1885">BID 1885</ref><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2000/a102600-1.txt">ATSTAKE:A102600-1</ref></refs><vuln_soft><prod name="Virtual Central Office" vendor="Cisco"><vers num="4000 (VCO/4K) 5.1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-25" name="CVE-2000-0956" published="2000-12-19" seq="2000-0956" severity="Medium" type="CVE"><desc><descript source="cve">cyrus-sasl before 1.5.24 in Red Hat Linux 7.0 does not properly verify the authorization for a local user, which could allow the users to bypass specified access restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5427.php">XF:cyrus-sasl-gain-access</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1875">BID 1875</ref><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA-2000-094.html">REDHAT:RHSA-2000:094-01</ref></refs><vuln_soft><prod name="Cyrus-SASL" vendor="Carnegie Mellon University"><vers num="1.5.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2000-0957" published="2000-12-19" seq="2000-0957" severity="High" type="CVE"><desc><descript source="cve">The pluggable authentication module for mysql (pam_mysql) before 0.4.7 does not properly cleanse user input when constructing SQL statements, which allows attackers to obtain plaintext passwords or hashes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5447.php">XF:pammysql-auth-input</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0374.html">BUGTRAQ:20001026 (SRADV00004) Remote and local vulnerabilities in pam_mysql</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1850">BID 1850</ref></refs><vuln_soft><prod name="pam_mysql" vendor="pam_mysql"><vers num="0.4"/><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0958" published="2000-12-19" seq="2000-0958" severity="Medium" type="CVE"><desc><descript source="cve">HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5428.php">XF:hotjava-browser-dom-access</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0349.html">BUGTRAQ:20001025 HotJava Browser 3.0 JavaScript security vulnerability</ref></refs><vuln_soft><prod name="HotJava Browser" vendor="Sun"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0959" published="2000-12-19" seq="2000-0959" severity="Low" type="CVE"><desc><descript source="cve">glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5299.php">XF:glibc-unset-symlink</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1719">BID 1719</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/85028">20000926 ld.so bug - LD_DEBUG_OUTPUT follows symlinks</ref></refs><vuln_soft><prod name="glibc" vendor="GNU"><vers num="2.1.3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-2000-0960" published="2000-12-19" seq="2000-0960" severity="Medium" type="CVE"><desc><descript source="cve">The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5364.php">XF:netscape-messaging-email-verify</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1787">BID 1787</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97138100426121&amp;w=2">20001011 Netscape Messaging server 4.15 poor error strings</ref></refs><vuln_soft><prod name="Netscape Messaging Server" vendor="Netscape"><vers num="4.15p2"/><vers num="4.15p1"/><vers num="4.15"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-2000-0961" published="2000-12-19" seq="2000-0961" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5292.php">XF:netscape-messaging-list-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1721">BID 1721</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0334.html">20000928 commercial products and security [ + new bug ]</ref></refs><vuln_soft><prod name="Netscape Messaging Server" vendor="Netscape"><vers num="4.0"/></prod><prod name="Netscape Messaging Server + Multiplexor" vendor="Netscape"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0962" published="2000-12-19" seq="2000-0962" severity="Medium" type="CVE"><desc><descript source="cve">The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1723">BID 1723</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0299.html">BUGTRAQ:20000925 Nmap Protocol Scanning DoS against OpenBSD IPSEC</ref><ref source="XF" url="http://xforce.iss.net/static/5634.php">openbsd-nmap-dos</ref><ref source="OSVDB" url="http://www.osvdb.org/1574">1574</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2000-0963" published="2000-12-19" seq="2000-0963" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1142">BID 1142</ref><ref adv="1" patch="1" source="Caldera Systems" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-036.0.txt">CALDERA:CSSA-2000-036.0</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/138550">20001009 ncurses buffer overflows</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/44487">gnu-ncurses-term-terminfodirs-bo(44487)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1.1 Stable"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0"/><vers num="3.5.1"/><vers num="3.4"/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.0"/><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0964" published="2000-12-19" seq="2000-0964" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the web administration service for the HiNet LP5100 IP-phone allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5298.php">XF:hinet-ipphone-get-bo</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1727">BID 1727</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0336.html">20000928 Another thingy.</ref></refs><vuln_soft><prod name="Hinet LP" vendor="Siemens"><vers num="5100.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2000-0965" published="2000-12-19" seq="2000-0965" severity="Medium" type="CVE"><desc><descript source="cve">The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2000-q4/0012.html">HP:HPSBUX0010-124</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5361.php">XF:hp-virtualvault-nsapi-dos</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers edition="VVOS" num="10.24"/><vers edition="VVOS" num="11.04"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0966" published="2000-12-19" seq="2000-0966" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5379.php">XF:hp-lpspooler-bo</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2000-q4/0020.html">HP:HPSBUX0010-125</ref><ref source="OSVDB" url="http://www.osvdb.org/7244">7244</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.0"/><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0967" published="2000-12-19" seq="2000-0967" severity="High" type="CVE"><desc><descript source="cve">PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1786">BID 1786</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5359.php">XF:php-logging-format-string</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a101200-1.txt">A101200-1</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-062.php3?dis=7.1">MDKSA-2000:062</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-037.0.txt">CSSA-2000-037.0</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:75.php.asc">FreeBSD-SA-00:75</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-088.html">RHSA-2000:088</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-095.html">RHSA-2000:095</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0204.html">20001012 Conectiva Linux Security Announcement - mod_php3</ref></refs><vuln_soft><prod name="PHP" vendor="PHP"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0968" published="2000-12-19" seq="2000-0968" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1799">BID 1799</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5375.php">XF:halflife-server-changelevel-bo</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html">20001016 Half-Life Dedicated Server Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141060">20001024 Tamandua Sekure Labs Security Advisory 2000-01</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html">20001027 Re: Half Life dedicated server Patch</ref></refs><vuln_soft><prod name="Half-Life Dedicated Server" vendor="Valve Software"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0969" published="2000-12-19" seq="2000-0969" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5413.php">XF:halflife-rcon-format-string</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1847">BID 1847</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html">20001016 Half-Life Dedicated Server Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141060">20001024 Tamandua Sekure Labs Security Advisory 2000-01</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html">20001027 Re: Half Life dedicated server Patch</ref><ref source="OSVDB" url="http://www.osvdb.org/6983">6983</ref></refs><vuln_soft><prod name="Half-Life Dedicated Server" vendor="Valve Software"><vers num="3.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0970" published="2000-12-19" seq="2000-0970" severity="High" type="CVE"><desc><descript source="cve">IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the &quot;Session ID Cookie Marking&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5396.php">XF:session-cookie-remote-retrieval</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-080.asp">MS:MS00-080</ref><ref source="" url="http://www.acrossecurity.com/aspr/ASPR-2000-07-22-1-PUB.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/7265">7265</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0971" published="2000-12-19" seq="2000-0971" severity="High" type="CVE"><desc><descript source="cve">Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possible execute arbitrary commands via a long &quot;RCPT TO&quot; or &quot;MAIL FROM&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5398.php">XF:avirt-rcpt-to-dos</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5397.php">XF:avirt-mail-from-dos</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0301.html">BUGTRAQ:20001023 Avirt Mail 4.x DoS</ref></refs><vuln_soft><prod name="Avirt Mail Server" vendor="Avirt"><vers num="4.0"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0972" published="2000-12-19" seq="2000-0972" severity="Low" type="CVE"><desc><descript source="cve">HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target file during the crontab session, quitting the session, and reading the error messages that crontab generates.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5410.php">XF:hp-crontab-read-files</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0317.html">BUGTRAQ:20001020 [ Hackerslab bug_paper ] HP-UX crontab temporary file symbolic link vulnerability</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.00"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0973" published="2000-12-19" seq="2000-0973" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbitrary commands by forcing a long error message to be generated.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5374.php">XF:curl-error-bo</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1804">BID 1804</ref><ref source="REDHAT" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0331.html">RHBA-2000:092-01</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:72.curl.asc">FreeBSD-SA-00:72</ref></refs><vuln_soft><prod name="curl" vendor="Daniel Stenberg"><vers num="7.4"/><vers num="7.3"/><vers num="7.2.1"/><vers num="7.2"/><vers num="7.1.1"/><vers num="7.1"/><vers num="6.5.2"/><vers num="6.5.1"/><vers num="6.5"/><vers num="6.4"/><vers num="6.3"/><vers num="6.1beta"/><vers num="6.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0974" published="2000-12-19" seq="2000-0974" severity="High" type="CVE"><desc><descript source="cve">GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1797">BID 1797</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5386.php">XF:gnupg-message-modify</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0201.html">20001011 GPG 1.0.3 doesn&apos;t detect modifications to files with multiple signatures</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001111">20001111 gnupg: incorrect signature verification</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:67.gnupg.asc">FreeBSD-SA-00:67</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-089.html">RHSA-2000:089</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2000-038.0.txt">CSSA-2000-038.0</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000334">CLSA-2000:334</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0361.html">20001025 Immunix OS Security Update for gnupg package</ref><ref source="OSVDB" url="http://www.osvdb.org/1608">1608</ref></refs><vuln_soft><prod name="GNU Privacy Guard" vendor="Gnu"><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2000-0975" published="2000-12-19" seq="2000-0975" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0210.html">BUGTRAQ:20001012 Anaconda Advisory</ref><ref source="XF" url="http://xforce.iss.net/static/5750.php">anaconda-apexec-directory-traversal</ref><ref source="OSVDB" url="http://www.osvdb.org/435">435</ref></refs><vuln_soft><prod name="Foundation Directory" vendor="Anaconda Partners"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0976" published="2000-12-19" seq="2000-0976" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1805">BID 1805</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0211.html">BUGTRAQ:20001012 another Xlib buffer overflow</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20020502-01-I">20020502-01-I</ref><ref source="XF" url="http://www.iss.net/security_center/static/5751.php">xfree-xlib-bo(5751)</ref></refs><vuln_soft><prod name="xlib" vendor="XFree86 Project"><vers num="3.3x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0977" published="2000-12-19" seq="2000-0977" severity="Medium" type="CVE"><desc><descript source="cve">mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file name in the &quot;filename&quot; parameter in a POST request, which is then sent by email to the address specified in the &quot;email&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1807">BID 1807</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0172.html">BUGTRAQ:20001011 Mail File POST Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/5358.php">mailfile-post-file-read</ref></refs><vuln_soft><prod name="Mail File" vendor="Oatmeal Studios"><vers num="1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2000-0978" published="2000-12-19" seq="2000-0978" severity="High" type="CVE"><desc><descript source="cve">bbd server in Big Brother System and Network Monitor before 1.5c2 allows remote attackers to execute arbitrary commands via the &quot;&amp;&quot; shell metacharacter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1779">BID 1779</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0162.html">BUGTRAQ:20001010 Big Brother Systems and Network Monitor vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/5719.php">bb4-netmon-execute-commands</ref></refs><vuln_soft><prod name="Big Brother Network Monitor" vendor="BB4"><vers num="1.5c2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0979" published="2000-12-19" seq="2000-0979" severity="Medium" type="CVE"><desc><descript source="cve">File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the &quot;Share Level Password&quot; vulnerability.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5395.php">XF:win9x-share-level-password</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1780">BID 1780</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-072.asp">MS:MS00-072</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97147777618139&amp;w=2">20001012 NSFOCUS SA2000-05: Microsoft Windows 9x NETBIOS password</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:996">oval:org.mitre.oval:def:996</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Windows ME" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0980" published="2000-12-19" seq="2000-0980" severity="Medium" type="CVE"><desc><descript source="cve">NMPI (Name Management Protocol on IPX) listener in Microsoft NWLink does not properly filter packets from a broadcast address, which allows remote attackers to cause a broadcast storm and flood the network.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5357.php">XF:win-nmpi-packet-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1781">BID 1781</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-073.asp">MS:MS00-073</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Windows ME" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-0981" published="2000-12-19" seq="2000-0981" severity="High" type="CVE"><desc><descript source="cve">MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5409.php">XF:mysql-authentication</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1826">BID 1826</ref><ref source="CONFIRM" url="http://www.mysql.com/documentation/mysql/commented/manual.php?section=Security">http://www.mysql.com/documentation/mysql/commented/manual.php?section=Security</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0318.html">20001023 [CORE SDI ADVISORY] MySQL weak authentication</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.23"/><vers num="3.22"/><vers num="3.21"/><vers num="3.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0982" published="2000-12-19" seq="2000-0982" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer before 5.5 forwards cached user credentials for a secure web site to insecure pages on the same web site, which could allow remote attackers to obtain the credentials by monitoring connections to the web server, aka the &quot;Cached Web Credentials&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5367.php">XF:ie-cache-info</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1793">BID 1793</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-076.asp">MS:MS00-076</ref><ref source="" url="http://www.acrossecurity.com/aspr/ASPR-2000-07-22-2-PUB.txt"></ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.0"/><vers num="4.0.1"/><vers num="4.0.0.1"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0983" published="2000-12-19" seq="2000-0983" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utilization) via a sequence of null bytes to the NetMeeting port, aka the &quot;NetMeeting Desktop Sharing&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5368.php">XF:netmeeting-desktop-sharing-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1798">BID 1798</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/140341">20001018 Denial of Service attack against computers running Microsoft NetMeeting</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms00-077.asp">MS00-077</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q273854">Q273854</ref></refs><vuln_soft><prod name="NetMeeting" vendor="Microsoft"><vers num="3.0.1_4.4.3385"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0984" published="2000-12-19" seq="2000-0984" severity="Medium" type="CVE"><desc><descript source="cve">The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a &quot;?/&quot; string.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5412.php">XF:cisco-ios-query-dos</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/ioshttpserverquery-pub.shtml">CISCO:20001025 Cisco IOS HTTP Server Query Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1838">BID 1838</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5412">cisco-ios-query-dos(5412)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1XP"/><vers num="12.1XL"/><vers num="12.1XJ"/><vers num="12.1XI"/><vers num="12.1XH"/><vers num="12.1XG"/><vers num="12.1XF"/><vers num="12.1XE"/><vers num="12.1XD"/><vers num="12.1XC"/><vers num="12.1XB"/><vers num="12.1XA"/><vers num="12.1T"/><vers num="12.1EC"/><vers num="12.1DC"/><vers num="12.1DB"/><vers num="12.1DA"/><vers num="12.1AA"/><vers num="12.0XJ"/><vers num="12.0XH"/><vers num="12.0XE"/><vers num="12.0XA"/><vers num="12.0W5"/><vers num="12.0T"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0985" published="2000-12-19" seq="2000-0985" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long &quot;MAIL FROM&quot; or &quot;RCPT TO&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1789">BID 1789</ref><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2000/a101200-2.txt">ATSTAKE:A101200-2</ref></refs><vuln_soft><prod name="All-Mail" vendor="Nevis Systems"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0986" published="2000-12-19" seq="2000-0986" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5390.php">XF:oracle-home-bo</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0294.html">BUGTRAQ:20001020 [ Hackerslab bug_paper ] Linux ORACLE 8.1.5 vulnerability</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0987" published="2000-12-19" seq="2000-0987" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long &quot;connect&quot; command line parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/140709">BUGTRAQ:20001020 In response to posting 10/18/2000 vulnerability in Oracle Internet Directory in Oracle 8.1.6</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5401.php">XF:oracle-oidldap-bo</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1828">BID 1828</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/140340">20001018 vulnerability in Oracle Internet Directory in Oracle 8.1.6</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.6"/></prod><prod name="Internet Directory" vendor="Oracle"><vers num="2.0.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0988" published="2000-12-19" seq="2000-0988" severity="High" type="CVE"><desc><descript source="cve">WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5376.php">XF:winu-backdoor</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1801">BID 1801</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0238.html">20001013 WinU Backdoor passwords!!!!</ref><ref source="CONFIRM" url="http://www.bardon.com/pwdcrack.htm">http://www.bardon.com/pwdcrack.htm</ref></refs><vuln_soft><prod name="WinU" vendor="Bardon Data Systems"><vers num="5.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-09" name="CVE-2000-0989" published="2000-12-19" seq="2000-0989" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5414.php">XF:intel-email-username-bo</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0293.html">BUGTRAQ:20001020 DoS in Intel corporation &apos;InBusiness eMail Station&apos;</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1844">BID 1844</ref><ref source="OSVDB" url="http://www.osvdb.org/6488">6488</ref></refs><vuln_soft><prod name="InBusiness eMail Station" vendor="Intel"><vers num="1.4.87"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0990" published="2000-12-19" seq="2000-0990" severity="High" type="CVE"><desc><descript source="cve">cmd5checkpw 0.21 and earlier allows remote attackers to cause a denial of service via an &quot;SMTP AUTH&quot; command with an unknown username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5382.php">XF:cmd5checkpw-qmail-bypass-authentication</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1809">BID 1809</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0258.html">BUGTRAQ:20001016 Authentication failure in cmd5checkpw 0.21</ref><ref source="CONFIRM" url="http://members.elysium.pl/brush/cmd5checkpw/changes.html">http://members.elysium.pl/brush/cmd5checkpw/changes.html</ref></refs><vuln_soft><prod name="cmd5checkpw" vendor="Krzysztof Dabrowski"><vers num="0.21"/><vers num="0.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-0991" published="2000-12-19" seq="2000-0991" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute arbitrary commands via a long telnet URL, aka the &quot;HyperTerminal Buffer Overflow&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5387.php">XF:win-hyperterminal-telnet-bo</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1815">BID 1815</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-079.asp">MS:MS00-079</ref></refs><vuln_soft><prod name="HyperTerminal" vendor="Hilgraeve"><vers num="6.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0992" published="2000-12-19" seq="2000-0992" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1742">BID 1742</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0359.html">BUGTRAQ:20000930 scp file transfer hole</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:057">MDKSA-2000:057</ref><ref source="XF" url="http://xforce.iss.net/static/5312.php">scp-overwrite-files</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.31"/><vers num="1.2.30"/><vers num="1.2.29"/><vers num="1.2.28"/><vers num="1.2.27"/><vers num="1.2.26"/><vers num="1.2.25"/><vers num="1.2.24"/><vers num="1.2.23"/><vers num="1.2.22"/><vers num="1.2.21"/><vers num="1.2.20"/><vers num="1.2.19"/><vers num="1.2.18"/><vers num="1.2.17"/><vers num="1.2.16"/><vers num="1.2.15"/><vers num="1.2.14"/></prod><prod name="OpenSSH" vendor="OpenBSD"><vers num="1.2.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-0993" published="2000-12-19" seq="2000-0993" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5339.php">XF:bsd-libutil-format</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1744">BID 1744</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata27.html#pw_error">20001003 A format string vulnerability exists in the pw_error(3) function.</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-015.txt.asc">NetBSD-SA2000-015</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:58.chpass.asc">FreeBSD-SA-00:58</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97068555106135&amp;w=2">20001004 Re: OpenBSD Security Advisory</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.0"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-08-22" name="CVE-2000-0994" published="2000-12-19" seq="2000-0994" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5338.php">XF:bsd-fstat-format</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1746">BID 1746</ref><ref patch="1" source="OpenBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">OPENBSD:20001006 There are printf-style format string bugs in several privileged programs.</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97068555106135&amp;w=2">20001004 Re: OpenBSD Security Advisory</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-08-22" name="CVE-2000-0995" published="2000-12-19" seq="2000-0995" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="OpenBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">OPENBSD:20001006 There are printf-style format string bugs in several privileged programs.</ref><ref source="XF" url="http://xforce.iss.net/static/5635.php">bsd-yp-passwd-format</ref><ref source="OSVDB" url="http://www.osvdb.org/6125">6125</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-08-22" name="CVE-2000-0996" published="2000-12-19" seq="2000-0996" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref patch="1" source="OpenBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">OPENBSD:20001006 There are printf-style format string bugs in several privileged programs.</ref><ref source="XF" url="http://xforce.iss.net/static/5636.php">bsd-su-format</ref><ref source="OSVDB" url="http://www.osvdb.org/6124">6124</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-0997" published="2000-12-19" seq="2000-0997" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5337.php">XF:bsd-eeprom-format</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1752">BID 1752</ref><ref source="OpenBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2000-0998" published="2000-12-11" seq="2000-0998" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in top program allows local attackers to gain root privileges via the &quot;kill&quot; or &quot;renice&quot; function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1895">BID 1895</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:62.top.v1.1.asc">FREEBSD:FreeBSD-SA-00:62</ref><ref source="OpenBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5"/><vers num="3.5 Stable"/><vers num="3.5 Stable pre 2000-12-23"/><vers num="3.5 Stable pre 2001-05-02"/><vers num="3.5.1"/><vers num="3.5.1 Release"/><vers num="3.5.1 Stable"/><vers num="3.5.1 Stable pre 2001-07-20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-0999" published="2000-12-11" seq="2000-0999" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="OpenBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch">OPENBSD:20001006 There are printf-style format string bugs in several privileged programs.</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1000" published="2000-12-11" seq="2000-1000" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in AOL Instant Messenger (AIM) 4.1.2010 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by transferring a file whose name includes format characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5314.php">XF:aim-file-transfer-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1747">BID 1747</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/137374">BUGTRAQ:20001003 AOL Instant Messenger DoS</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="4.1.2010"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1001" published="2000-12-11" seq="2000-1001" severity="High" type="CVE"><desc><descript source="cve">add_2_basket.asp in Element InstantShop allows remote attackers to modify price information via the &quot;price&quot; hidden form variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97240616129614&amp;w=2">BUGTRAQ:200024 Price modification in Element InstantShop</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1836">BID 1836</ref><ref source="XF" url="http://xforce.iss.net/static/5402.php">instantshop-modify-price</ref><ref source="OSVDB" url="http://www.osvdb.org/6487">6487</ref></refs><vuln_soft><prod name="Element InstantShop" vendor="Element N.V"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1002" published="2000-12-11" seq="2000-1002" severity="Medium" type="CVE"><desc><descript source="cve">POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1792">BID 1792</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5363.php">XF:communigate-email-verify</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/139523">BUGTRAQ:20001012 Re: Netscape Messaging server 4.15 poor error strings</ref></refs><vuln_soft><prod name="Communigate Pro" vendor="Stalker"><vers num="3.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1003" published="2000-12-11" seq="2000-1003" severity="Low" type="CVE"><desc><descript source="cve">NETBIOS client in Windows 95 and Windows 98 allows a remote attacker to cause a denial of service by changing a file sharing service to return an unknown driver type, which causes the client to crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5370.php">XF:win-netbios-driver-type-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1794">BID 1794</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/139511">20001012 NSFOCUS SA2000-04: Microsoft Win9x client driver type comparing vulnerability</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1004" published="2000-12-11" seq="2000-1004" severity="Medium" type="CVE"><desc><descript source="cve">Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5336.php">XF:bsd-photurisd-format</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97068555106135&amp;w=2">BUGTRAQ:20001004 Re: OpenBSD Security Advisory</ref><ref source="OSVDB" url="http://www.osvdb.org/6123">6123</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.6"/><vers num="2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-1005" published="2000-12-11" seq="2000-1005" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5347.php">XF:extropia-webstore-fileread</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1774">BID 1774</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/138495">20001009 Security Advisory : eXtropia WebStore (web_store.cgi) Directory Traversal Vulnerability</ref></refs><vuln_soft><prod name="Extropia WebStore" vendor="Extropia"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1006" published="2000-12-11" seq="2000-1006" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Exchange Server 5.5 does not properly handle a MIME header with a blank charset specified, which allows remote attackers to cause a denial of service via a charset=&quot;&quot; command, aka the &quot;Malformed MIME Header&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1869">BID 1869</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5448.php">XF:ms-exchange-mime-dos</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-082.asp">MS:MS00-082</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1007" published="2000-12-11" seq="2000-1007" severity="Medium" type="CVE"><desc><descript source="cve">I-gear 3.5.7 and earlier does not properly process log entries in which a URL is longer than 255 characters, which allows an attacker to cause reporting errors.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0048.html">NTBUGTRAQ:20001025 I-gear 3.5.x for Microsoft Proxy logging vulnerability + temporary fix.</ref><ref source="XF" url="http://xforce.iss.net/static/5791.php">igear-invalid-log(5791)</ref></refs><vuln_soft><prod name="I-gear" vendor="Symantec"><vers num="3.5.7"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1008" published="2000-12-11" seq="2000-1008" severity="Medium" type="CVE"><desc><descript source="cve">PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1715">BID 1715</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.atstake.com/research/advisories/2000/a092600-1.txt">ATSTAKE:A092600- 1</ref></refs><vuln_soft><prod name="Palm OS" vendor="Palm"><vers num="3.5.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1009" published="2000-12-11" seq="2000-1009" severity="High" type="CVE"><desc><descript source="cve">dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1871">BID 1871</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5437.php">XF:linux-dump-execute-code</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0438.html">20001030 Redhat 6.2 dump command executes external program with suid priviledge.</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/></prod><prod name="Trustix Linux" vendor="Trustix"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1010" published="2000-12-11" seq="2000-1010" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5344.php">XF:linux-talkd-overwrite-root</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1764">BID 1764</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/137890">BUGTRAQ:20001006 talkd [WAS: Re: OpenBSD Security Advisory]</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="5.2"/><vers edition="i386" num="5.2"/><vers edition="Alpha" num="5.2"/><vers num="5.1"/><vers num="5.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2000-1011" published="2000-12-11" seq="2000-1011" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc">FREEBSD:FreeBSD-SA-00:53</ref><ref source="XF" url="http://xforce.iss.net/static/5638.php">freebsd-catopen-bo</ref><ref source="OSVDB" url="http://www.osvdb.org/6070">6070</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0"/><vers num="4.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2000-1012" published="2000-12-11" seq="2000-1012" severity="High" type="CVE"><desc><descript source="cve">The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc">FREEBSD:FreeBSD-SA-00:53</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0"/><vers num="4.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2000-1013" published="2000-12-11" seq="2000-1013" severity="High" type="CVE"><desc><descript source="cve">The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc">FREEBSD:FreeBSD-SA-00:53</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="5.0"/><vers num="4.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1014" published="2000-12-11" seq="2000-1014" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attackers to execute arbitrary commands via format characters in the queryText parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5291.php">XF:unixware-scohelp-format</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1717">BID:1717</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0325.html">20000927 Unixware SCOhelp http server format string vulnerability</ref><ref source="OSVDB" url="http://www.osvdb.org/3240">3240</ref></refs><vuln_soft><prod name="Unixware" vendor="SCO"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-2000-1015" published="2000-12-11" seq="2000-1015" severity="High" type="CVE"><desc><descript source="cve">The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode priviliges and possibly execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5306.php">XF:slashcode-default-admin-passwords</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1731">BID 1731</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0366.html">BUGTRAQ:20000929 Default admin password with Slashcode.</ref></refs><vuln_soft><prod name="Slashcode" vendor="Open Source Development Network"><vers num="1.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1016" published="2000-12-11" seq="2000-1016" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5276.php">XF:suse-installed-packages-exposed</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1707">BID 1707</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/84360">20000921 httpd.conf in Suse 6.4</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.4"/><vers num="6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1017" published="2000-12-11" seq="2000-1017" severity="Medium" type="CVE"><desc><descript source="cve">Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1732">BID 1732</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0032.html">BUGTRAQ:20001003 Update to DST2K0039: Webteachers Webdata: Importing files lower t han web root possible in to database</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0007.html">20001002 DST2K0039: Webteachers Webdata: Importing files lower than web ro ot possible in to database</ref></refs><vuln_soft><prod name="WebData" vendor="WebTeacher"><vers num="2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1018" published="2000-12-11" seq="2000-1018" severity="Low" type="CVE"><desc><descript source="cve">shred 1.0 file wiping utility does not properly open a file for overwriting or flush its buffers, which prevents shred from properly replacing the file&apos;s data and allows local users to recover the file.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1788">BID 1788</ref><ref adv="1" patch="1" source="Security Focus" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97131166004145&amp;w=2">BUGTRAQ:20001011 Shred v1.0 Fix</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119799515246&amp;w=2">20001010 Shred 1.0 Bug Report</ref><ref source="XF" url="http://xforce.iss.net/static/5722.php">shred-recover-files</ref></refs><vuln_soft><prod name="Shred" vendor="Mendel Cooper"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1019" published="2000-12-11" seq="2000-1019" severity="Medium" type="CVE"><desc><descript source="cve">Search engine in Ultraseek 3.1 and 3.1.10 (aka Inktomi Search) allows remote attackers to cause a denial of service via a malformed URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5439.php">XF:ultraseek-malformed-url-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1866">BID 1866</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97301487015664&amp;w=2">20001030 Ultraseek 3.1.x Remote DoS Vulnerability</ref></refs><vuln_soft><prod name="Search Software" vendor="Inktomi"><vers num="3.0"/><vers num="3.1.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1020" published="2000-12-11" seq="2000-1020" severity="High" type="CVE"><desc><descript source="cve">Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5250.php">XF:mdaemon-url-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1689">BID 1689</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96925269716274&amp;w=2">20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS</ref></refs><vuln_soft><prod name="MDaemon" vendor="Alt-N"><vers num="3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1021" published="2000-12-11" seq="2000-1021" severity="High" type="CVE"><desc><descript source="cve">Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/static/5250.php">XF:mdaemon-url-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1689">BID 1689</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96925269716274&amp;w=2">20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS</ref></refs><vuln_soft><prod name="MDaemon" vendor="Alt-N"><vers num="3.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1022" published="2000-12-11" seq="2000-1022" severity="High" type="CVE"><desc><descript source="cve">The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands, which allows remote attackers to execute restricted commands by sending a DATA command before sending the restricted commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1698">BID 1698</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5277.php">XF:cisco-pix-smtp-filtering</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0222.html">20000919 Cisco PIX Firewall (smtp content filtering hack)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0241.html">20000920 Re: Cisco PIX Firewall (smtp content filtering hack) - Version 4.2(1) not exploitable</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/PIXfirewallSMTPfilter-pub.shtml">20001005 Cisco Secure PIX Firewall Mailguard Vulnerability</ref></refs><vuln_soft><prod name="PIX Firewall" vendor="Cisco"><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4(4)"/><vers num="4.3"/><vers num="4.2.2"/><vers num="4.2.1"/><vers num="4.2(5)"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1023" published="2000-12-11" seq="2000-1023" severity="High" type="CVE"><desc><descript source="cve">The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/static/5284.php">XF:alabanza-unauthorized-access</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1710">BID 1710</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/84766">20000924 Major Vulnerability in Alabanza Control Panel</ref></refs><vuln_soft><prod name="Control Panel" vendor="Alabanza"><vers num="3.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1024" published="2000-12-11" seq="2000-1024" severity="High" type="CVE"><desc><descript source="cve">eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/static/5450.php">http://xforce.iss.net/static/5450.php</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1876">BID 1876</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97306581513537&amp;w=2">20001101 Unify eWave ServletExec upload</ref></refs><vuln_soft><prod name="eWave ServletExec" vendor="Unify"><vers num="3.0c"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1025" published="2000-12-11" seq="2000-1025" severity="Medium" type="CVE"><desc><descript source="cve">eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the &quot;/servlet/&quot; string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1868">BID 1868</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97295224226042&amp;w=2">BUGTRAQ:20001030 Unify eWave ServletExec DoS</ref><ref source="XF" url="http://xforce.iss.net/static/5435.php">ewave-servletexec-dos</ref></refs><vuln_soft><prod name="eWave ServletExec" vendor="Unify"><vers num="3.0c"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2000-1026" published="2000-12-11" seq="2000-1026" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in LBNL tcpdump allow remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1870">BID 1870</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:61.tcpdump.v1.1.asc">FreeBSD-SA-00:61</ref><ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0681.html">SuSE-SA:2000:46</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5480">tcpdump-afs-packet-overflow(5480)</ref></refs><vuln_soft><prod name="tcpdump" vendor="LBL"><vers num="3.5 alpha"/><vers num="3.5"/><vers num="3.4a6"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1027" published="2000-12-11" seq="2000-1027" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server with PASV requests, which includes the real IP address in the response when passive mode is established.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1877">BID 1877</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97059440000367&amp;w=2">BUGTRAQ:20001003 Cisco PIX Firewall allow external users to discover internal Ips</ref><ref source="XF" url="http://xforce.iss.net/static/5646.php">cisco-pix-reveal-address</ref><ref source="OSVDB" url="http://www.osvdb.org/1623">1623</ref></refs><vuln_soft><prod name="PIX Firewall" vendor="Cisco"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1028" published="2000-12-11" seq="2000-1028" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1886">BID 1886</ref><ref source="Security Focus" url="http://www.securityfocus.com/archive/1/142792">BUGTRAQ:20001102 HPUX cu -l option buffer overflow vulnerabilit</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.9"/><vers num="9.8"/><vers num="9.7"/><vers num="9.6"/><vers num="9.5"/><vers num="9.4"/><vers num="9.10"/><vers num="9.1"/><vers num="9.0"/><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1029" published="2000-12-11" seq="2000-1029" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1887">BID 1887</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/141660">BUGTRAQ:20001027 old version of host command vulnearbility</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2000-1030" published="2000-12-11" seq="2000-1030" severity="Medium" type="CVE"><desc><descript source="cve">CS&amp;T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1888">BID 1888</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/142672">20001031 Re: Samba 2.0.7 SWAT vulnerabilities</ref></refs><vuln_soft><prod name="CorporateTime for the Web" vendor="CSandT"><vers num="2.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2000-1031" published="2000-12-11" seq="2000-1031" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in dtterm in HP-UX 11.0 and HP Tru64 UNIX 4.0f through 5.1a allows local users to execute arbitrary code via a long -tn option.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1889">BID:1889</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2000-q4/0034.html">HP:HPSBUX0011-128</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/75188">20000810 Re: Possible vulnerability in HPUX ( Add vulnerability List )</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/290115">20020902 Happy Labor Day from Snosoft</ref><ref source="FULLDISC" url="http://archives.neohapsis.com/archives/fulldisclosure/2002-q3/1203.html">20020919 iDEFENSE OSF1/Tru64 3.x vuln clarification</ref><ref source="HP" url="http://wwss1pro.compaq.com/support/reference_library/viewdocument.asp?source=SRB0039W.xml&amp;dt=11">SSRT2275</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/320067">VU#320067</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5461">hp-dtterm(5461)</ref></refs><vuln_soft><prod name="Tru64 UNIX" vendor="HP"><vers num="5.1a"/><vers num="5.1"/><vers num="5.0a"/><vers num="4.0G PK4"/><vers num="4.0g"/><vers num="4.0F PK8"/><vers num="4.0f"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.4"/><vers num="11.0"/><vers num="10.24"/><vers num="10.20"/><vers num="10.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1032" published="2000-12-11" seq="2000-1032" severity="Medium" type="CVE"><desc><descript source="cve">The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1890">BID 1890</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/142808">BUGTRAQ:20001101 Re: Samba 2.0.7 SWAT vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5816">fw1-login-response(5816)</ref><ref source="OSVDB" url="http://www.osvdb.org/1632">1632</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1033" published="2000-12-11" seq="2000-1033" severity="High" type="CVE"><desc><descript source="cve">Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5436.php">XF:ftp-servu-brute-force</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1860">BID 1860</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/141905">20001029 Brute Forcing FTP Servers with enabled anti-hammering (anti brute-force) modus</ref></refs><vuln_soft><prod name="Serv-U" vendor="Cat Soft"><vers num="2.5x"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1034" published="2000-12-11" seq="2000-1034" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the &quot;ActiveX Parameter Validation&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1899">BID 1899</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-085.asp">MS:MS00-085</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349782305448&amp;w=2">20001106 System Monitor ActiveX Buffer Overflow Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5467">system-monitor-activex-bo(5467)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1035" published="2000-12-11" seq="2000-1035" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1690">BID 1690</ref><ref source="MISC" url="http://www.synnergy.net/Archives/Advisories/dethy/typsoft-ftpd.txt">http://www.synnergy.net/Archives/Advisories/dethy/typsoft-ftpd.txt</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96879389027478&amp;w=2">20000912 TYPSoft FTP Server remote DoS Problem</ref></refs><vuln_soft><prod name="TYPSoft" vendor="TYPSoft"><vers num="0.7x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1036" published="2000-12-11" seq="2000-1036" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via a .. (dot dot) attack on the Image parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1704">BID 1704</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5275.php">XF:rbs-isp-directory-traversal</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0252.html">BUGTRAQ:20000920 Extent RBS directory Transversal.</ref></refs><vuln_soft><prod name="RBS ISP" vendor="Extent Technologies"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1037" published="2000-12-11" seq="2000-1037" severity="High" type="CVE"><desc><descript source="cve">Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1662">BID 1662</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/76389">BUGTRAQ:20000815 Firewall-1 session agent 3.0 -&gt; 4.1, dictionnary and brute force attack</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1038" published="2000-12-11" seq="2000-1038" severity="Medium" type="CVE"><desc><descript source="cve">The web administration interface for IBM AS/400 Firewall allows remote attackers to cause a denial of service via an empty GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5266.php">XF:as400-firewall-dos</ref><ref adv="1" patch="1" source="" url="http://as400service.rochester.ibm.com/n_dir/nas4apar.NSF/5ec6cdc6ab42894a862568f90073c74a/9ce636030a58807186256955003d128d?OpenDocument">AIXAPAR:SA90544</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=SA90544&amp;apar=only">SA90544</ref></refs><vuln_soft><prod name="AS400 Firewall" vendor="IBM"><vers num="R440"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1039" published="2001-01-09" seq="2000-1039" severity="Medium" type="CVE"><desc><descript source="cve">Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the &quot;NAPTHA&quot; class of vulnerabilities.  NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2022">BID 2022</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2000-21.html">CERT:CA-2000-21</ref><ref adv="1" patch="1" source="&#xa;Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-091.asp">MS:MS00-091</ref><ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_NAPTHA.html">20001130 The NAPTHA DoS vulnerabilities</ref><ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0105.html">20001204 NAPTHA Advisory Updated - BindView RAZOR</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="SE"/><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Windows ME" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1040" published="2000-12-11" seq="2000-1040" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in logging function of ypbind 3.3, while running in debug mode, leaks file descriptors and allows an attacker to cause a denial of service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1820">BID 1820</ref><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA-2000-086-05.html">REDHAT:RHSA-2000:086-05</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001014">20001014 nis: local exploit</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1">MDKSA-2000:064</ref><ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html">SuSE-SA:2000:042</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-086.html">RHSA-2000:086</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-039.0.txt">CSSA-2000-039.0</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0356.html">20001025 Immunix OS Security Update for ypbind package</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html">20001030 Trustix Security Advisory - ping gnupg ypbind</ref><ref source="XF" url="http://xforce.iss.net/static/5394.php">ypbind-printf-format-string</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1041" published="2000-12-11" seq="2000-1041" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ypbind 3.3 possibly allows an attacker to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-039.0.txt">CALDERA:CSSA-2000-039.0</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html">SUSE:SuSE-SA:2000:042</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1">MANDRAKE:MDKSA-2000:064</ref><ref source="XF" url="http://xforce.iss.net/static/5759.php">ypbind-remote-bo</ref></refs><vuln_soft><prod name="ypbind" vendor="Swen Thuemmler"><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1042" published="2000-12-11" seq="2000-1042" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Linux Mandrake" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1">MANDRAKE:MDKSA-2000:064</ref><ref source="XF" url="http://xforce.iss.net/static/5730.php">linux-ypserv-bo</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="6.1"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1043" published="2000-12-11" seq="2000-1043" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Linux Mandrake" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-064.php3?dis=7.1">MANDRAKE:MDKSA-2000:064</ref><ref source="XF" url="http://xforce.iss.net/static/5731.php">linux-ypserv-format-string</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="6.1"/><vers num="7.0"/><vers num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1044" published="2000-12-11" seq="2000-1044" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in ypbind-mt in SuSE SuSE-6.2, and possibly other Linux operating systems, allows an attacker to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1820">BID 1820</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0262.html">SUSE:SuSE-SA:2000:042</ref><ref source="XF" url="http://xforce.iss.net/static/5394.php">ypbind-printf-format-string</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1045" published="2000-12-11" seq="2000-1045" severity="Low" type="CVE"><desc><descript source="cve">nss_ldap earlier than 121, when run with nscd (name service caching daemon), allows remote attackers to cause a denial of service via a flood of LDAP requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Linux Mandrake" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-066-1.php3">MANDRAKE:MDKSA-2000-066</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1863">BID 1863</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-024.html">REDHAT:RHSA-2000:024</ref><ref source="XF" url="http://xforce.iss.net/static/5449.php">nssldap-nscd-dos</ref></refs><vuln_soft><prod name="nss_ldap" vendor="Padl Software"><vers num="Build 85"/><vers num="Build 113"/><vers num="Build 105"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1046" published="2000-12-11" seq="2000-1046" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long (1) &quot;RCPT TO,&quot; (2) &quot;SAML FROM,&quot; or (3) &quot;SOML FROM&quot; commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0093.html">BUGTRAQ:20000911 Advisory Code: VIGILANTE-2000011 Lotus Domino ESMTP Service Buffer overflow</ref></refs><vuln_soft><prod name="Domino" vendor="Lotus"><vers num="5.0.2a"/><vers num="5.0.2c"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1047" published="2000-12-11" seq="2000-1047" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SMTP service of Lotus Domino 5.0.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long ENVID keyword in the &quot;MAIL FROM&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1905">BID:1905</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/143071">BUGTRAQ:20001103 [SAFER] Buffer overflow in Lotus Domino SMTP Server</ref><ref source="XF" url="http://xforce.iss.net/static/5488.php">lotus-domino-smtp-envid(5488)</ref><ref source="OSVDB" url="http://www.osvdb.org/442">442</ref></refs><vuln_soft><prod name="Domino Enterprise Server" vendor="Lotus"><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2b"/><vers num="5.0.2"/><vers num="5.0.1"/></prod><prod name="Domino Mail Server" vendor="Lotus"><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2b"/><vers num="5.0.2"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1048" published="2000-12-11" seq="2000-1048" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5373.php">XF:wingate-view-files</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0245.html">BUGTRAQ:20001016 Wingate 4.1 Beta A vulnerability</ref></refs><vuln_soft><prod name="WinGate" vendor="Qbik"><vers num="4.1 Beta A"/><vers num="4.0.1"/><vers num="3.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-1049" published="2000-12-11" seq="2000-1049" severity="Medium" type="CVE"><desc><descript source="cve">Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of &quot;.&quot; characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5452.php">XF:allaire-jrun-servlet-dos</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=18085&amp;Method=Full"> ALLAIRE:ASB00-030</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97310314724964&amp;w=2">20001101 Allaire&apos;s JRUN DoS</ref></refs><vuln_soft><prod name="JRun" vendor="Macromedia"><vers num="3.0"/><vers num="3.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-1050" published="2000-12-11" seq="2000-1050" severity="Medium" type="CVE"><desc><descript source="cve">Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request that contains an extra &quot;/&quot; in the beginning of the request (aka the &quot;extra leading slash&quot;).</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5407.php">XF:allaire-jrun-webinf-access</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=17966&amp;Method=Full">ALLAIRE:ASB00-027</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236316510117&amp;w=2">20001023 Allaire&apos;s JRUN Unauthenticated Access to WEB-INF directory</ref><ref source="OSVDB" url="http://www.osvdb.org/500">500</ref></refs><vuln_soft><prod name="JRun" vendor="Macromedia"><vers num="3.0"/><vers num="3.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-1051" published="2000-12-11" seq="2000-1051" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Allaire JRun 2.3 server allows remote attackers to read arbitrary files via the SSIFilter servlet.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5405.php"> XF:allaire-jrun-ssifilter-url</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=17968&amp;Method=Full"> ALLAIRE:ASB00-028</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236692714978&amp;w=2">20001023 Allaire JRUN 2.3 Arbitrary File Retrieval</ref></refs><vuln_soft><prod name="JRun" vendor="Macromedia"><vers num="2.3.x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-1052" published="2000-12-11" seq="2000-1052" severity="Medium" type="CVE"><desc><descript source="cve">Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236692714978&amp;w=2">BUGTRAQ:20001023 Allaire JRUN 2.3 Arbitrary File Retrieval</ref></refs><vuln_soft><prod name="JRun" vendor="Macromedia"><vers num="2.3.x"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-1053" published="2000-12-11" seq="2000-1053" severity="High" type="CVE"><desc><descript source="cve">Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5406.php">XF:allaire-jrun-jsp-execute</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=17969&amp;Method=Full">ALLAIRE:ASB00-029</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236125107957&amp;w=2">BUGTRAQ:20001023 Allaire JRUN 2.3 Remote command execution</ref></refs><vuln_soft><prod name="JRun" vendor="Macromedia"><vers num="2.3.x"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1054" published="2000-12-11" seq="2000-1054" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5272.php">XF:ciscosecure-csadmin-bo</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1705">BID 1705</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml">CISCO:20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref></refs><vuln_soft><prod name="CiscoSecure ACS" vendor="Cisco"><vers num="2.42 for Windows NT"/><vers num="2.3(3) for Windows NT"/><vers num="2.1(x) for Windows NT"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1055" published="2000-12-11" seq="2000-1055" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1706">BID 1706</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5273.php">XF:ciscosecure-tacacs-dos</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml">CISCO:20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref><ref source="OSVDB" url="http://www.osvdb.org/1569">1569</ref></refs><vuln_soft><prod name="CiscoSecure ACS" vendor="Cisco"><vers num="2.42 for Windows NT"/><vers num="2.3(3) for Windows NT"/><vers num="2.1(x) for Windows NT"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1056" published="2000-12-11" seq="2000-1056" severity="High" type="CVE"><desc><descript source="cve">CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows null passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5274.php">XF:ciscosecure-ldap-bypass-authentication</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1708">BID 1708</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/csecureacsnt-pub.shtml">CISCO:20000921 Multiple Vulnerabilities in CiscoSecure ACS for Windows NT Server</ref></refs><vuln_soft><prod name="CiscoSecure ACS" vendor="Cisco"><vers num="2.42 for Windows NT"/><vers num="2.3(3) for Windows NT"/><vers num="2.1(x) for Windows NT"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1057" published="2000-12-11" seq="2000-1057" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerabilities in database configuration scripts in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows local users to gain privileges, possibly via insecure permissions.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5229.php">XF:hp-openview-nnm-scripts</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1682">BID 1682</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0140.html">HP:HPSBUX0009-120</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers edition="Solaris" num="6.1"/><vers edition="HP_UX 11.X" num="6.1"/><vers edition="HP_UX 10.X" num="6.1"/><vers edition="Solaris" num="5.01"/><vers edition="HP_UX" num="5.01"/><vers edition="Solaris" num="4.11"/><vers edition="HP_UX" num="4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1058" published="2000-12-11" seq="2000-1058" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, in the SNMP service (snmp.exe), aka the &quot;Java SNMP MIB Browser Object ID parsing problem.&quot;</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5282.php">XF:openview-nmm-snmp-bo</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0274.html">HP:HPSBUX0009-121</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97004856403173&amp;w=2">BUGTRAQ:20000926 DST2K0014: BufferOverrun in HP Openview Network Node Manager v6.1 (Round2)</ref></refs><vuln_soft><prod name="OpenView Network Node Manager" vendor="HP"><vers num="6.1"/><vers num="5.01"/><vers num="4.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1059" published="2000-12-11" seq="2000-1059" severity="High" type="CVE"><desc><descript source="cve">The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an &quot;xhost + localhost&quot; command, which allows local users to sniff X Windows events and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5305.php">XF:xinitrc-bypass-xauthority</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1735">BID 1735</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/136495">20000929 Mandrake 7.1 bypasses Xauthority X session security.</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-052.php3">MDKSA-2000:052</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1060" published="2000-12-11" seq="2000-1060" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an &quot;xhost + localhost&quot; command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5305.php">XF:xinitrc-bypass-xauthority</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1736">BID 1736</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0022.html">20001002 Local vulnerability in XFCE 3.5.1</ref></refs><vuln_soft><prod name="Xfce" vendor="XFree86 Project"><vers num="3.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1061" published="2000-12-11" seq="2000-1061" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX controls, which allows a remote attacker to bypass Internet Explorer&apos;s security settings and execute arbitrary commands via a malicious web page or email, aka the &quot;Microsoft VM ActiveX Component&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-075.asp">MS:MS00-075</ref><ref source="XF" url="http://xforce.iss.net/static/5127.php">java-vm-applet</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.x"/><vers num="5.x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1062" published="2000-12-11" seq="2000-1062" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the FTP service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5353.php">XF:hp-jetdirect-firmware-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1775">BID 1775</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119729613778&amp;w=2">BUGTRAQ:20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref></refs><vuln_soft><prod name="JetDirect" vendor="HP"><vers num="x.08.20"/><vers num="x.08.05"/><vers num="x.08.04"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1063" published="2000-12-11" seq="2000-1063" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the Telnet service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5353.php">XF:hp-jetdirect-firmware-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1775">BID 1775</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119729613778&amp;w=2">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref></refs><vuln_soft><prod name="JetDirect" vendor="HP"><vers num="x.08.20"/><vers num="x.08.05"/><vers num="x.08.04"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1064" published="2000-12-11" seq="2000-1064" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the LPD service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5353.php">XF:hp-jetdirect-firmware-dos</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1775">BID 1775</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119729613778&amp;w=2">20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref></refs><vuln_soft><prod name="JetDirect" vendor="HP"><vers num="x.08.20"/><vers num="x.08.05"/><vers num="x.08.04"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1065" published="2000-12-11" seq="2000-1065" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in IP implementation of HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service (printer crash) via a malformed packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5354.php">XF:hp-jetdirect-ip-implementation</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1775">BID 1775</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97119729613778&amp;w=2">BUGTRAQ:20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS</ref></refs><vuln_soft><prod name="JetDirect" vendor="HP"><vers num="x.08.20"/><vers num="x.08.05"/><vers num="x.08.04"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1066" published="2000-12-11" seq="2000-1066" severity="Medium" type="CVE"><desc><descript source="cve">The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1894">BID 1894</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:63.getnameinfo.asc">FreeBSD-SA-00:63</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1.1 Release"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 alpha"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1068" published="2000-12-11" seq="2000-1068" severity="High" type="CVE"><desc><descript source="cve">pollit.cgi in Poll It 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the poll_options parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236719315352&amp;w=2">BUGTRAQ:20001023 Re: Poll It v2.0 cgi (again)</ref><ref source="CONFIRM" url="http://www.cgi-world.com/pollit.html">http://www.cgi-world.com/pollit.html</ref><ref source="XF" url="http://xforce.iss.net/static/5792.php">pollit-polloptions-execute-commands</ref></refs><vuln_soft><prod name="Poll It Pro" vendor="CGI-World"><vers num="1.6"/></prod><prod name="Poll It" vendor="CGI-World"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1069" published="2000-12-11" seq="2000-1069" severity="Medium" type="CVE"><desc><descript source="cve">pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the real password by specifying the same value to the entered_password and admin_password parameters.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5419.php"> XF:pollit-admin-password-var</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236719315352&amp;w=2">BUGTRAQ:20001023 Re: Poll It v2.0 cgi (again)</ref></refs><vuln_soft><prod name="Poll It Pro" vendor="CGI-World"><vers num="1.6"/></prod><prod name="Poll It" vendor="CGI-World"><vers num="2.01"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1070" published="2000-12-11" seq="2000-1070" severity="Medium" type="CVE"><desc><descript source="cve">pollit.cgi in Poll It 2.01 and earlier uses data files that are located under the web document root, which allows remote attackers to access sensitive or private information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97236719315352&amp;w=2">BUGTRAQ:20001023 Re: Poll It v2.0 cgi (again)</ref><ref source="XF" url="http://xforce.iss.net/static/5794.php">pollit-webroot-gain-access</ref></refs><vuln_soft><prod name="Poll It Pro" vendor="CGI-World"><vers num="1.6"/></prod><prod name="Poll It" vendor="CGI-World"><vers num="2.01"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1071" published="2000-12-11" seq="2000-1071" severity="High" type="CVE"><desc><descript source="cve">The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an &quot;xhost +&quot; command, which allows remote attackers to monitor X Windows events and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/1767">BID 1767</ref><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt">ATSTAKE:A100900-1</ref><ref source="XF" url="http://xforce.iss.net/static/5752.php">ical-xhost-gain-privileges</ref><ref source="OSVDB" url="http://www.osvdb.org/7213">7213</ref></refs><vuln_soft><prod name="iCal" vendor="Netscape"><vers num="2.1Patch2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1072" published="2000-12-11" seq="2000-1072" severity="High" type="CVE"><desc><descript source="cve">iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1768">BID 1768</ref><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt">ATSTAKE:A100900-1</ref><ref source="XF" url="http://xforce.iss.net/static/5756.php">ical-iplncal-gain-access</ref><ref source="OSVDB" url="http://www.osvdb.org/7212">7212</ref></refs><vuln_soft><prod name="iCal" vendor="Netscape"><vers num="2.1Patch2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1073" published="2000-12-11" seq="2000-1073" severity="High" type="CVE"><desc><descript source="cve">csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1769">BID 1769</ref><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt">ATSTAKE:A100900-1</ref><ref source="XF" url="http://xforce.iss.net/static/5757.php">ical-csstart-gain-access</ref><ref source="OSVDB" url="http://www.osvdb.org/7210">7210</ref></refs><vuln_soft><prod name="iCal" vendor="Netscape"><vers num="2.1Patch2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1074" published="2000-12-11" seq="2000-1074" severity="High" type="CVE"><desc><descript source="cve">csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1769">BID 1769</ref><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2000/a100900-1.txt">ATSTAKE:A100900-1</ref><ref source="XF" url="http://xforce.iss.net/static/5757.php">ical-csstart-gain-access</ref><ref source="OSVDB" url="http://www.osvdb.org/7209">7209</ref></refs><vuln_soft><prod name="iCal" vendor="Netscape"><vers num="2.1Patch2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2000-1075" published="2000-12-11" seq="2000-1075" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5421.php"> XF:iplanet-netscape-directory-traversal</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1839">BID 1839</ref><ref source="CONFIRM" url="http://www.iplanet.com/downloads/patches/0122.html">http://www.iplanet.com/downloads/patches/0122.html</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html">20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug</ref><ref source="OSVDB" url="http://www.osvdb.org/4086">4086</ref><ref source="OSVDB" url="http://www.osvdb.org/486">486</ref></refs><vuln_soft><prod name="Netscape Directory Server" vendor="Netscape"><vers num="4.12"/></prod><prod name="iPlanet Certificate Management System" vendor="Sun - Netscape Alliance"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2000-1076" published="2000-12-11" seq="2000-1076" severity="High" type="CVE"><desc><descript source="cve">Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5422.php">XF:iplanet-netscape-plaintext-password</ref><ref adv="1" patch="1" source="Core" url="http://www.core-sdi.com/advisories/iplanet_cms_netscape.htm">CORE-2000-10-26</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html">20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug</ref></refs><vuln_soft><prod name="Netscape Directory Server" vendor="Netscape"><vers num="4.12"/></prod><prod name="iPlanet Certificate Management System" vendor="Sun - Netscape Alliance"><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-1077" published="2000-12-11" seq="2000-1077" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5446.php">XF:iplanet-web-server-shtml-bo</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/141435">BUGTRAQ:20001026 Buffer overflow in iPlanet Web Server 4 server side SHTML parsing module</ref></refs><vuln_soft><prod name="iPlanet Web Server" vendor="iPlanet"><vers num="4.x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1078" published="2000-12-11" seq="2000-1078" severity="Medium" type="CVE"><desc><descript source="cve">ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a &quot;?&quot; character.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5332.php">XF:icq-webfront-url-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/138332">BUGTRAQ:20001007 ICQ WebFront HTTPd DoS</ref></refs><vuln_soft><prod name="ICQ Web Front" vendor="Mirabilis"><vers num="Windows 9x"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1079" published="2000-08-29" seq="2000-1079" severity="High" type="CVE"><desc><descript source="cve">Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1620">BID 1620</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5168.php">XF:win-netbios-corrupt-cache</ref><ref adv="1" patch="1" source="PGP Security" url="http://www.pgp.com/research/covert/advisories/045.asp">Windows NetBIOS Unsolicited Cache Corruption</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/045.asp">20000829 Windows NetBIOS Unsolicited Cache Corruption</ref><ref source="NTBUGTRAQ" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0116.html">20000829 Re: [COVERT-2000-10] Windows NetBIOS Unsolicited Cache Corruption</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval1079.html">OVAL1079</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1079">oval:org.mitre.oval:def:1079</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1080" published="2000-11-01" seq="2000-1080" severity="Medium" type="CVE"><desc><descript source="cve">Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1900">BID 1900</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97318797630246&amp;w=2">BUGTRAQ:20001102 dos on quake1 servers</ref><ref source="CONFIRM" url="http://proquake.ai.mit.edu/">http://proquake.ai.mit.edu/</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5527">quake-empty-udp-dos(5527)</ref></refs><vuln_soft><prod name="Quake" vendor="id Software"><vers num="1.9"/></prod><prod name="ProQuake" vendor="J. P. Grossman"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1081" published="2001-01-09" seq="2000-1081" severity="Medium" type="CVE"><desc><descript source="cve">The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the &quot;Extended Stored Procedure Parameter Parsing&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2030">BID 2030</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp">MS:MS00-092</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval231.html">OVAL231</ref><ref source="ATSTAKE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570878710037&amp;w=2">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:231">oval:org.mitre.oval:def:231</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/><vers num="2000"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1082" published="2001-01-09" seq="2000-1082" severity="Medium" type="CVE"><desc><descript source="cve">The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the &quot;Extended Stored Procedure Parameter Parsing&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2031">BID 2031</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp">MS:MS00-092</ref><ref source="ATSTAKE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570878710037&amp;w=2">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/><vers num="2000"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1083" published="2001-01-09" seq="2000-1083" severity="Low" type="CVE"><desc><descript source="cve">The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the &quot;Extended Stored Procedure Parameter Parsing&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2038">BID 2038</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp">MS:MS00-092</ref><ref source="ATSTAKE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570878710037&amp;w=2">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/><vers num="2000"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1084" published="2001-01-09" seq="2000-1084" severity="Medium" type="CVE"><desc><descript source="cve">The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the &quot;Extended Stored Procedure Parameter Parsing&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2039">BID 2039</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp">MS:MS00-092</ref><ref source="ATSTAKE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570878710037&amp;w=2">20001201 Microsoft SQL Server extended stored procedure vulnerability</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/><vers num="2000"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1085" published="2001-01-09" seq="2000-1085" severity="Medium" type="CVE"><desc><descript source="cve">The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the &quot;Extended Stored Procedure Parameter Parsing&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2040">BID 2040</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp">MS:MS00-092</ref><ref source="ATSTAKE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570884410184&amp;w=2">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/><vers num="2000"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1086" published="2001-01-09" seq="2000-1086" severity="Medium" type="CVE"><desc><descript source="cve">The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the &quot;Extended Stored Procedure Parameter Parsing&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2041">BID 2041</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp">MS:MS00-092</ref><ref source="ATSTAKE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570884410184&amp;w=2">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/><vers num="2000"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1087" published="2001-01-09" seq="2000-1087" severity="Medium" type="CVE"><desc><descript source="cve">The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the &quot;Extended Stored Procedure Parameter Parsing&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2042">BID 2042</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp">MS:MS00-092</ref><ref source="ATSTAKE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570884410184&amp;w=2">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/><vers num="2000"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1088" published="2001-01-09" seq="2000-1088" severity="Medium" type="CVE"><desc><descript source="cve">The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the &quot;Extended Stored Procedure Parameter Parsing&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2043">BID 2043</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-092.asp">MS:MS00-092</ref><ref source="ATSTAKE" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97570884410184&amp;w=2">20001201 SQL Server 2000 Extended Stored Procedure Vulnerability</ref></refs><vuln_soft><prod name="Data Engine" vendor="Microsoft"><vers num="1.0"/><vers num="2000"/></prod><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1089" published="2001-01-09" seq="2000-1089" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the &quot;Phone Book Service Buffer Overflow&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2048">BID 2048</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-094.asp">MS:MS00-094</ref><ref adv="1" patch="1" source="@Stake" url="http://www.stake.com/research/advisories/2000/a120400-1.txt">ATSTAKE:A120400-1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5623">phone-book-service-bo(5623)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-25" name="CVE-2000-1090" published="2001-02-12" seq="2000-1090" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2100">bid 2100</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5729.php">microsoft-iis-file-disclosure(5729)</ref><ref adv="1" source="" url="http://www.nsfocus.com/english/homepage/sa_08.htm"></ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers edition="Far East" num="5.0"/><vers edition="Far East" num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1092" published="2001-01-09" seq="2000-1092" severity="Medium" type="CVE"><desc><descript source="cve">loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a &quot;/&quot; in front of the target filename in the &quot;file&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2109">BID 2109</ref><ref source="BID" url="http://online.securityfocus.com/bid/2109">2109</ref><ref source="XF" url="http://xforce.iss.net/static/5740.php">ezshopper-cgi-file-disclosure(5740)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97676270729984&amp;w=2">20001213 NSFOCUS SA2000-09 : AHG EZshopper Loadpage.cgi File List</ref></refs><vuln_soft><prod name="EZShopper" vendor="Alex Heiphetz Group"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1093" published="2001-01-09" seq="2000-1093" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long &quot;goim&quot; command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2000/a121200-1.txt">ATSTAKE:A121200-1</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="4.2.1193"/><vers num="4.1.2010"/><vers num="4.0"/><vers num="3.5.1856"/><vers num="3.5.1808"/><vers num="3.5.1670"/><vers num="3.5.1635"/><vers num="3.0 N"/><vers num="3.0.1470"/><vers num="2.5.1598"/><vers num="2.5.1366"/><vers num="2.0 N"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1094" published="2001-01-09" seq="2000-1094" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a &quot;buddyicon&quot; command with a long &quot;src&quot; argument.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2000/a121200-1.txt">ATSTAKE:A121200-1</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97668265628917&amp;w=2">20001213 Administrivia &amp; AOL IM Advisory</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97683774417132&amp;w=2">20001214 Re: AIM &amp; @stake&apos;s advisory</ref><ref source="OSVDB" url="http://www.osvdb.org/1692">1692</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="4.2.1193"/><vers num="4.1.2010"/><vers num="4.0"/><vers num="3.5.1856"/><vers num="3.5.1808"/><vers num="3.5.1670"/><vers num="3.5.1635"/><vers num="3.0 N"/><vers num="3.0.1470"/><vers num="2.5.1598"/><vers num="2.5.1366"/><vers num="2.0 N"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2000-1095" published="2001-01-09" seq="2000-1095" severity="High" type="CVE"><desc><descript source="cve">modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1936">BID 1936</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-108.html">REDHAT:RHSA-2000:108-05</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0179.html">20001112 RedHat 7.0 (and SuSE): modutils + netkit = root compromise. (fwd)</ref><ref source="SUSE" url="http://archives.neohapsis.com/archives/linux/suse/2000-q4/0596.html">SuSE-SA:2000:44</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-071-1.php3?dis=7.1">MDKSA-2000:071</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001120">20001120 modutils: local exploit</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000340">CLSA-2000:340</ref><ref source="XF" url="http://xforce.iss.net/static/5516.php">linux-modprobe-execute-code</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers num="6.4"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="5.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2000-1096" published="2001-01-09" seq="2000-1096" severity="Low" type="CVE"><desc><descript source="cve">crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute arbitrary commands by creating world-writeable temporary files and modifying them while the victim is editing the file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1960">BID1960</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20001118a">DEBIAN:20001118 cron: local privilege escalation</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0237.html">20001116 vixie cron...</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5543">vixie-cron-execute-commands(5543)</ref></refs><vuln_soft><prod name="Vixie Cron" vendor="Paul Vixie"><vers num="3.0 pl1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1097" published="2001-01-09" seq="2000-1097" severity="Medium" type="CVE"><desc><descript source="cve">The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via a long username in the authentication page.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2013">BID 2013</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0406.html">BUGTRAQ:20001129 DoS in Sonicwall SOHO firewall</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0435.html">20001201 FW: SonicWALL SOHO Vulnerability (fwd)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5596">sonicwall-soho-dos(5596)</ref><ref source="OSVDB" url="http://www.osvdb.org/1667">1667</ref></refs><vuln_soft><prod name="SOHO Firewall" vendor="SonicWALL"><vers num="5.0.0"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1098" published="2001-01-09" seq="2000-1098" severity="Medium" type="CVE"><desc><descript source="cve">The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0435.html">BUGTRAQ:20001201 FW: SonicWALL SOHO Vulnerability (fwd)</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0439.html">BUGTRAQ:20001201 Re: DoS in Sonicwall SOHO firewall</ref></refs><vuln_soft><prod name="SOHO Firewall" vendor="SonicWALL"><vers num="5.0.0"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1099" published="2001-01-09" seq="2000-1099" severity="Medium" type="CVE"><desc><descript source="cve">Java Runtime Environment in Java Development Kit (JDK) 1.2.2_05 and earlier can allow an untrusted Java class to call into a disallowed class, which could allow an attacker to escape the Java sandbox and conduct unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Sun" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/199&amp;type=0&amp;nav=sec.sba">SUN:00199</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2000-q4/0061.html">HP:HPSBUX0011-132</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0011-132">HPSBUX0011-132</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5605">jdk-untrusted-java-class(5605)</ref><ref source="OSVDB" url="http://www.osvdb.org/7255">7255</ref></refs><vuln_soft><prod name="JDK" vendor="Sun"><vers num="1.2.2_05" prev="1"/><vers num="1.2.1"/><vers num="1.1.8_10" prev="1"/><vers num="1.1.7B"/><vers num="1.1.6"/><vers num="1.2.2_004" prev="1"/><vers num="1.2.1_003" prev="1"/><vers num="1.1.8_002" prev="1"/><vers num="1.1.7B_005" prev="1"/><vers num="1.1.6_007" prev="1"/><vers num="1.2.2_005" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1100" published="2001-01-09" seq="2000-1100" severity="High" type="CVE"><desc><descript source="cve">The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2029">BID 2029</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0433.html">BUGTRAQ:20001130 PostACI Webmail Vulnerability</ref></refs><vuln_soft><prod name="Postaci Webmail" vendor="Trlinux"><vers num="1.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1101" published="2001-01-09" seq="2000-1101" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the &quot;Restrict to home directory&quot; option enabled allows local users to escape the home directory via a &quot;/../&quot; string, a variation of the .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2005">BID 2005</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0386.html">BUGTRAQ:20001127 Vulnerability in Winsock FTPD 2.41/3.00 (Pro)</ref><ref source="XF" url="http://www.iss.net/security_center/static/5608.php">wftpd-dir-traverse(5608)</ref></refs><vuln_soft><prod name="WFTPD" vendor="Texas Imperial Software"><vers edition="Pro" num="3.0"/><vers edition="Pro" num="2.41 RC14"/><vers num="2.41 RC14"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1102" published="2001-01-09" seq="2000-1102" severity="Medium" type="CVE"><desc><descript source="cve">PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via &quot;mode +owgscfxeb&quot; and &quot;oper&quot; commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/147115">BUGTRAQ:20001126 Vulnerablity in PTlink3.5.3ircd + PTlink.Services.1.8.1...</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2008">BID 2008</ref></refs><vuln_soft><prod name="PTlink IRCd" vendor="Ptlink"><vers num="3.5.3"/></prod><prod name="PTlink IRC Services" vendor="Ptlink"><vers num="1.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1103" published="2001-01-09" seq="2000-1103" severity="High" type="CVE"><desc><descript source="cve">rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2009">BID 2009</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/147120">BUGTRAQ:20001127 BSDi 3.0/4.0 rcvtty gid=tty exploit... (mh package)</ref></refs><vuln_soft><prod name="BSD_OS" vendor="BSDI"><vers num="4.0.1"/><vers num="4.0"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-31" name="CVE-2000-1104" published="2001-01-09" seq="2000-1104" severity="High" type="CVE"><desc><descript source="cve">Variant of the &quot;IIS Cross-Site Scripting&quot; vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client.  The client then executes those scripts in the same context as the trusted site.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-060.asp">MS:MS00-060</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1105" published="2001-01-09" seq="2000-1105" severity="Medium" type="CVE"><desc><descript source="cve">The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1933">BID 1933</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0074.html"> WIN2KSEC:20001110 IE 5.x Win2000 Indexing service vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/144270">20001110 IE 5.x Win2000 Indexing service vulnerability</ref></refs><vuln_soft><prod name="Indexing Service" vendor="Microsoft"><vers num="Windows 2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1106" published="2001-01-09" seq="2000-1106" severity="Medium" type="CVE"><desc><descript source="cve">Trend Micro InterScan VirusWall creates an &quot;Intscan&quot; share to the &quot;InterScan&quot; directory with permissions that grant Full Control permissions to the Everyone group, which allows attackers to gain privileges by modifying the VirusWall programs.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2014">BID 2014</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/147563">BUGTRAQ:20001128 TrendMicro InterScan VirusWall shared folder problem</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0016.html">20001201 Responding to BugTraq ID 2014 - &quot;Trend Micro InterScan VirusWall Shared Directory Vulnerability&quot;</ref><ref source="XF" url="http://xforce.iss.net/static/5606.php">interscan-viruswall-unauth-access</ref></refs><vuln_soft><prod name="InterScan VirusWall" vendor="Trend Micro"><vers num="3.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1107" published="2001-01-09" seq="2000-1107" severity="Medium" type="CVE"><desc><descript source="cve">in.identd ident server in SuSE Linux 6.x and 7.0 allows remote attackers to cause a denial of service via a long request, which causes the server to access a NULL pointer and crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2015">BID 2015</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0387.html">BUGTRAQ:20001128 SuSE Linux 6.x 7.0 Ident buffer overflow</ref><ref source="XF" url="http://xforce.iss.net/static/5590.php">linux-ident-bo</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1108" published="2001-01-09" seq="2000-1108" severity="Medium" type="CVE"><desc><descript source="cve">cons.saver in Midnight Commander (mc) 4.5.42 and earlier does not properly verify if an output file descriptor is a TTY, which allows local users to corrupt files by creating a symbolic link to the target file, calling mc, and specifying that link as a TTY argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1945">BID 1945</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20001125">DEBIAN:20001125 mc: local DoS</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0192.html">20001113 Problems with cons.saver</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-078.php3">MDKSA-2000:078</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5519">midnight-commander-conssaver-symlink(5519)</ref></refs><vuln_soft><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.42"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1109" published="2001-01-09" seq="2000-1109" severity="Medium" type="CVE"><desc><descript source="cve">Midnight Commander (mc) 4.5.51 and earlier does not properly process malformed directory names when a user opens a directory, which allows other local users to gain privileges by creating directories that contain special characters followed by the commands to be executed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2016">BID 2016</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0373.html">BUGTRAQ:20001127 Midnight Commander</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-036">DSA-036</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_011_mc.html">SuSE-SA:2001:11</ref><ref source="XF" url="http://xforce.iss.net/static/5929.php">midnight-commander-elevate-privileges(5929)</ref></refs><vuln_soft><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4.5.51"/><vers num="4.5.50"/><vers num="4.5.49"/><vers num="4.5.48"/><vers num="4.5.47"/><vers num="4.5.46"/><vers num="4.5.45"/><vers num="4.5.44"/><vers num="4.5.43"/><vers num="4.5.42"/><vers num="4.5.41"/><vers num="4.5.40"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1110" published="2001-01-09" seq="2000-1110" severity="Medium" type="CVE"><desc><descript source="cve">document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2017">BID 2017</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0384.html">BUGTRAQ:20001128 IBM Net.Data Local Path Disclosure Vulnerability?</ref></refs><vuln_soft><prod name="Net.Data" vendor="IBM"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1111" published="2001-01-09" seq="2000-1111" severity="Medium" type="CVE"><desc><descript source="cve">Telnet Service for Windows 2000 Professional does not properly terminate incomplete connection attempts, which allows remote attackers to cause a denial of service by connecting to the server and not providing any input.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2018">BID 2018</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/147914">BUGTRAQ:20001129 Windows 2000 Telnet Service DoS</ref><ref source="XF" url="http://xforce.iss.net/static/5598.php">win2k-telnet-dos(5598)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1112" published="2001-01-09" seq="2000-1112" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the &quot;.WMS Script Execution&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1976">BID 1976</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-090.asp">MS:MS00-090</ref><ref source="XF" url="http://xforce.iss.net/static/5575.php">mediaplayer-wms-script-exe</ref></refs><vuln_soft><prod name="Media Player" vendor="Microsoft"><vers num="7"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1113" published="2001-01-09" seq="2000-1113" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed Active Stream Redirector (.ASX) file, aka the &quot;.ASX Buffer Overrun&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1980">BID 1980</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-090.asp">MS:MS00-090</ref><ref source="ATSTAKE" url="http://www.atstake.com/research/advisories/2000/a112300-1.txt">A112300-1</ref><ref source="XF" url="http://xforce.iss.net/static/5574.php">mediaplayer-asx-bo</ref></refs><vuln_soft><prod name="Media Player" vendor="Microsoft"><vers num="6.4"/><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1114" published="2001-01-09" seq="2000-1114" severity="Medium" type="CVE"><desc><descript source="cve">Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as &quot;.&quot;, or &quot;+&quot;, or &quot;%20&quot;.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1970">BID 1970</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0285.html">BUGTRAQ:20001121 Disclosure of JSP source code with ServletExec AS v3.0c + web ins tance</ref></refs><vuln_soft><prod name="eWave ServletExec" vendor="Unify"><vers num="3.0c"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-17" name="CVE-2000-1115" published="2001-01-09" seq="2000-1115" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1979">BID 1979</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0299.html">BUGTRAQ:20001122 602Pro Lan Suite Web Admin Overflow</ref><ref source="CONFIRM" url="http://www.software602.com/products/ls/support/newbuild.html">http://www.software602.com/products/ls/support/newbuild.html</ref><ref source="XF" url="http://xforce.iss.net/static/5583.php">software602-lan-suite-bo</ref></refs><vuln_soft><prod name="602Pro LAN SUITE" vendor="Software602"><vers num="2000a 2000.0.1.32" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1116" published="2001-01-09" seq="2000-1116" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5388.php">XF:broker-ftp-username-dos</ref><ref source="WIN2KSEC" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0041.html">20001018 TransSoft&apos;s Broker FTP Server 3.x &amp; 4.x Remote DoS attack Vulnerability</ref></refs><vuln_soft><prod name="Broker FTP Server" vendor="TransSoft"><vers num="4.0"/><vers num="3.0"/><vers num="3.0 Build 1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-1117" published="2001-01-09" seq="2000-1117" severity="Medium" type="CVE"><desc><descript source="cve">The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1994">BID 1994</ref><ref source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0341.htm">BUGTRAQ:20001124 Security Hole in ECL Feature of Java VM Embedded in Lotus Notes Client R5</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0341.html">20001124 Security Hole in ECL Feature of Java VM Embedded in Lotus Notes Client R5</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="R5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1118" published="2001-01-09" seq="2000-1118" severity="High" type="CVE"><desc><descript source="cve">24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as &quot;/+/&quot; or &quot;/.&quot; to the HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0369.html">BUGTRAQ:20001127 24Link Webserver</ref></refs><vuln_soft><prod name="24Link" vendor="24Link"><vers num="1.06"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1119" published="2001-01-09" seq="2000-1119" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long &quot;x=&quot; argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2032">BID 2032</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">BUGTRAQ:20001201 Fixed local AIX V43 vulnerabilities</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08812&amp;apar=only">IY08812</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY10721&amp;apar=only">IY10721</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5621">aix-setsenv-bo(5621)</ref><ref source="OSVDB" url="http://www.osvdb.org/1676">1676</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1120" published="2001-01-09" seq="2000-1120" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2033">BID 2033</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">BUGTRAQ:20001201 Fixed local AIX V43 vulnerabilities</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08143&amp;apar=only">IY08143</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08287&amp;apar=only">IY08287</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5620">aix-digest-bo(5620)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1121" published="2001-01-09" seq="2000-1121" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long -M argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2034">BID 2034</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">BUGTRAQ:20001201 Fixed local AIX V43 vulnerabilities</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08143&amp;apar=only">IY08143</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY08287&amp;apar=only">IY08287</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5619">aix-enq-bo(5619)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1122" published="2001-01-09" seq="2000-1122" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in setclock command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a long argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2035">BID 2035</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">BUGTRAQ:20001201 Fixed local AIX V43 vulnerabilities</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY07831&amp;apar=only">IY07831</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY07790&amp;apar=only">IY07790</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1123" published="2001-01-09" seq="2000-1123" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2036">BID 2036</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">BUGTRAQ:20001201 Fixed local AIX V43 vulnerabilities</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY12638&amp;apar=only">IY12638</ref><ref source="XF" url="http://xforce.iss.net/static/5617.php">aix-pioout-bo</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1124" published="2001-01-09" seq="2000-1124" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2037">BID 2037</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97569466809056&amp;w=2">BUGTRAQ:20001201 Fixed local AIX V43 vulnerabilities</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY12638&amp;apar=only">IY12638</ref><ref source="XF" url="http://xforce.iss.net/static/5616.php">aix-piobe-bo(5616)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.3"/><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1125" published="2001-01-09" seq="2000-1125" severity="High" type="CVE"><desc><descript source="cve">restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1914">BID 1914</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97336034309944&amp;w=2">BUGTRAQ:20001104 Redhat 6.2 restore exploit</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2E"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1126" published="2001-01-09" seq="2000-1126" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1954">BID 1954</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/advisories/2850">HP:HPSBUX0011-130</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.4"/><vers num="11.0"/><vers num="10.24"/><vers num="10.20"/><vers num="10.10"/><vers num="10.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1127" published="2001-01-09" seq="2000-1127" severity="Low" type="CVE"><desc><descript source="cve">registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1919">BID 1919</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/143845">BUGTRAQ:20001108 HP-UX 10.20 resource monitor service</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1128" published="2001-01-09" seq="2000-1128" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse &quot;common.exe&quot; program in the C:\Program Files directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1920">BID 1920</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0073.html">NTBUGTRAQ:20001103 Elevation of Privileges Exploit with McAfee VirusScan 4.5</ref></refs><vuln_soft><prod name="VirusScan" vendor="McAfee"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1129" published="2001-01-09" seq="2000-1129" severity="Medium" type="CVE"><desc><descript source="cve">McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1999">BID 1999</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0324.html">BUGTRAQ:20001123 McAfee WebShield SMTP vulnerabilities</ref></refs><vuln_soft><prod name="WebShield SMTP" vendor="Network Associates"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1130" published="2001-01-09" seq="2000-1130" severity="High" type="CVE"><desc><descript source="cve">McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1993">BID:1993</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0324.html">BUGTRAQ:20001123 McAfee WebShield SMTP vulnerabilities</ref></refs><vuln_soft><prod name="WebShield SMTP" vendor="Network Associates"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1131" published="2001-01-09" seq="2000-1131" severity="High" type="CVE"><desc><descript source="cve">Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1940">BID 1940</ref><ref adv="1" source="Security Focus" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0144.html">BUGTRAQ:20001110 [hacksware] gbook.cgi remote command execution vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/5509.php">gbook-cgi-remote-execution</ref></refs><vuln_soft><prod name="GBook.cgi" vendor="Bill Kendrick"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1132" published="2001-01-09" seq="2000-1132" severity="Medium" type="CVE"><desc><descript source="cve">DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed &quot;forum&quot; variable.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1951">BID:1951</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0218.html">BUGTRAQ:20001114 Cgisecurity.com advisory on dcforum</ref><ref source="CONFIRM" url="http://www.dcscripts.com/dcforum/dcfNews/124.html#1">http://www.dcscripts.com/dcforum/dcfNews/124.html#1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5533">dcforum-cgi-view-files(5533)</ref><ref source="OSVDB" url="http://www.osvdb.org/1646">1646</ref></refs><vuln_soft><prod name="DCForum" vendor="DCScripts"><vers num="6.0"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1133" published="2001-01-09" seq="2000-1133" severity="Medium" type="CVE"><desc><descript source="cve">Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1907">BID 1907</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97362374200478&amp;w=2">BUGTRAQ:20001107 Explanation Authentix Input Validation Error</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97353881829760&amp;w=2">20001106 Authentix Security Advisory</ref></refs><vuln_soft><prod name="Authentix" vendor="Flicks Software"><vers num="5.1c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2000-1134" published="2001-01-09" seq="2000-1134" severity="High" type="CVE"><desc><descript source="cve">Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing &lt;&lt; redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2006">BID 2006</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc">FREEBSD:FreeBSD-SA-00:76</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/146657">20001128  /bin/sh creates insecure tmp files</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001111a">20001111a</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-069.php3">MDKSA-2000-069</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-043.0.txt">CSSA-2000-043.0</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-042.0.txt">CSSA-2000-042.0</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-117.html">RHSA-2000:117</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-121.html">RHSA-2000:121</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-075.php3">MDKSA-2000:075</ref><ref source="BID" url="http://www.securityfocus.com/bid/1926">1926</ref><ref source="COMPAQ" url="http://archives.neohapsis.com/archives/tru64/2002-q1/0009.html">SSRT1-41U</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P">20011103-02-P</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/10277">VU#10277</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval4047.html">OVAL4047</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0418.html">20001028 tcsh: unsafe tempfile in &lt;&lt; redirects</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97561816504170&amp;w=2">20001130 [ADV/EXP]: RH6.x root from bash /tmp vuln + MORE</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000354">CLSA-2000:354</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000350">CLA-2000:350</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:4047">oval:org.mitre.oval:def:4047</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/></prod><prod name="OpenLinux eDesktop" vendor="Caldera"><vers num="2.4"/></prod><prod name="OpenLinux Eserver" vendor="Caldera"><vers num="2.3"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0es"/><vers num="4.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.11"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers num="6.2E"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.2"/></prod><prod name="Immunix" vendor="Immunix"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2000-1135" published="2001-01-09" seq="2000-1135" severity="Medium" type="CVE"><desc><descript source="cve">fshd (fsh daemon) in Debian GNU/Linux allows local users to overwrite files of other users via a symlink attack.</descript></desc><sols><sol source="nvd">Note: fixed in potato version</sol></sols><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20001130">DEBIAN:20001130 DSA-002-1 fsh: symlink attack</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5633">linux-fsh-symlink(5633)</ref><ref source="OSVDB" url="http://www.osvdb.org/7208">7208</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2000-1136" published="2001-01-09" seq="2000-1136" severity="Medium" type="CVE"><desc><descript source="cve">elvis-tiny before 1.4-10 in Debian GNU/Linux, and possibly other Linux operating systems, allows local users to overwrite files of other users via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1984">BID 1984</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97502995616099&amp;w=2">BUGTRAQ:20001122 New version of elvis-tiny released</ref><ref source="XF" url="http://xforce.iss.net/static/5632.php">linux-tinyelvis-tmpfiles</ref></refs><vuln_soft><prod name="Elvis tiny" vendor="Debian"><vers num="1.4.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1137" published="2001-01-09" seq="2000-1137" severity="Medium" type="CVE"><desc><descript source="cve">GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2000-123.html">REDHAT:RHSA-2000:123-01</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2095">BID 2095</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001129">20001129 DSA-001-1 ed: symlink attack</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-076.php3">MDKSA-2000:076</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000359">CLA-2000:359-2</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5723">gnu-ed-symlink(5723)</ref><ref source="OSVDB" url="http://www.osvdb.org/6491">6491</ref></refs><vuln_soft><prod name="Ed" vendor="Gnu"><vers num="2.18.0"/><vers num="2.18"/><vers num="2.16tr"/><vers num="2.15"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2000-1138" published="2001-01-09" seq="2000-1138" severity="High" type="CVE"><desc><descript source="cve">Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1925">BID 1925</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97370725220953&amp;w=2">BUGTRAQ:20001108 Lotus Notes R5 clients - no warning for broken signature or encryption</ref></refs><vuln_soft><prod name="Lotus Notes R5" vendor="IBM"><vers num="5.0.5" prev="1"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2000-1139" published="2001-01-09" seq="2000-1139" severity="High" type="CVE"><desc><descript source="cve">The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the &quot;Exchange User Account&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1958">BID 1958</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-088.asp">MS:MS00-088</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5537">ms-exchange-username-pwd(5537)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1140" published="2001-01-09" seq="2000-1140" severity="Low" type="CVE"><desc><descript source="cve">Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they are in a honeypot system by comparing the results from kill commands with the process listing in the /proc filesystem.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1908">BID 1908</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">BUGTRAQ:20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">BUGTRAQ:20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref><ref source="XF" url="http://xforce.iss.net/static/5473.php">mantrap-hidden-processes</ref></refs><vuln_soft><prod name="ManTrap" vendor="Recourse Technologies"><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1141" published="2001-01-09" seq="2000-1141" severity="Low" type="CVE"><desc><descript source="cve">Recourse ManTrap 1.6 modifies the kernel so that &quot;..&quot; does not appear in the /proc listing, which allows attackers to determine that they are in a honeypot system.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">BUGTRAQ:20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">BUGTRAQ:20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref><ref source="XF" url="http://xforce.iss.net/static/5473.php">mantrap-hidden-processes</ref></refs><vuln_soft><prod name="ManTrap" vendor="Recourse Technologies"><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1142" published="2001-01-09" seq="2000-1142" severity="Low" type="CVE"><desc><descript source="cve">Recourse ManTrap 1.6 generates an error when an attacker cd&apos;s to /proc/self/cwd and executes the pwd command, which allows attackers to determine that they are in a honeypot system.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">BUGTRAQ:20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">BUGTRAQ:20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref><ref source="XF" url="http://xforce.iss.net/static/5949.php">mantrap-pwd-reveal-information</ref></refs><vuln_soft><prod name="ManTrap" vendor="Recourse Technologies"><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1143" published="2001-01-09" seq="2000-1143" severity="Low" type="CVE"><desc><descript source="cve">Recourse ManTrap 1.6 hides the first 4 processes that run on a Solaris system, which allows attackers to determine that they are in a honeypot system.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">BUGTRAQ:20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">BUGTRAQ:20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">BUGTRAQ:20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref><ref source="XF" url="http://xforce.iss.net/static/5473.php">mantrap-hidden-processes</ref></refs><vuln_soft><prod name="ManTrap" vendor="Recourse Technologies"><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1144" published="2001-01-09" seq="2000-1144" severity="Low" type="CVE"><desc><descript source="cve">Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting &quot;/&quot; file system is higher than normal, which allows attackers to determine that they are in a chroot environment.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1909">BID 1909</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">BUGTRAQ:20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref source="XF" url="http://xforce.iss.net/static/5472.php">mantrap-inode-disclosure</ref></refs><vuln_soft><prod name="ManTrap" vendor="Recourse Technologies"><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1145" published="2001-01-09" seq="2000-1145" severity="Medium" type="CVE"><desc><descript source="cve">Recourse ManTrap 1.6 allows attackers who have gained root access to use utilities such as crash or fsdb to read /dev/mem and raw disk devices to identify ManTrap processes or modify arbitrary data files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">BUGTRAQ:20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">BUGTRAQ:20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref><ref source="XF" url="http://xforce.iss.net/static/5950.php">mantrap-identify-processes</ref></refs><vuln_soft><prod name="ManTrap" vendor="Recourse Technologies"><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1146" published="2001-01-09" seq="2000-1146" severity="Low" type="CVE"><desc><descript source="cve">Recourse ManTrap 1.6 allows attackers to cause a denial of service via a sequence of commands that navigate into and out of the /proc/self directory and executing various commands such as ls or pwd.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1913">BID 1913</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0100.html">BUGTRAQ:20001107 Vendor Response Re: Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0041.html">20001102 Mantrap By Recourse Technologies - Fate Advisory (11-01-00)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97349791405580&amp;w=2">20001105 Mantrap Advisory Vendor Followup - Fate Research Labs</ref><ref source="XF" url="http://xforce.iss.net/static/5528.php">mantrap-dir-dos</ref></refs><vuln_soft><prod name="ManTrap" vendor="Recourse Technologies"><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1147" published="2001-01-09" seq="2000-1147" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the &quot;LANGUAGE&quot; argument in a script tag.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1911">BID 1911</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/143070">BUGTRAQ:20001103 IIS ASP $19.95 hack - IISHack 1.5</ref><ref source="XF" url="http://xforce.iss.net/static/5510.php">iis-isapi-asp-bo</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1148" published="2001-01-09" seq="2000-1148" severity="Medium" type="CVE"><desc><descript source="cve">The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1906">BID 1906</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0085.html">BUGTRAQ:20001106 Re: FW: Filesystem Access + VolanoChat = VChat admin (fwd)</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0072.html">BUGTRAQ:20001104 Filesystem Access + VolanoChat = VChat admin (fwd)</ref><ref source="XF" url="http://xforce.iss.net/static/5465.php">volanochatpro-plaintext-password</ref></refs><vuln_soft><prod name="VolanoChatPro" vendor="Volano LLC"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1149" published="2001-01-09" seq="2000-1149" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in RegAPI.DLL used by Windows NT 4.0 Terminal Server allows remote attackers to execute arbitrary commands via a long username, aka the &quot;Terminal Server Login Buffer Overflow&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1924">BID 1924</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-087.asp">MS:MS00-087</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/143991">BUGTRAQ:20001108 [CORE SDI ADVISORY] MS NT4.0 Terminal Server Edition GINA buffer overflow</ref><ref source="XF" url="http://xforce.iss.net/static/5489.php">nt-termserv-gina-bo</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Terminal Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1150" published="2001-01-09" seq="2000-1150" severity="Medium" type="CVE"><desc><descript source="cve">Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html">BUGTRAQ:20001113 beos vulnerabilities</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1946">BID 1946</ref></refs><vuln_soft><prod name="Felix" vendor="Xavier Ducrohet"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1151" published="2001-01-09" seq="2000-1151" severity="Medium" type="CVE"><desc><descript source="cve">Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html">BUGTRAQ:20001113 beos vulnerabilities</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1947">BID 1947</ref></refs><vuln_soft><prod name="Baxter" vendor="ABiSoft"><vers num="Y"/><vers num="X"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1152" published="2001-01-09" seq="2000-1152" severity="Medium" type="CVE"><desc><descript source="cve">Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html">BUGTRAQ:20001113 beos vulnerabilities</ref></refs><vuln_soft><prod name="BeOS" vendor="Be"><vers num="5"/><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1153" published="2001-01-09" seq="2000-1153" severity="Medium" type="CVE"><desc><descript source="cve">PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1943">BID 1943</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html">BUGTRAQ:20001113 beos vulnerabilities</ref></refs><vuln_soft><prod name="Postmaster" vendor="Kenny Carruthers"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1154" published="2001-01-09" seq="2000-1154" severity="Medium" type="CVE"><desc><descript source="cve">RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html">BUGTRAQ:20001113 beos vulnerabilities</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1944">BID 1944</ref></refs><vuln_soft><prod name="RobinHood" vendor="Joe Kloss"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1155" published="2001-01-09" seq="2000-1155" severity="Medium" type="CVE"><desc><descript source="cve">RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html">BUGTRAQ:20001113 beos vulnerabilities</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1944">BID 1944</ref></refs><vuln_soft><prod name="RobinHood" vendor="Joe Kloss"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1156" published="2001-01-09" seq="2000-1156" severity="Low" type="CVE"><desc><descript source="cve">StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1922">BID 1922</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0115.html">BUGTRAQ:20001108 StarOffice 5.2 Temporary Dir Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/5487.php">staroffice-tmp-sym-link</ref></refs><vuln_soft><prod name="StarOffice" vendor="Sun"><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1157" published="2001-01-09" seq="2000-1157" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1901">BID 1901</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html">BUGTRAQ:20001102 Remotely exploitable buffer overflow in NAI&apos;s Distributed Sniffer Agent</ref></refs><vuln_soft><prod name="Sniffer Agent" vendor="Network Associates"><vers num="3.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1158" published="2001-01-09" seq="2000-1158" severity="High" type="CVE"><desc><descript source="cve">NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html">BUGTRAQ:20001102 Remotely exploitable buffer overflow in NAI&apos;s Distributed Sniffer Agent</ref></refs><vuln_soft><prod name="Sniffer Agent" vendor="Network Associates"><vers num="3.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1159" published="2001-01-09" seq="2000-1159" severity="High" type="CVE"><desc><descript source="cve">NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication packets and spoofing commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1902">BID 1902</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html">BUGTRAQ:20001102 Remotely exploitable buffer overflow in NAI&apos;s Distributed Sniffer Agent</ref></refs><vuln_soft><prod name="Sniffer Agent" vendor="Network Associates"><vers num="3.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1160" published="2001-01-09" seq="2000-1160" severity="Medium" type="CVE"><desc><descript source="cve">NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1903">BID 1903</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html">BUGTRAQ:20001102 Remotely exploitable buffer overflow in NAI&apos;s Distributed Sniffer Agent</ref></refs><vuln_soft><prod name="Sniffer Agent" vendor="Network Associates"><vers num="3.0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1161" published="2001-01-09" seq="2000-1161" severity="High" type="CVE"><desc><descript source="cve">The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1969">BID 1969</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0271.html">BUGTRAQ:20001120 security problem in AdCycle installation</ref></refs><vuln_soft><prod name="Adcycle" vendor="Adcycle"><vers num="0.77b"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1162" published="2001-01-09" seq="2000-1162" severity="Low" type="CVE"><desc><descript source="cve">ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1990">BID 1990</ref><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-041.0.txt">CALDERA:CSSA-2000-041</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-074.php3">MDKSA-2000:074</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000343">CLSA-2000:343</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-114.html">RHSA-2000:114</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001123">20001123 ghostscript: symlink attack</ref><ref source="XF" url="http://xforce.iss.net/static/5563.php">ghostscript-sym-link</ref></refs><vuln_soft><prod name="Ghostscript" vendor="Aladdin Enterprises"><vers num="5.50"/><vers num="5.10.15"/><vers num="5.10.10"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1163" published="2001-01-09" seq="2000-1163" severity="Medium" type="CVE"><desc><descript source="cve">ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1991">BID 1991</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20001123">DEBIAN:20001123 ghostscript: symlink attack</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2000-041.0.txt">CSSA-2000-041</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-074.php3">MDKSA-2000:074</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000343">CLSA-2000:343</ref><ref source="XF" url="http://xforce.iss.net/static/5564.php">ghostscript-env-variable</ref></refs><vuln_soft><prod name="Ghostscript" vendor="Aladdin Enterprises"><vers num="5.50"/><vers num="5.10.15"/><vers num="5.10.10"/><vers num="5.10cl"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-15" name="CVE-2000-1164" published="2001-01-09" seq="2000-1164" severity="High" type="CVE"><desc><descript source="cve">WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1961">BID 1961</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0253.html">BUGTRAQ:20001118 WinVNC 3.3.x</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5545">winvnc-modify-registry(5545)</ref></refs><vuln_soft><prod name="WinVNC" vendor="ATT"><vers num="3.3.3"/><vers num="3.3.3r7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2000-1165" published="2001-01-09" seq="2000-1165" severity="Medium" type="CVE"><desc><descript source="cve">Balabit syslog-ng allows remote attackers to cause a denial of service (application crash) via a malformed log message that does not have a closing &gt; in the priority specifier.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1981">BID 1981</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0300.html">BUGTRAQ:20001122 DoS possibility in syslog-ng</ref><ref source="CONFIRM" url="http://www.balabit.hu/products/syslog-ng/">http://www.balabit.hu/products/syslog-ng/</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:02.syslog-ng.asc">FreeBSD-SA-01:02</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5576">balabit-syslog-ng-dos(5576)</ref></refs><vuln_soft><prod name="syslog-ng" vendor="Balabit"><vers num="1.4.8"/><vers num="1.4.7"/><vers num="1.4.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2000-1166" published="2001-01-09" seq="2000-1166" severity="High" type="CVE"><desc><descript source="cve">Twig webmail system does not properly set the &quot;vhosts&quot; variable if it is not configured on the site, which allows remote attackers to insert arbitrary PHP (PHP3) code by specifying an alternate vhosts as an argument to the index.php3 program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1998">BID 1998</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0351.html">BUGTRAQ:20001124 Security problems with TWIG webmail system</ref><ref source="CONFIRM" url="http://twig.screwdriver.net/file.php3?file=CHANGELOG">http://twig.screwdriver.net/file.php3?file=CHANGELOG</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5581">twig-php3-script-execute(5581)</ref></refs><vuln_soft><prod name="Twig" vendor="TWIG Development Team"><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1167" published="2001-01-09" seq="2000-1167" severity="High" type="CVE"><desc><descript source="cve">ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the &quot;nat deny_incoming&quot; command, which allows remote attackers to connect to the target system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1974">BID 1974</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:70.ppp-nat.asc">FreeBSD-SA-00:70</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5584">freebsd-ppp-bypass-gateway(5584)</ref><ref source="OSVDB" url="http://www.osvdb.org/1655">1655</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1.1 Stable"/><vers num="4.1"/><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2000-1168" published="2001-01-09" seq="2000-1168" severity="High" type="CVE"><desc><descript source="cve">IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1988">BID 1988</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97502498610979&amp;w=2">BUGTRAQ:20001123 IBM HTTP Server 1.3.6 Remote Overflow</ref></refs><vuln_soft><prod name="IBM HTTP Server" vendor="IBM"><vers num="1.3.6.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1169" published="2001-01-09" seq="2000-1169" severity="High" type="CVE"><desc><descript source="cve">OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0195.html">BUGTRAQ:20001123 OpenSSH Security Advisory (adv.fwd)</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-068.php3">MDKSA-2000:068</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0217.html">20001115 Trustix Security Advisory - bind and openssh (and modutils)</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001118">20001118 openssh: possible remote exploit</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000345">CLSA-2000:345</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-111.html">RHSA-2000:111</ref><ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2000-Nov/0004.html">SuSE-SA:2000:47</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5517">openssh-unauthorized-access(5517)</ref><ref source="OSVDB" url="http://www.osvdb.org/2114">2114</ref><ref source="OSVDB" url="http://www.osvdb.org/6248">6248</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1949">BID 1949</ref></refs><vuln_soft><prod name="OpenSSH" vendor="OpenBSD"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1170" published="2001-01-09" seq="2000-1170" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Netsnap webcam HTTP server before 1.2.9 allows remote attackers to execute arbitrary commands via a long GET request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1956">BID 1956</ref><ref adv="1" patch="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97439536016554&amp;w=2">BUGTRAQ:20001115 Netsnap Webcam Software Remote Overflow</ref><ref source="CONFIRM" url="http://www.netsnap.com/new.htm">http://www.netsnap.com/new.htm</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5534">netsnap-remote-bo(5534)</ref></refs><vuln_soft><prod name="NetSnap" vendor="PeleSoft"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2000-1171" published="2001-01-09" seq="2000-1171" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in the &quot;thesection&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1963">BID 1963</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0263.html">BUGTRAQ:20001120 CGIForum 1.0 Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5553">cgiforum-view-files(5553)</ref></refs><vuln_soft><prod name="CGIForum" vendor="Markus Triska"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1172" published="2001-01-09" seq="2000-1172" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Gaim 0.10.3 and earlier using the OSCAR protocol allows remote attackers to conduct a denial of service and possibly execute arbitrary commands via a long HTML tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1948">BID 1948</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0204.html">BUGTRAQ:20001110 Advisory: Gaim remote vulnerability</ref></refs><vuln_soft><prod name="Gaim" vendor="Rob Flynn"><vers num="0.10.3"/><vers num="0.10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1173" published="2001-01-09" seq="2000-1173" severity="Medium" type="CVE"><desc><descript source="cve">Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1977">BID 1977</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0323.html">BUGTRAQ:20001122 CyberPatrol - poor credit card protection</ref></refs><vuln_soft><prod name="CyberPatrol" vendor="Microsys"><vers num="4.04.005"/><vers num="4.04.003"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-1174" published="2001-01-09" seq="2000-1174" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary commands via a packet with a long username.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1972">BID 1972</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0251.html">20001118 [hacksware] Ethereal 0.8.13 AFS ACL parsing buffer overflow bug</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001122a">20001121 ethereal: remote exploit</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000342">CLSA-2000:342</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-116.html">RHSA-2000:116</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:81.ethereal.asc">FreeBSD-SA-00:81</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5557">ethereal-afs-bo(5557)</ref></refs><vuln_soft><prod name="Ethereal" vendor="Ethereal Group"><vers num="0.8.13" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1175" published="2001-01-09" seq="2000-1175" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1967">BID 1967</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/145823">BUGTRAQ:20001120 local exploit for linux&apos;s Koules1.4 package</ref></refs><vuln_soft><prod name="Koules" vendor="Jan Hubicka"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1176" published="2001-01-09" seq="2000-1176" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the &quot;catsearch&quot; form field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1921">BID 1921</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0110.html">BUGTRAQ:20001107 Insecure input balidation in YaBB Search.pl</ref></refs><vuln_soft><prod name="YaBB" vendor="YaBB"><vers num="2000-09-11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1177" published="2001-01-09" seq="2000-1177" severity="Medium" type="CVE"><desc><descript source="cve">bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID&apos;s by specifying the target file in the HISTFILE parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1971">BID 1971</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0284.html">BUGTRAQ:20001121 Big Brother Advisory - Fate Research Labs</ref><ref source="CONFIRM" url="http://bb4.com/incident.nov21">http://bb4.com/incident.nov21</ref></refs><vuln_soft><prod name="Big Brother Network Monitor" vendor="BB4"><vers num="1.5d2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1178" published="2001-01-09" seq="2000-1178" severity="Low" type="CVE"><desc><descript source="cve">Joe text editor follows symbolic links when creating a rescue copy called DEADJOE during an abnormal exit, which allows local users to overwrite the files of other users whose joe session crashes.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1959">BID 1959</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0227.html">BUGTRAQ:20001116 Joe&apos;s Own Editor File Link Vulnerability</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-110.html">RHSA-2000:110</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-072.php3">MDKSA-2000:072</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000356">CLA-2000:356</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001201">20001201 DSA-003-1 joe: symlink attack</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97500174210821&amp;w=2">20001121 Immunix OS Security update for joe</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5546">joe-symlink-corruption(5546)</ref></refs><vuln_soft><prod name="joe" vendor="Joseph Allen"><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1179" published="2001-01-09" seq="2000-1179" severity="Medium" type="CVE"><desc><descript source="cve">Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1952">BID 1952</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97440068130051&amp;w=2">BUGTRAQ:20001115 Netopia ISDN Router 650-ST: Viewing of all system logs without login</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5536">netopia-view-system-log(5536)</ref></refs><vuln_soft><prod name="650-ST ISDN Router" vendor="Netopia"><vers num="3.3.2 firmware"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2000-1180" published="2001-01-09" seq="2000-1180" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1968">BID 1968</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97474521003453&amp;w=2">BUGTRAQ:20001120 vulnerability in Connection Manager Control binary in Oracle</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5551">oracle-cmctl-bo(5551)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-01-05" name="CVE-2000-1181" published="2001-01-09" seq="2000-1181" severity="Medium" type="CVE"><desc><descript source="cve">Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer&apos;s memory contents, possibly including sensitive information, by accessing the /admin/includes/ URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1957">BID 1957</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0236.html">BUGTRAQ:20001116 [CORE SDI ADVISORY] RealServer memory contents disclosure</ref><ref source="CONFIRM" url="http://service.real.com/help/faq/security/memory.html">http://service.real.com/help/faq/security/memory.html</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5538">realserver-gain-access(5538)</ref></refs><vuln_soft><prod name="RealServer" vendor="RealNetworks"><vers num="7.0"/><vers num="6.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1182" published="2001-01-09" seq="2000-1182" severity="Medium" type="CVE"><desc><descript source="cve">WatchGuard Firebox II allows remote attackers to cause a denial of service by flooding the Firebox with a large number of FTP or SMTP requests, which disables proxy handling.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1953">BID 1953</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0224.html">BUGTRAQ:20001116 Possible Watchguard Firebox II DoS</ref><ref source="" url="https://www.watchguard.com/support/patches.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5535">watchguard-firebox-ftp-dos(5535)</ref></refs><vuln_soft><prod name="Firebox II" vendor="WatchGuard"><vers num="4.5"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1183" published="2001-01-09" seq="2000-1183" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0219.html">BUGTRAQ:20001115 socks5 remote exploit / linux x86</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/154">BID 154</ref></refs><vuln_soft><prod name="socks5" vendor="NEC"><vers num="1.0r5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1184" published="2001-01-09" seq="2000-1184" severity="Medium" type="CVE"><desc><descript source="cve">telnetd in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service by specifying an arbitrary large file in the TERMCAP environmental variable, which consumes resources as the server processes the file.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:69.telnetd.v1.1.asc">FREEBSD:FreeBSD-SA-00:69</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5959">telnetd-termcap-dos(5959)</ref><ref source="OSVDB" url="http://www.osvdb.org/6083">6083</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.0"/><vers num="3.5.1 Stable"/><vers num="4.0"/><vers num="4.1"/><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1185" published="2001-01-09" seq="2000-1185" severity="Medium" type="CVE"><desc><descript source="cve">The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1938">BID 1938</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0201.html">BUGTRAQ:20001113 Rideway PN Telnet DoS</ref></refs><vuln_soft><prod name="RideWayPN" vendor="ITServ Incorporated"><vers num="6.22"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1186" published="2001-01-09" seq="2000-1186" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0221.html">BUGTRAQ:20001115 Exploit: phf buffer overflow (CGI)</ref><ref source="XF" url="http://xforce.iss.net/static/5970.php">phf-cgi-bo(5970)</ref></refs><vuln_soft><prod name="phf" vendor="phf"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1187" published="2001-01-09" seq="2000-1187" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:66.netscape.asc">FREEBSD:FreeBSD-SA-00:66</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-109.html">REDHAT:RHSA-2000:109-05</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000344">CLSA-2000:344</ref><ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2000-Nov/0005.html">SuSE-SA:2000:48</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97500270012529&amp;w=2">20001121 Immunix OS Security update for netscape</ref><ref source="XF" url="http://xforce.iss.net/static/5542.php">netscape-client-html-bo</ref><ref source="OSVDB" url="http://www.osvdb.org/7207">7207</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.75" prev="1"/></prod><prod name="Navigator" vendor="Netscape"><vers num="4.75" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-25" name="CVE-2000-1188" published="2001-01-09" seq="2000-1188" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Quikstore shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the &quot;page&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0283.html">BUGTRAQ:20001120 Cgisecurity Quickstore Shopping cart</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2049">BID 2049</ref></refs><vuln_soft><prod name="Quikstore" vendor="I-Soft"><vers num="2.9.5"/><vers num="2.9.10"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2000-1189" published="2001-01-09" seq="2000-1189" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in pam_localuser PAM module in Red Hat Linux 7.x and 6.x allows attackers to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2000-120.html">REDHAT:RHSA-2000:120</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000358">CLA-2000:358</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-082.php3">MDKSA-2000:082-1</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5747">pam-localuser-bo(5747)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/><vers edition="i386" num="6.1"/><vers edition="i386" num="6.2"/><vers edition="i386" num="7.0"/><vers edition="Alpha" num="6.0"/><vers edition="Sparc" num="6.0"/><vers edition="Alpha" num="6.1"/><vers edition="Sparc" num="6.1"/><vers edition="Alpha" num="6.2"/><vers edition="Sparc" num="6.2"/><vers edition="Alpha" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1190" published="2001-08-31" seq="2000-1190" severity="Low" type="CVE"><desc><descript source="cve">imwheel-solo in imwheel package allows local users to modify arbitrary files via a symlink attack from the .imwheelrc file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/powertools/RHSA-2000-016-03.html">RHSA-2000:016-03</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95984116811100&amp;w=2">20000531 Re: strike#2</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-016.html">RHSA-2000:016</ref><ref source="XF" url="http://www.iss.net/security_center/static/4941.php">linux-imwheel-symlink(4941)</ref></refs><vuln_soft><prod name="IMWheel" vendor="Jon Atkins"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1191" published="2001-08-31" seq="2000-1191" severity="Medium" type="CVE"><desc><descript source="cve">htsearch program in htDig 3.2 beta, 3.1.6, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="MISC" url="http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html">http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/4366">4366</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7367">htdig-htsearch-path-disclosure(7367)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1192" published="2001-08-31" seq="2000-1192" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="SecuriTeam" url="http://www.securiteam.com/windowsntfocus/5ZP0C000KC.html"></ref><ref adv="1" source="BTT Software" url="http://www.bttsoftware.co.uk/snmptrap.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=985">bid985</ref><ref source="BID" url="http://www.securityfocus.com/bid/985">985</ref></refs><vuln_soft><prod name="SNMP Trap Watcher" vendor="BTT Software"><vers num="1.16"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1193" published="2001-08-31" seq="2000-1193" severity="Medium" type="CVE"><desc><descript source="cve">Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial of service (resource exhaustion) via an extremely long string to the PMCD port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="NT Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0056.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4284.php">irix-pcp-pmcd-dos(4284)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20020407-01-I">20020407-01-I</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.4"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-1194" published="2001-08-31" seq="2000-1194" severity="High" type="CVE"><desc><descript source="cve">Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1227">bid1227</ref><ref source="MISC" url="http://www.mdma.za.net/fk/FK9.zip">http://www.mdma.za.net/fk/FK9.zip</ref></refs><vuln_soft><prod name="FTP Server" vendor="ArGoSoft"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2000-1195" published="2001-08-31" seq="2000-1195" severity="High" type="CVE"><desc><descript source="cve">telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Caldera" url="http://www.caldera.com/support/security/advisories/CSSA-2000-008.0.txt">CSSA-2000-008.0</ref><ref source="XF" url="http://xforce.iss.net/static/4225.php">telnetd-login-bypass(4225)</ref></refs><vuln_soft><prod name="OpenLinux Edesktop" vendor="Caldera"><vers num="2.3"/></prod><prod name="OpenLinux Eserver" vendor="Caldera"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1196" published="2001-08-31" seq="2000-1196" severity="Medium" type="CVE"><desc><descript source="cve">PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="iPlanet" url="http://docs.iplanet.com/docs/manuals/pubx/2.5.2_Relnotes.html"></ref><ref adv="1" source="PacketStormSecurity" url="http://packetstormsecurity.org/0004-exploits/ooo1.txt"></ref><ref source="XF" url="http://xforce.iss.net/static/7362.php">publishingxpert-pscoerrpage-url(7362)</ref></refs><vuln_soft><prod name="PublishingXpert" vendor="Netscape"><vers edition="SP2" num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1197" published="2001-08-31" seq="2000-1197" severity="Low" type="CVE"><desc><descript source="cve">POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95624629924545&amp;w=2"></ref><ref source="" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:15.imap-uw.asc"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=1132">bid1132</ref><ref source="BID" url="http://www.securityfocus.com/bid/1132">1132</ref></refs><vuln_soft><prod name="imap" vendor="University of Washington"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1198" published="2001-08-31" seq="2000-1198" severity="Low" type="CVE"><desc><descript source="cve">qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95634229925906&amp;w=2"></ref><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95624629924545&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/vdb/bottom.html?vid=1132">bid1132</ref><ref source="BID" url="http://www.securityfocus.com/bid/1132">1132</ref></refs><vuln_soft><prod name="Qpopper" vendor="Qualcomm"><vers num="3.0"/><vers num="2.53"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1199" published="2001-08-31" seq="2000-1199" severity="Medium" type="CVE"><desc><descript source="cve">PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95659987018649&amp;w=2"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4364.php">postgresql-plaintext-passwords(4364)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1139">bid1139</ref></refs><vuln_soft><prod name="PostgreSQL" vendor="PostgreSQL"><vers num="6.5.3"/><vers num="6.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-2000-1200" published="2001-08-31" seq="2000-1200" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT allows remote attackers to list all users in a domain by obtaining the domain SID with the LsaQueryInformationPolicy policy function via a null session and using the SID to list the users.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/44430"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4015.php">nt-lsa-domain-sid(4015)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/959">bid959</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-01-04" name="CVE-2000-1201" published="2001-08-31" seq="2000-1201" severity="Medium" type="CVE"><desc><descript source="cve">Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-07/0085.html">CheckPoint FW1 BUG (fwd)</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1202" published="2001-08-31" seq="2000-1202" severity="High" type="CVE"><desc><descript source="cve">ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user&apos;s own CLASSPATH directories before the system&apos;s directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/54073"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1092">bid1092</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/4235.php">ibm-ikeyman(4235)</ref></refs><vuln_soft><prod name="IBMHSSSB" vendor="IBM"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2000-1203" published="2001-08-20" seq="2000-1203" severity="Medium" type="CVE"><desc><descript source="cve">Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/3212">Lotus Domino Mail Loop Denial of Service Vulnerability</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=vuln-dev&amp;m=95886062521327&amp;w=2"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/7012">Lotus Domino SMTP server bounced message loop denial of service</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/cgi-bin/archive.pl?id=1&amp;start=2002-01-21&amp;end=2002-01-27&amp;mid=209116&amp;threads=1">20010820 Lotus Domino DoS</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/209754">20010823 Lotus Domino DoS solution</ref></refs><vuln_soft><prod name="Domino" vendor="Lotus"><vers num="4.6.1"/><vers num="4.6.3"/><vers num="4.6.4"/><vers num="5.0.1"/><vers num="5.0.2"/><vers num="5.0.3"/><vers num="5.0.4"/><vers num="5.0.5"/><vers num="5.0.6"/><vers num="5.0.7"/><vers num="5.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1204" published="2000-10-13" seq="2000-1204" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Apache Week" url="http://www.apacheweek.com/issues/00-10-13">Security vulnerability in mod_rewrite</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.9"/><vers num="1.3.11"/><vers num="1.3.12"/></prod></vuln_soft></entry><entry CVSS_base_score="4.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="2.9" CVSS_score="4.3" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2000-1205" published="2000-02-01" seq="2000-1205" severity="Medium" type="CVE"><desc><descript source="cve">Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code.  NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache.  The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.</descript></desc><loss_types><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Apache" url="http://httpd.apache.org/info/css-security/apache_specific.html"></ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2002-12/0233.html">20021222 &apos;printenv&apos; XSS vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/10938">apache-printenv-xss(10938)</ref><ref source="BUGTRAQ" url="http://archive.cert.uni-stuttgart.de/bugtraq/2002/12/msg00243.html">20021223 Re: &apos;printenv&apos; XSS vulnerability</ref><ref source="BUGTRAQ" url="http://marc.info/?l=bugtraq&amp;m=118529436424127&amp;w=2">20070724 printenv.pl(all versions) cross site scripting Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/35597">apache-printenv-acuparam-xss(35597)</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.0"/><vers num="1.3.1"/><vers num="1.3.2"/><vers num="1.3.3"/><vers num="1.3.4"/><vers num="1.3.5"/><vers num="1.3.6"/><vers num="1.3.7"/><vers num="1.3.8"/><vers num="1.3.9"/><vers num="1.3.10"/><vers num="1.3.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1206" published="1999-08-20" seq="2000-1206" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Apache Week" url="http://www.apacheweek.com/issues/00-01-07status"></ref><ref source="CONFIRM" url="http://www.apacheweek.com/issues/00-01-07#status">http://www.apacheweek.com/issues/00-01-07#status</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3.9"/><vers num="1.3.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1207" published="2000-09-30" seq="2000-1207" severity="High" type="CVE"><desc><descript source="cve">userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97034397026473&amp;w=2">glibc and userhelper - local root</ref><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2000-075.html">Updated usermode packages available</ref><ref adv="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3">MandrakeSoft Update Advisory MDKSA-2000:059 : usermode</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97063854808796&amp;w=2">20001003 SuSE: userhelper/usermode</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2000-1208" published="2002-08-12" seq="2000-1208" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2000-066.html">lpr has a format string security bug, LPRng compat issues, and a race cond</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/5286.php">lpr-checkremote-format-string(5286)</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/1711">bid 1711</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/137555">20001004 Immunix OS Security Update for lpr</ref><ref source="BID" url="http://www.securityfocus.com/bid/1711">1711</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96994604300675&amp;w=2">20000925 Format strings: bug #1: BSD-lpr</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.7"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.4"/><vers num="1.4.1"/><vers num="1.4.2"/></prod><prod name="Immunix" vendor="Immunix"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1209" published="2002-08-12" seq="2000-1209" severity="High" type="CVE"><desc><descript source="cve">The &quot;sa&quot; account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers to gain privileges, as exploited by worms such as Voyager Alpha Force and Spida.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.kb.cert.org/vuls/id/635463">Microsoft SQL Server and Microsoft Data Engine (MSDE) ship with a null default password</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/4797">bid 4797</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/1459.php">mssql-no-sapassword(1459)</ref><ref source="BUGTRAQ" url="http://security-archive.merton.ox.ac.uk/bugtraq-200008/0233.html">20000815 MS-SQL &apos;sa&apos; user exploit code</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q313418">Q313418</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;EN-US;q321081">Q321081</ref><ref source="CONFIRM" url="http://www.microsoft.com/security/security_bulletins/ms02020_sql.asp">http://www.microsoft.com/security/security_bulletins/ms02020_sql.asp</ref><ref source="BID" url="http://www.securityfocus.com/bid/4797">4797</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96333895000350&amp;w=2">20000710 MSDE / Re: Default Password Database</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96593218804850&amp;w=2">20000810 Tumbleweed Worldsecure (MMS) BLANK &apos;sa&apos; account password</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=96644570412692&amp;w=2">20000816 Released Patch: Tumbleweed Worldsecure (MMS) BLANK &apos;sa&apos; account password</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/273639">20020522 Opty-Way Enterprise includes MSDE with sa &lt;blank&gt;</ref><ref source="OSVDB" url="http://www.osvdb.org/3570">3570</ref></refs><vuln_soft><prod name="MSDE" vendor="Microsoft"><vers num="1.0"/></prod><prod name="Insight Manager" vendor="Compaq"><vers num="7.0 SP1"/><vers num="7.0"/></prod><prod name="Insight Manager XE" vendor="Compaq"><vers num="1.1"/><vers num="1.21"/><vers num="2.1c"/><vers num="2.1b"/><vers num="2.1"/><vers num="2.2"/></prod><prod name="SQL Server Desktop Engine" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1210" published="2002-03-22" seq="2000-1210" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/4205.php">apache-tomcat-file-contents(4205)</ref><ref adv="1" source="The Aims Group" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95371672300045&amp;w=2"></ref></refs><vuln_soft><prod name="Tomcat" vendor="Apache Software Foundation"><vers num="3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1211" published="2000-12-16" seq="2000-1211" severity="High" type="CVE"><desc><descript source="cve">Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3">MDKSA-2000:083</ref><ref adv="1" patch="1" source="Zope" url="http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-125.html">RHSA-2000:125</ref><ref source="XF" url="http://www.iss.net/security_center/static/5824.php">zope-legacy-names(5824)</ref><ref source="OSVDB" url="http://www.osvdb.org/6282">6282</ref></refs><vuln_soft><prod name="Zope" vendor="Zope"><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1b1"/><vers num="2.2.1"/><vers num="2.2.0b4"/><vers num="2.2.0b3"/><vers num="2.2.0b2"/><vers num="2.2.0b1"/><vers num="2.2.0a1"/><vers num="2.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2000-1212" published="2000-12-18" seq="2000-1212" severity="Medium" type="CVE"><desc><descript source="cve">Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Zope" url="http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert"></ref><ref adv="1" source="RedHat" url="http://rhn.redhat.com/errata/RHSA-2000-135.html">RHSA-2000:135</ref><ref adv="1" source="Security Focus" url="http://www.iss.net/security_center/static/5778.php">zope-image-file(5778)</ref><ref source="MANDRAKE" url="http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:086">MDKSA-2000:086</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000365">CLA-2000:365</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-007">DSA-007</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-135.html">RHSA-2000:135</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5778">zope-image-file(5778)</ref><ref source="OSVDB" url="http://www.osvdb.org/6283">6283</ref></refs><vuln_soft><prod name="Zope" vendor="Zope"><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2.1b1"/><vers num="2.2.1"/><vers num="2.2.0b4"/><vers num="2.2.0b3"/><vers num="2.2.0b2"/><vers num="2.2.0b1"/><vers num="2.2.0a1"/><vers num="2.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2000-1213" published="2000-10-18" seq="2000-1213" severity="High" type="CVE"><desc><descript source="cve">ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping&apos;s exposure to bugs that otherwise would occur at lower privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-087.html">RHSA-2000:087</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97249980727834&amp;w=2">20001025 Immunix OS Security Update for ping package</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97292944103571&amp;w=2">20001030 Trustix Security Advisory - ping gnupg ypbind</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html">20001030 Trustix Security Advisory - ping gnupg ypbind</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers num="7.0"/></prod><prod name="iputils" vendor="iputils"><vers num="2000-10-10" prev="1"/></prod><prod name="Immunix" vendor="Immunix"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2000-1214" published="2000-10-18" seq="2000-1214" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/1813">RedHat Linux ping Buffer Overflow Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/5431.php">ping-buf-bo(5431)</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-087.html">RHSA-2000:087-02</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97249980727834&amp;w=2">20001025 Immunix OS Security Update for ping package</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97208562830613&amp;w=2">20001020 Re: [RHSA-2000:087-02] Potential security problems in ping fixed.</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97292944103571&amp;w=2">20001030 Trustix Security Advisory - ping gnupg ypbind</ref><ref source="BID" url="http://www.securityfocus.com/bid/1813">1813</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-10/0429.html">20001030 Trustix Security Advisory - ping gnupg ypbind</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers num="7.0"/></prod><prod name="iputils" vendor="iputils"><vers num="2000-10-10" prev="1"/></prod><prod name="Immunix" vendor="Immunix"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1215" published="2001-09-19" seq="2000-1215" severity="Medium" type="CVE"><desc><descript source="cve">The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-09/0166.html">20010919 lotus domino server 5.08 is very gabby</ref><ref source="CONFIRM" url="http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/5552251934afaa9585256c0000737a7f?OpenDocument&amp;Highlight=0,AWHN4A8QWM">http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/5552251934afaa9585256c0000737a7f?OpenDocument&amp;Highlight=0,AWHN4A8QWM</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/984555">VU#984555</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/10685">lotus-domino-information-disclosure(10685)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=100094373621813&amp;w=2">20010919 lotus domino server 5.08 is very gabby</ref></refs><vuln_soft><prod name="Lotus Domino" vendor="IBM"><vers num="5.0.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1216" published="2000-01-27" seq="2000-1216" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref source="AIXAPAR" url="http://www-1.ibm.com/support/docview.wss?uid=isg1IY07832">IY07832</ref><ref patch="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/433499">VU#433499</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/7929">aix-portmir-echoerror-bo(7929)</ref></refs></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1217" published="2000-11-21" seq="2000-1217" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows 2000 before Service Pack 2 (SP2), when running in a non-Windows 2000 domain and using NTLM authentication, and when credentials of an account are locally cached, allows local users to bypass account lockout policies and make an unlimited number of login attempts, aka the &quot;Domain Account Lockout&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS00-089.mspx">MS00-089</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/818496">VU#818496</ref><ref source="BID" url="http://www.securityfocus.com/bid/1973">Microsoft Windows 2000 Domain Account Lockout Bypass Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5585">win2k-brute-force(5585)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Advanced Server SP1"/><vers num="Professional SP1"/><vers num="Server SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1218" published="2000-04-14" seq="2000-1218" severity="High" type="CVE"><desc><descript source="cve">The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000, and XP sets the QueryIpMatching parameter to 0, which causes Windows to accept DNS updates from hosts that it did not query, which allows remote attackers to poison the DNS cache.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/458659">VU#458659</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/4280">win2k-dns-resolver(4280)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="Gold"/><vers num="SE"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP6a alpha"/><vers num="4.0 SP6a"/><vers num="4.0 SP6 alpha"/><vers num="4.0 SP6"/><vers num="4.0 SP5 alpha"/><vers num="4.0 SP5"/><vers num="4.0 SP4 alpha"/><vers num="4.0 SP4"/><vers num="4.0 SP3 alpha"/><vers num="4.0 SP3"/><vers num="4.0 SP2 alpha"/><vers num="4.0 SP2"/><vers num="4.0 SP1 alpha"/><vers num="4.0 SP1"/><vers num="4.0 alpha"/><vers num="4.0"/></prod><prod name="Windows XP" vendor="Microsoft"><vers edition="SP2" num="Home"/><vers edition="SP1" num="Home"/><vers num="Home"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="Gold" num="Professional"/><vers edition="SP2" num="Media Center"/><vers edition="SP1" num="Media Center"/><vers num="Media Center"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Professional SP4"/><vers num="Professional SP3"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1219" published="2000-11-01" seq="2000-1219" severity="High" type="CVE"><desc><descript source="cve">The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="MLIST" url="http://gcc.gnu.org/ml/gcc-bugs/2002-05/msg00198.html">[gcc-bugs] 20020506 c/6586: -ftrapv doesnt catch multiplication overflow</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/540517">VU#540517</ref></refs><vuln_soft><prod name="gcc" vendor="Gnu"><vers num="3.3.3" prev="1"/></prod><prod name="g++" vendor="Gnu"><vers num="3.3.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1220" published="2000-01-08" seq="2000-1220" severity="High" type="CVE"><desc><descript source="cve">The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://seclists.org/lists/bugtraq/2000/Jan/0116.html">20000108 L0pht Advisory: LPD, RH 4.x,5.x,6.x</ref><ref adv="1" source="L0PHT" url="http://www.atstake.com/research/advisories/2000/lpd_advisory.txt">20000108 Quadruple Inverted Backflip</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20000109">20000109 lpr -- access control problem and root exploit</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-002.html">RHSA-2000:002</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P">20021104-01-P</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/39001">VU#39001</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/927">Multiple Vendor lpd Vulnerabilities</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3841">redhat-lpd-print-control(3841)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.0"/><vers num="4.1"/><vers num="4.2"/><vers num="5.0"/><vers num="5.1"/><vers edition="i386" num="5.2"/><vers num="6.0"/><vers edition="i386" num="6.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/><vers num="6.5.4"/><vers num="6.5.5"/><vers num="6.5.6"/><vers num="6.5.7"/><vers num="6.5.8"/><vers num="6.5.9"/><vers num="6.5.10"/><vers num="6.5.11"/><vers num="6.5.12"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.18m"/><vers num="6.5.18f"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1221" published="2000-01-08" seq="2000-1221" severity="High" type="CVE"><desc><descript source="cve">The line printer daemon (lpd) in the lpr package in multiple Linux operating systems authenticates by comparing the reverse-resolved hostname of the local machine to the hostname of the print server as returned by gethostname, which allows remote attackers to bypass intended access controls by modifying the DNS for the attacking IP.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="L0PHT" url="http://www.atstake.com/research/advisories/2000/lpd_advisory.txt">20000108 Quadruple Inverted Backflip</ref><ref patch="1" source="DEBIAN" url="http://www.debian.org/security/2000/20000109">20000109 lpr -- access control problem and root exploit</ref><ref source="REDHAT" url="http://rhn.redhat.com/errata/RHSA-2000-002.html">RHSA-2000:002</ref><ref patch="1" source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20021104-01-P">20021104-01-P</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/30308">VU#30308</ref><ref source="BID" url="http://www.securityfocus.com/bid/0927">927</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3840">redhat-lpd-auth(3840)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.1"/><vers num="4.2"/><vers num="5.0"/><vers edition="i386" num="5.2"/><vers num="6.0"/><vers edition="i386" num="6.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.5"/><vers num="6.5.1"/><vers num="6.5.2"/><vers num="6.5.3"/><vers num="6.5.4"/><vers num="6.5.5"/><vers num="6.5.6"/><vers num="6.5.7"/><vers num="6.5.8"/><vers num="6.5.9"/><vers num="6.5.10"/><vers num="6.5.11"/><vers num="6.5.12"/><vers num="6.5.13"/><vers num="6.5.14m"/><vers num="6.5.14f"/><vers num="6.5.15m"/><vers num="6.5.15f"/><vers num="6.5.16m"/><vers num="6.5.16f"/><vers num="6.5.17m"/><vers num="6.5.17f"/><vers num="6.5.18m"/><vers num="6.5.18f"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1222" published="2000-12-10" seq="2000-1222" severity="High" type="CVE"><desc><descript source="cve">AIX sysback before 4.2.1.13 uses a relative path to find and execute the hostname program, which allows local users to gain privileges by modifying the path to point to a malicious hostname program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/17566">VU#17566</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/6432">aix-sysback-elevate-privileges(6432)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1223" published="2000-11-20" seq="2000-1223" severity="High" type="CVE"><desc><descript source="cve">quikstore.cgi in Quikstore Shopping Cart allows remote attackers to execute arbitrary commands via shell metacharacters in the URL portion of an HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/671444">VU#671444</ref></refs><vuln_soft><prod name="Quikstore" vendor="I-Soft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1224" published="2000-11-23" seq="2000-1224" severity="Medium" type="CVE"><desc><descript source="cve">Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .jsp file with certain characters appended to the file name, such as (1) &quot;..&quot;, (2) &quot;%2e..&quot;, (3) &quot;%81&quot;, (4) &quot;%82&quot;, and others.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97502269408279&amp;w=2">20001123 RESIN ServletExec JSP Source Disclosure Vulnerability(Apache 1.3.6 Win2k))</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/146770">20001123 Re: RESIN ServletExec JSP Source Disclosure Vulnerability(Apache 1.3.6 Win2k))</ref><ref adv="1" source="BID" url="http://www.securityfocus.com/bid/1986">1986</ref><ref adv="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/5568">resin-jsp-source-disclosure(5568)</ref></refs><vuln_soft><prod name="Resin" vendor="Caucho Technology"><vers num="1.2"/><vers num="1.1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1225" published="2000-12-31" seq="2000-1225" severity="Medium" type="CVE"><desc><descript source="cve">Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0109.html">Xitami Web/Ftp Server Multiple Security Vulnerabilities - NSSI Advisory [1st Vulnerability]</ref></refs><vuln_soft><prod name="Xitami" vendor="Imatix"><vers num="2.5 b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1226" published="2000-12-31" seq="2000-1226" severity="Medium" type="CVE"><desc><descript source="cve">Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0122.html">20000614 Snort 1.6 and nmap 2.54beta1</ref><ref adv="1" patch="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0126.html">20000614 Re: Snort 1.6 and nmap 2.54beta1</ref></refs><vuln_soft><prod name="Snort" vendor="Snort"><vers num="1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1227" published="2000-12-31" seq="2000-1227" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 and Windows 2000 hosts allow remote attackers to cause a denial of service (unavailable connections) by sending multiple SMB SMBnegprots requests but not reading the response that is sent back.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/1301">1301</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server"/><vers num="Professional"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1228" published="2000-12-31" seq="2000-1228" severity="Medium" type="CVE"><desc><descript source="cve">Phorum 3.0.7 allows remote attackers to change the administrator password without authentication via an HTTP request for admin.php3 that sets step, option, confirm and newPssword variables.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html">20000106 Phorum 3.0.7 exploits and IDS signatures</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/2271">2271</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1229" published="2000-12-31" seq="2000-1229" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Phorum 3.0.7 allows remote Phorum administrators to read arbitrary files via &quot;..&quot; (dot dot) sequences in the default .langfile name field in the Master Settings administrative function, which causes the file to be displayed in admin.php3.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html">20000106 Phorum 3.0.7 exploits and IDS signatures</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1230" published="2000-12-31" seq="2000-1230" severity="Medium" type="CVE"><desc><descript source="cve">Backdoor in auth.php3 in Phorum 3.0.7 allows remote attackers to access restricted web pages via an HTTP request with the PHP_AUTH_USER parameter set to &quot;boogieman&quot;.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html">20000106 Phorum 3.0.7 exploits and IDS signatures</ref><ref patch="1" source="MISC" url="http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm">http://www.digitalsec.net/stuff/z-mirrors/hispahack/mi020.htm</ref><ref source="BID" url="http://www.securityfocus.com/bid/2274">2274</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1231" published="2000-12-31" seq="2000-1231" severity="Medium" type="CVE"><desc><descript source="cve">code.php3 in Phorum 3.0.7 allows remote attackers to read arbitrary files in the phorum directory via the query string.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html">20000106 Phorum 3.0.7 exploits and IDS signatures</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1232" published="2000-12-31" seq="2000-1232" severity="Medium" type="CVE"><desc><descript source="cve">upgrade.php3 in Phorum 3.0.7 could allow remote attackers to modify certain Phorum database tables via an unknown method.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html">20000106 Phorum 3.0.7 exploits and IDS signatures</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1233" published="2000-12-31" seq="2000-1233" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in read.php3 and other scripts in Phorum 3.0.7 allows remote attackers to execute arbitrary SQL queries via the sSQL parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html">20000106 Phorum 3.0.7 exploits and IDS signatures</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1234" published="2000-12-31" seq="2000-1234" severity="Medium" type="CVE"><desc><descript source="cve">violation.php3 in Phorum 3.0.7 allows remote attackers to send e-mails to arbitrary addresses and possibly use Phorum as a &quot;spam proxy&quot; by setting the Mod and ForumName parameters.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://cert.uni-stuttgart.de/archive/bugtraq/2000/01/msg00215.html">20000106 Phorum 3.0.7 exploits and IDS signatures</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/2272">2272</ref></refs><vuln_soft><prod name="Phorum" vendor="Phorum"><vers num="3.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1235" published="2000-12-31" seq="2000-1235" severity="Medium" type="CVE"><desc><descript source="cve">The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0339.html">20001219 Oracle WebDb engine brain-damagse</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0372.html">20001221 Re: Oracle WebDb engine brain-damagse</ref><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0463.html">20001223 Potential Vulnerabilities in Oracle Internet Application Server</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/2150">2150</ref><ref patch="1" source="XF" url="http://www.iss.net/security_center/static/5818.php">oracle-webdb-admin-access(5818)</ref></refs><vuln_soft><prod name="Internet Application Server" vendor="Oracle"><vers num="3.0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1236" published="2000-12-31" seq="2000-1236" severity="High" type="CVE"><desc><descript source="cve">SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/2150">2150</ref><ref patch="1" source="XF" url="http://www.iss.net/security_center/static/5817.php">oracle-execute-plsql(5817)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0339.html">20001219 Oracle WebDb engine brain-damagse</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0372.html">20001221 Re: Oracle WebDb engine brain-damagse</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0463.html">20001223 Potential Vulnerabilities in Oracle Internet Application Server</ref></refs><vuln_soft><prod name="Internet Application Server" vendor="Oracle"><vers num="3.0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2000-1237" published="2000-12-31" seq="2000-1237" severity="Medium" type="CVE"><desc><descript source="cve">The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-06/0282.html">20000626 Problems with FTGate</ref><ref source="XF" url="http://www.iss.net/security_center/static/4793.php">ftgate-invalid-user-requests(4793)</ref></refs><vuln_soft><prod name="FTGate" vendor="Floosietek"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 upgrade from v1.0" modified="2006-05-01" name="CVE-2000-1238" published="2000-12-31" seq="2000-1238" severity="High" type="CVE"><desc><descript source="cve">BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.</descript></desc><sols><sol source="nvd">This vulnerability is addressed in the following product releases:
BEA Systems Weblogic Server 5.1 SP 7
BEA Systems WebLogic Express 5.1 SP 7</sol></sols><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref patch="1" source="" url="ftp://ftpna.bea.com/pub/releases/patches/SecurityBEA00-0600.zip"></ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/5089">5089</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/5588">weblogic-bypass-auth(5588)</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="5.1 SP6"/><vers num="5.1 SP5"/><vers num="5.1 SP4"/><vers num="5.1 SP3"/><vers num="5.1 SP2"/><vers num="5.1 SP1"/><vers num="5.1"/></prod><prod name="WebLogic Express" vendor="BEA Systems"><vers num="5.1 SP6"/><vers num="5.1 SP5"/><vers num="5.1 SP4"/><vers num="5.1 SP3"/><vers num="5.1 SP2"/><vers num="5.1 SP1"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" discovered="2000-03-13" modified="2006-05-01" name="CVE-2000-1239" published="2000-12-31" seq="2000-1239" severity="High" type="CVE"><desc><descript source="cve">The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/17085">17085</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3927">tivoli-lcf-file-read(3927)</ref></refs><vuln_soft><prod name="Tivoli Management Framework" vendor="IBM"><vers num="3.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 upgrade from v1.0" discovered="2000-04-22" modified="2006-05-01" name="CVE-2000-1240" published="2000-12-31" seq="2000-1240" severity="Medium" type="CVE"><desc><descript source="cve">Unspecified vulnerability in siteman.php3 in AnyPortal(php) before 22 APR 00 allows remote attackers to obtain sensitive information via unknown attack vectors, which reveal the absolute path.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref patch="1" source="OSVDB" url="http://www.osvdb.org/23983">23983</ref><ref patch="1" source="XF" url="http://xforce.iss.net/xforce/xfdb/25441">anyportalphp-siteman-information-disclosure(25441)</ref></refs><vuln_soft><prod name="AnyPortal php" vendor="AnyPortal php"><vers num="2000-04-18" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 upgrade from v1.0" modified="2006-09-22" name="CVE-2000-1241" published="2000-12-31" seq="2000-1241" severity="High" type="CVE"><desc><descript source="cve">Unspecified vulnerability in Haakon Nilsen simple, integrated publishing system (SIPS) before 0.2.4 allows attackers to has an unknown impact and unspecified vectors, related to a &quot;grave security fault.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="" url="http://sourceforge.net/forum/forum.php?forum_id=25971"></ref></refs><vuln_soft><prod name="SIPS" vendor="SIPS"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="9.0" CVSS_exploit_subscore="8.0" CVSS_impact_subscore="10.0" CVSS_score="9.0" CVSS_vector="(AV:N/AC:L/Au:S/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-22" name="CVE-2000-1242" published="2000-12-31" seq="2000-1242" severity="High" type="CVE"><desc><descript source="cve">The HTTP service in American Power Conversion (APC) PowerChute uses a default username and password, which allows remote attackers to gain system access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="" url="http://governmentsecurity.org/articles/DefaultLoginsandPasswordsforNetworkedDevices.php"></ref><ref adv="1" source="OSVDB" url="http://www.osvdb.org/30768">30768</ref></refs><vuln_soft><prod name="PowerChute" vendor="APC"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-08-01" name="CVE-2000-1243" published="2000-12-31" seq="2000-1243" severity="Medium" type="CVE"><desc><descript source="cve">Privacy leak in Dansie Shopping Cart 3.04, and probably earlier versions, sends sensitive information such as user credentials to an e-mail address controlled by the product developers.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0051.html">20000411 Back Door in Commercial Shopping Cart</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0071.html">20000413 Re: Back Door in Commercial Shopping Cart</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0086.html">20000413 Re: Back Door in Commercial Shopping Cart [RESOLVED]</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-04/0066.html">20000413 Re: Back Door in Commercial Shopping Cart [Stormer Hosting]</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/archive/1/470457/100/0/threaded">20070603 Dansie Cart Script Exploit Reported</ref></refs><vuln_soft><prod name="Shopping Cart" vendor="Dansie"><vers num="3.04"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-02" name="CVE-2000-1244" published="2000-12-31" seq="2000-1244" severity="High" type="CVE"><desc><descript source="cve">Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP header is missing the &quot;From&quot; field, which allows remote attackers to bypass virus protection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0158.html">20001110 CA&apos;s InoculateIT Agent for Exchange Server</ref></refs><vuln_soft><prod name="InoculateIT_Agent" vendor="Computer Associates"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0001" published="2001-06-02" seq="2001-0001" severity="High" type="CVE"><desc><descript source="cve">cookiedecode function in PHP-Nuke 4.4 allows users to bypass authentication and gain access to other user accounts by extracting the authentication information from a cookie.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0257.html"></ref><ref source="XF" url="http://xforce.iss.net/static/6183.php">php-nuke-elevate-privileges(6183)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="4.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0002" published="2001-07-21" seq="2001-0002" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1978">bid1978</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-015.asp">MS:MS01-015</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp">MS01-015</ref><ref source="" url="http://www.guninski.com/chmtempmain.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/2456">2456</ref><ref source="OSVDB" url="http://www.osvdb.org/7823">7823</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:920">oval:org.mitre.oval:def:920</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5567">ie-chm-execute-files(5567)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5" prev="1"/><vers num="5.01"/></prod><prod name="Windows Script Host" vendor="Microsoft"><vers num="5.1"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0003" published="2001-02-12" seq="2001-0003" severity="Medium" type="CVE"><desc><descript source="cve">Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the &quot;Web Client NTLM Authentication&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-001.asp">MS01-001</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2199">BID 2199</ref><ref source="XF" url="http://xforce.iss.net/static/5920.php">wec-ntlm-authentication</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Office" vendor="Microsoft"><vers num="2000"/></prod><prod name="Windows ME" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0004" published="2001-02-12" seq="2001-0004" severity="Medium" type="CVE"><desc><descript source="cve">IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending &quot;%3F+.htr&quot; to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the &quot;File Fragment Reading via .HTR&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-004.asp">MS01-004</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97897954625305&amp;w=2">BUGTRAQ:20010108 IIS 5.0 allows viewing files using %3F+.htr</ref><ref source="BID" url="http://www.securityfocus.com/bid/2313">2313</ref><ref source="XF" url="http://xforce.iss.net/static/5903.php">iis-read-files(5903)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0005" published="2001-02-12" seq="2001-0005" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-002.asp">MS01-002</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2297">bid 2297</ref><ref adv="1" source="@stake, Inc." url="http://www.atstake.com/research/advisories/2001/a012301-1.txt">Parsing Overflow in Microsoft PowerPoint 2000</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5996">powerpoint-execute-code(5996)</ref></refs><vuln_soft><prod name="PowerPoint" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0006" published="2001-02-12" seq="2001-0006" severity="Low" type="CVE"><desc><descript source="cve">The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to &quot;No Access&quot; and disable Winsock network connectivity to cause a denial of service, aka the &quot;Winsock Mutex&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98075221915234&amp;w=2">ntsecurity.nu advisory: Winsock Mutex Vulnerability in Windows NT 4.0 SP6 and below</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-003.asp">MS01-003</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6006">winnt-mutex-dos(6006)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2001-0007" published="2001-02-12" seq="2001-0007" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2176">bid 2176</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/155149">20000109 NSFOCUS SA2001-01: NetScreen Firewall WebUI Buffer Overflow vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/5908.php">netscreen-webui-bo(5908)</ref><ref source="OSVDB" url="http://www.osvdb.org/1707">1707</ref></refs><vuln_soft><prod name="Screen OS" vendor="NetScreen"><vers num="2.5r1"/><vers num="2.1r6"/><vers num="2.10r3"/><vers num="1.73r"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2001-0008" published="2001-02-12" seq="2001-0008" severity="High" type="CVE"><desc><descript source="cve">Backdoor account in Interbase database server allows remote attackers to overwrite arbitrary files using stored procedures.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-01.html">CA-2001-01</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2192">bid 2192</ref><ref source="XF" url="http://xforce.iss.net/static/5911.php">interbase-backdoor-account(5911)</ref></refs><vuln_soft><prod name="Firebird" vendor="Firebird"><vers num="0.9.3" prev="1"/></prod><prod name="Interbase" vendor="Borland Software"><vers num="4.0"/><vers num="5.0"/><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0009" published="2001-02-12" seq="2001-0009" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2173">bid 2173</ref><ref patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/155124">BUGTRAQ:20010109 bugtraq id 2173 Lotus Domino Server</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/154537">BUGTRAQ:20010105 Lotus Domino 5.0.5 Web Server vulnerability - reading files outside the web root</ref><ref source="XF" url="http://xforce.iss.net/static/5899.php">lotus-domino-directory-traversal(5899)</ref><ref source="OSVDB" url="http://www.osvdb.org/1703">1703</ref></refs><vuln_soft><prod name="Domino Server" vendor="Lotus"><vers num="5.0.6"/><vers num="5.0.5"/><vers num="5.0.3"/><vers num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0010" published="2001-02-12" seq="2001-0010" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html">CA-2001-02</ref><ref adv="1" patch="1" source="PGP Security" url="http://www.pgp.com/research/covert/advisories/047.asp">Vulnerabilities in BIND 4 and 8</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2302">bid 2302</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-026">DSA-026</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.2.2 p7"/><vers num="8.2.2 p6"/><vers num="8.2.2 p5"/><vers num="8.2.2 p4"/><vers num="8.2.2 p3"/><vers num="8.2.2 p2"/><vers num="8.2.2 p1"/><vers num="8.2.2"/><vers num="8.2.1"/><vers num="8.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0011" published="2001-02-12" seq="2001-0011" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html">CA-2001-02</ref><ref adv="1" patch="1" source="PGP Security" url="http://www.pgp.com/research/covert/advisories/047.asp">Vulnerabilities in BIND 4 and 8</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref><ref source="BID" url="http://www.securityfocus.com/bid/2307">2307</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="4.9.3"/><vers num="4.9.5 P1"/><vers num="4.9.5"/><vers num="4.9.6"/><vers num="4.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0012" published="2001-02-12" seq="2001-0012" severity="Medium" type="CVE"><desc><descript source="cve">BIND 4 and BIND 8 allow remote attackers to access sensitive information such as environment variables.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html">CA-2001-02</ref><ref adv="1" patch="1" source="PGP Security" url="http://www.pgp.com/research/covert/advisories/047.asp">Vulnerabilities in BIND 4 and 8</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-026">DSA-026</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref><ref source="BID" url="http://www.securityfocus.com/bid/2321">2321</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.2.2 p7"/><vers num="8.2.2 p6"/><vers num="8.2.2 p5"/><vers num="8.2.2 p4"/><vers num="8.2.2 p3"/><vers num="8.2.2 p2"/><vers num="8.2.2 p1"/><vers num="8.2.2"/><vers num="8.2.1"/><vers num="8.2"/><vers num="4.9.3"/><vers num="4.9.5 P1"/><vers num="4.9.5"/><vers num="4.9.6"/><vers num="4.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0013" published="2001-02-12" seq="2001-0013" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in nslookupComplain function in BIND 4 allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-02.html">CA-2001-02</ref><ref adv="1" patch="1" source="PGP Security" url="http://www.pgp.com/research/covert/advisories/047.asp">Vulnerabilities in BIND 4 and 8</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/047.asp">20010129 Vulnerabilities in BIND 4 and 8</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-007.html">RHSA-2001:007</ref><ref source="BID" url="http://www.securityfocus.com/bid/2309">2309</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="4.9.3"/><vers num="4.9.5 P1"/><vers num="4.9.5"/><vers num="4.9.6"/><vers num="4.9.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0014" published="2001-02-12" seq="2001-0014" severity="Medium" type="CVE"><desc><descript source="cve">Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not properly handle certain malformed packets, which allows remote attackers to cause a denial of service, aka the &quot;Invalid RDP Data&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-006.asp">MS01-006</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2326">bid 2326</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Server"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0015" published="2001-03-12" seq="2001-0015" severity="High" type="CVE"><desc><descript source="cve">Network Dynamic Data Exchange (DDE) in Windows 2000 allows local users to gain SYSTEM privileges via a &quot;WM_COPYDATA&quot; message to an invisible window that is running with the privileges of the WINLOGON process.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-007.asp">MS01-007</ref><ref adv="1" patch="1" source="@stake" url="http://www.atstake.com/research/advisories/2001/a020501-1.txt">A020501-1</ref><ref source="BID" url="http://www.securityfocus.com/bid/2341">2341</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6062">win-dde-elevate-privileges(6062)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0016" published="2001-03-12" seq="2001-0016" severity="High" type="CVE"><desc><descript source="cve">NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-008.asp">MS01-008</ref><ref source="Razor" url="http://razor.bindview.com/publish/advisories/adv_NTLMSSP.html">Local promotion vulnerability in NT4&apos;s NTLM Security Support Provider</ref><ref source="BID" url="http://www.securityfocus.com/bid/2348">2348</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6076">ntlm-ssp-elevate-privileges(6076)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0017" published="2001-03-12" seq="2001-0017" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in PPTP server in Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed data packet, aka the &quot;Malformed PPTP Packet Stream&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-009.asp">MS01-009</ref><ref source="BID" url="http://www.securityfocus.com/bid/2368">2368</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6103">winnt-pptp-dos(6103)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0018" published="2001-07-21" seq="2001-0018" severity="Medium" type="CVE"><desc><descript source="cve">Windows 2000 domain controller in Windows 2000 Server, Advanced Server, or Datacenter Server allows remote attackers to cause a denial of service via a flood of malformed service requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-011.asp">MS01-011</ref><ref source="VULN-DEV" url="http://online.securityfocus.com/archive/82/148411">20001202 UDP Ping-pong in Win2k</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms01-011.asp">MS01-011</ref><ref source="XF" url="http://xforce.iss.net/static/6136.php">win2k-domain-controller-dos(6136)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-049.shtml">L-049</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Server"/><vers num="Advanced Server"/><vers num="Datacenter Server"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0019" published="2001-02-12" seq="2001-0019" severity="Low" type="CVE"><desc><descript source="cve">Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the &quot;show script,&quot; &quot;clear script,&quot; &quot;show archive,&quot; &quot;clear archive,&quot; &quot;show log,&quot; or &quot;clear log&quot; commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="@stake, Inc." url="http://www.atstake.com/research/advisories/2001/a013101-1.txt">A013101-1</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml">Security Advisory: Cisco Content Services Switch Vulnerability</ref></refs><vuln_soft><prod name="Arrowpoint" vendor="Cisco"><vers num=""/></prod><prod name="Cisco Content Services" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0020" published="2001-02-12" seq="2001-0020" severity="Low" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="@stake, Inc." url="http://www.atstake.com/research/advisories/2001/a013101-1.txt">A013101-1</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml">Security Advisory: Cisco Content Services Switch Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/6031.php">cisco-ccs-file-access(6031)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2331">2331</ref><ref source="OSVDB" url="http://www.osvdb.org/1757">1757</ref></refs><vuln_soft><prod name="Arrowpoint" vendor="Cisco"><vers num=""/></prod><prod name="Cisco Content Services" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2001-0021" published="2001-02-16" seq="2001-0021" severity="High" type="CVE"><desc><descript source="cve">MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2063">bid 2063</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5649.php">mailman-alternate-templates(5649)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0057.html">BUGTRAQ:20001206 (SRADV00005) Remote command execution</ref><ref source="CONFIRM" url="http://www.endymion.com/products/mailman/history.htm">http://www.endymion.com/products/mailman/history.htm</ref></refs><vuln_soft><prod name="MailMan WebMail" vendor="Endymion"><vers num="3.0.25"/><vers num="3.0.24"/><vers num="3.0.23"/><vers num="3.0.22"/><vers num="3.0.21"/><vers num="3.0.20"/><vers num="3.0.19"/><vers num="3.0.18"/><vers num="3.0.16"/><vers num="3.0.15"/><vers num="3.0.14"/><vers num="3.0.13"/><vers num="3.0.12"/><vers num="3.0.11"/><vers num="3.0.10"/><vers num="3.0.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0022" published="2001-02-12" seq="2001-0022" severity="High" type="CVE"><desc><descript source="cve">simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2106">bid 2106</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5743.php">http-cgi-simplestguest(5743)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0168.html">BUGTRAQ:20001213 Re: Insecure input validation in simplestmail.cgi</ref></refs><vuln_soft><prod name="simplestguest.cgi" vendor="Leif M. Wright"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0023" published="2001-02-12" seq="2001-0023" severity="High" type="CVE"><desc><descript source="cve">everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2101">bid 2101</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5736.php">http-cgi-everythingform(5736)</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0137.html">BUGTRAQ:20001211 Insecure input validation in everythingform.cgi (remote command execution)</ref></refs><vuln_soft><prod name="everythingform.cgi" vendor="Leif M. Wright"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0024" published="2001-02-12" seq="2001-0024" severity="High" type="CVE"><desc><descript source="cve">simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2102">bid 2102</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5739.php">http-cgi-simplestmail(5739)</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0136.html">BUGTRAQ:20001211 Insecure input validation in simplestmail.cgi (remote command execution)</ref></refs><vuln_soft><prod name="simplestmail.cgi" vendor="Leif M. Wright"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-16" name="CVE-2001-0025" published="2001-02-12" seq="2001-0025" severity="High" type="CVE"><desc><descript source="cve">ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2103">bid 2103</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5741.php">http-cgi-ad(5741)</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0143.html">BUGTRAQ:20001211 Insecure input validation in ad.cgi</ref></refs><vuln_soft><prod name="ad.cgi" vendor="Leif M. Wright"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0026" published="2001-02-12" seq="2001-0026" severity="Medium" type="CVE"><desc><descript source="cve">rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2098">bid 2098</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5727.php">rppppoe-zero-length-dos(5727)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0134.html">BUGTRAQ:20001211 DoS vulnerability in rp-pppoe versions &lt;= 2.4</ref><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA-2000-130.html">RHSA-2000:130-05</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000357">CLA-2000:357</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-084.php3">MDKSA-2000:084</ref></refs><vuln_soft><prod name="PPPoE" vendor="Roaring Penguin"><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0027" published="2001-02-12" seq="2001-0027" severity="High" type="CVE"><desc><descript source="cve">mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the &quot;user&quot; command to change accounts, which allows authenticated attackers to gain privileges of other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0139.html">BUGTRAQ:20001211 mod_sqlpw Password Caching Bug</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5737.php">proftpd-modsqlpw-unauth-access(5737)</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0028" published="2001-02-12" seq="2001-0028" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of &quot; (quotation) characters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2099">bid 2099</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5725.php">oops-ftputils-bo(5725)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0127.html">BUGTRAQ:20001211 [pkc] remote heap buffer overflow in oops</ref><ref adv="1" patch="1" source="FreeBSD" url="http://archives.neohapsis.com/archives/freebsd/2000-12/0418.html">FreeBSD-SA-00:79</ref></refs><vuln_soft><prod name="Oops Proxy Server" vendor="Igor Khasilev"><vers num="1.4.22"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0029" published="2001-02-12" seq="2001-0029" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0158.html">BUGTRAQ:20001212 Re: [pkc] remote heap buffer overflow in oops</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2099">bid 2099</ref><ref source="MISC" url="http://zipper.paco.net/~igor/oops/ChangeLog">http://zipper.paco.net/~igor/oops/ChangeLog</ref><ref source="XF" url="http://xforce.iss.net/static/6122.php">oops-dns-bo(6122)</ref></refs><vuln_soft><prod name="Oops Proxy Server" vendor="Igor Khasilev"><vers num="1.4.22"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0030" published="2001-02-16" seq="2001-0030" severity="High" type="CVE"><desc><descript source="cve">FoolProof 3.9 allows local users to bypass program execution restrictions by downloading the restricted executables from another source and renaming them.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2089">bid 2089</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5758.php">foolproof-security-bypass(5758)</ref></refs><vuln_soft><prod name="FoolProof Security" vendor="SmartStuff"><vers num="3.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0031" published="2001-02-16" seq="2001-0031" severity="Medium" type="CVE"><desc><descript source="cve">BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5661.php">broadvision-bv1to1-reveal-path(5661)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0074.html">BUGTRAQ:20001207 BroadVision One-To-One Enterprise Path Disclosure Vulnerability</ref></refs><vuln_soft><prod name="One-To-One Enterprise Server" vendor="BroadVision"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0032" published="2001-02-16" seq="2001-0032" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2096">bid 2096</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5717.php">ssldump-format-strings(5717)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/149917">BUGTRAQ:20001208 format string in ssl dump</ref></refs><vuln_soft><prod name="ssldump" vendor="Eric Rescorla"><vers num="0.9b1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2001-0033" published="2001-02-16" seq="2001-0033" severity="High" type="CVE"><desc><descript source="cve">KTH Kerberos IV allows local users to change the configuration of a Kerberos server running at an elevated privilege by specifying an alternate directory using with the KRBCONFDIR environmental variable, which allows the user to gain additional privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html">BUGTRAQ:20001210 KTH upgrade and FIX</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html">BUGTRAQ:20001208 Vulnerabilities in KTH Kerberos IV</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5738.php">kerberos4-user-config(5738)</ref></refs><vuln_soft><prod name="KTH Kerberos" vendor="KTH"><vers num="4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2001-0034" published="2001-02-16" seq="2001-0034" severity="High" type="CVE"><desc><descript source="cve">KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to generate false proxy responses and possibly gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html">BUGTRAQ:20001210 KTH upgrade and FIX</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html">BUGTRAQ:20001208 Vulnerabilities in KTH Kerberos IV</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5733.php">kerberos4-arbitrary-proxy(5733)</ref></refs><vuln_soft><prod name="KTH Kerberos" vendor="KTH"><vers num="4.1.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2001-0035" published="2001-02-16" seq="2001-0035" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the kdc_reply_cipher function in KTH Kerberos IV allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long authentication request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html">BUGTRAQ:20001210 KTH upgrade and FIX</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html">BUGTRAQ:20001208 Vulnerabilities in KTH Kerberos IV</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5734.php">kerberos4-auth-packet-overflow(5734)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0511.html">20010130 Buffer overflow in old ssh-1.2.2x-afs-kerberosv4 patches</ref></refs><vuln_soft><prod name="KTH Kerberos" vendor="KTH"><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2001-0036" published="2001-02-16" seq="2001-0036" severity="Low" type="CVE"><desc><descript source="cve">KTH Kerberos IV allows local users to overwrite arbitrary files via a symlink attack on a ticket file.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0105.html">BUGTRAQ:20001210 KTH upgrade and FIX</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0093.html">BUGTRAQ:20001208 Vulnerabilities in KTH Kerberos IV</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5754.php">kerberos4-tmpfile-dos(5754)</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-025.html">RHSA-2001:025</ref></refs><vuln_soft><prod name="KTH Kerberos" vendor="KTH"><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0037" published="2001-02-16" seq="2001-0037" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2085">bid 2085</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0082.html">BUGTRAQ:20001207 HomeSeer Directory Traversal Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5663.php">homeseer-directory-traversal(5663)</ref><ref source="MISC" url="http://www.keware.com/hsbetachanges.htm">http://www.keware.com/hsbetachanges.htm</ref></refs><vuln_soft><prod name="HomeSeer" vendor="Keware Technologies"><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0038" published="2001-02-16" seq="2001-0038" severity="Medium" type="CVE"><desc><descript source="cve">Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2084">bid 2084</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5728.php">offline-explorer-reveal-files(5728)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0078.html">BUGTRAQ:20001207 MetaProducts Offline Explorer</ref></refs><vuln_soft><prod name="Offline Explorer" vendor="MetaProducts"><vers num="1.3x"/><vers num="1.2x"/><vers num="1.1x"/><vers num="1.0x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0039" published="2001-02-16" seq="2001-0039" severity="Medium" type="CVE"><desc><descript source="cve">IPSwitch IMail 6.0.5 allows remote attackers to cause a denial of service using the SMTP AUTH command by sending a base64-encoded user password whose length is between 80 and 136 bytes.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0071.html">BUGTRAQ:20001206 DoS by SMTP AUTH command in IPSwitch IMail server</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5674.php">imail-smtp-auth-dos(5674)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2083">bid 2083</ref><ref source="CONFIRM" url="http://www.ipswitch.com/Support/IMail/news.html">http://www.ipswitch.com/Support/IMail/news.html</ref></refs><vuln_soft><prod name="Imail" vendor="Ipswitch"><vers num="6.0.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0040" published="2001-02-16" seq="2001-0040" severity="Low" type="CVE"><desc><descript source="cve">APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2070">bid 2070</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5654.php">apc-apcupsd-dos(5654)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0066.html">BUGTRAQ:20001206 apcupsd 3.7.2 Denial of Service</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/MDKSA-2000-077.php3">MDKSA-2000:077</ref></refs><vuln_soft><prod name="apcupsd" vendor="APC"><vers num="3.7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-07-02" name="CVE-2001-0041" published="2001-02-16" seq="2001-0041" severity="High" type="CVE"><desc><descript source="cve">Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service via a series of failed telnet authentication attempts.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2072">bid 2072</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5656.php">cisco-catalyst-telnet-dos(5656)</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/catalyst-memleak-pub.shtml">CSCds66191</ref><ref source="OSVDB" url="http://www.osvdb.org/801">801</ref></refs><vuln_soft><prod name="Catalyst 4000" vendor="Cisco"><vers num="5.5(1)"/><vers num="5.5"/><vers num="5.4(3)"/><vers num="5.4(2)"/><vers num="5.4(1)"/><vers num="5.4"/><vers num="5.2(7)"/><vers num="5.2(6)"/><vers num="5.2(5)"/><vers num="5.2(4)"/><vers num="5.2(2)"/><vers num="5.2(1a)"/><vers num="5.2(1)"/><vers num="5.2"/><vers num="5.1(2a)"/><vers num="5.1(1a)"/><vers num="5.1(1)"/><vers num="5.1"/><vers num="4.5(9)"/><vers num="4.5(8)"/><vers num="4.5(7)"/><vers num="4.5(6)"/><vers num="4.5(5)"/><vers num="4.5(4)"/><vers num="4.5(3)"/><vers num="4.5(2)"/></prod><prod name="Catalyst 5000" vendor="Cisco"><vers num="5.5(4)"/><vers num="5.5(3)"/><vers num="5.5(2)"/><vers num="5.5(1)"/><vers num="5.4.1"/><vers num="5.4(4)"/><vers num="5.4(2)"/><vers num="5.4(1)"/><vers num="5.2(4)"/><vers num="5.2(3)"/><vers num="5.2(2)"/><vers num="5.2(1)"/><vers num="5.2"/><vers num="5.1(2a)"/><vers num="5.1(1)"/><vers num="5.1"/><vers num="4.5(9)"/><vers num="4.5(8)"/><vers num="4.5(7)"/><vers num="4.5(6)"/><vers num="4.5(5)"/><vers num="4.5(4)"/><vers num="4.5(3)"/><vers num="4.5(2)"/></prod><prod name="Catalyst 6000" vendor="Cisco"><vers num="5.5(4a)"/><vers num="5.5(4)"/><vers num="5.5(3)"/><vers num="5.5(2)"/><vers num="5.5(1)"/><vers num="5.5"/><vers num="5.4(4)"/><vers num="5.4(3)"/><vers num="5.4(2)"/><vers num="5.4(1)"/><vers num="5.4"/><vers num="5.3(6)CSX"/><vers num="5.3(5a)CSX"/><vers num="5.3(5)CSX"/><vers num="5.3(4)CSX"/><vers num="5.3(3)CSX"/><vers num="5.3(2)CSX"/><vers num="5.3(1a)CSX"/><vers num="5.3(1)CSX"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2001-0042" published="2001-02-16" seq="2001-0042" severity="Medium" type="CVE"><desc><descript source="cve">PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing &quot;%5c&quot; (encoded backslash) sequences.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2060">bid 2060</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5659.php">apache-php-disclose-files(5659)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/149210">BUGTRAQ:20001206 CHINANSL Security Advisory(CSA-200011)</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2001-0043" published="2001-02-16" seq="2001-0043" severity="High" type="CVE"><desc><descript source="cve">phpGroupWare before 0.9.7 allows remote attackers to execute arbitrary PHP commands by specifying a malicious include file in the phpgw_info parameter of the phpgw.inc.php program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2069">bid 2069</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5650.php">phpgroupware-include-files(5650)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0053.html">BUGTRAQ:20001206 (SRADV00006) Remote command execution vulnerabilities in phpGroupWare</ref><ref patch="1" source="" url="http://sourceforge.net/project/shownotes.php?release_id=17604"></ref><ref source="OSVDB" url="http://www.osvdb.org/1682">1682</ref></refs><vuln_soft><prod name="phpGroupWare" vendor="phpGroupWare"><vers num="0.9.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0044" published="2001-02-16" seq="2001-0044" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2075">bid 2075</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5651.php">markvision-printer-driver-bo(5651)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0064.html"></ref></refs><vuln_soft><prod name="MarkVision" vendor="Lexmark"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0045" published="2001-02-16" seq="2001-0045" severity="High" type="CVE"><desc><descript source="cve">The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the &quot;Registry Permissions&quot; vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2064">bid 2064</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-095.asp">MS00-095</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5671.php">nt-ras-reg-perms(5671)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval500.html">OVAL500</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:500">oval:org.mitre.oval:def:500</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="Terminal Server"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0046" published="2001-02-16" seq="2001-0046" severity="Medium" type="CVE"><desc><descript source="cve">The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the &quot;Registry Permissions&quot; vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2066">bid 2066</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-095.asp">MS00-095</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5672.php">nt-snmp-reg-perms(5672)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval139.html">OVAL139</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:139">oval:org.mitre.oval:def:139</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0047" published="2001-02-16" seq="2001-0047" severity="High" type="CVE"><desc><descript source="cve">The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the &quot;Registry Permissions&quot; vulnerabilities.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/bid/2065">bid 2065</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-095.asp">MS00-095</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5673.php">nt-mts-reg-perms(5673)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/oval/definitions/data/oval140.html">OVAL140</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:140">oval:org.mitre.oval:def:140</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="Terminal Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0048" published="2001-02-12" seq="2001-0048" severity="High" type="CVE"><desc><descript source="cve">The &quot;Configure Your Server&quot; tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the &quot;Directory Service Restore Mode Password&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2133">bid 2133</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-099.asp">MS00-099</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Server"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0049" published="2001-02-16" seq="2001-0049" severity="Medium" type="CVE"><desc><descript source="cve">WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2082">bid 2082</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0079.html">BUGTRAQ:20001207 WatchGuard SOHO v2.2.1 DoS</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5665.php">watchguard-soho-get-dos(5665)</ref></refs><vuln_soft><prod name="SOHO Firewall" vendor="WatchGuard"><vers num="2.2.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0050" published="2001-02-16" seq="2001-0050" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2087">bid 2087</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5701.php">irc-bitchx-dns-bo(5701)</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0081.html">BUGTRAQ:20001207 BitchX DNS Overflow Patch</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0086.html">BUGTRAQ:20001207 bitchx/ircd DNS overflow demonstration</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-126.html">RHSA-2000:126</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-079.php3">MDKSA-2000:079</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:78.bitchx.v1.1.asc">FreeBSD-SA-00:78</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000364">CLA-2000:364</ref></refs><vuln_soft><prod name="BitchX" vendor="Colten Edwards"><vers num="1.0c17"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0051" published="2001-02-16" seq="2001-0051" severity="High" type="CVE"><desc><descript source="cve">IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the databasse.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2068">bid 2068</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5662.php">ibm-db2-gain-access(5662)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/149222">BUGTRAQ:20001205 IBM DB2 default account and password Vulnerability</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="Linux" num="6.1"/><vers edition="Windows NT" num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0052" published="2001-02-16" seq="2001-0052" severity="Low" type="CVE"><desc><descript source="cve">IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2067">bid 2067</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5664.php">ibm-db2-dos(5664)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/149207">BUGTRAQ:20001205 IBM DB2 SQL DOS</ref></refs><vuln_soft><prod name="DB2 Universal Database" vendor="IBM"><vers edition="Windows NT" num="6.1"/><vers edition="Windows NT" num="7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0053" published="2001-02-12" seq="2001-0053" severity="High" type="CVE"><desc><descript source="cve">One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2124">bid 2124</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5776.php">bsd-ftpd-replydirname-bo(5776)</ref><ref patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0275.html">BUGTRAQ:20001218 Trustix Security Advisory - ed, tcsh, and ftpd-BSD</ref><ref adv="1" patch="1" source="OpenBSD" url="http://www.openbsd.org/advisories/ftpd_replydirname.txt">OPENBSD:20001218</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc">NetBSD-SA2000-018</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.5"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/></prod><prod name="ftpd-BSD" vendor="David Madore"><vers num="0.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0054" published="2001-02-16" seq="2001-0054" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as &quot;/..%20.&quot; to a CD command, a variant of a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2052">bid 2052</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5639.php">ftp-servu-homedir-travers(5639)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97604119024280&amp;w=2">BUGTRAQ:20001205 (no subject)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0043.html">BUGTRAQ:20001205 Serv-U FTP directory traversal vunerability (all versions)</ref><ref source="OSVDB" url="http://www.osvdb.org/464">464</ref></refs><vuln_soft><prod name="Serv-U" vendor="Cat Soft"><vers num="2.5"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0055" published="2001-02-16" seq="2001-0055" severity="Medium" type="CVE"><desc><descript source="cve">CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5627.php">cisco-cbos-syn-packets(5627)</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml">CISCO:20001204 Multiple Vulnerabilities in CBOS</ref></refs><vuln_soft><prod name="Cisco Broadband Operating System" vendor="Cisco"><vers num="2.3.8" prev="1"/></prod><prod name="Cisco 6xx Routers" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0056" published="2001-02-16" seq="2001-0056" severity="High" type="CVE"><desc><descript source="cve">The Cisco Web Management interface in routers running CBOS 2.4.1 and earlier does not log invalid logins, which allows remote attackers to guess passwords without detection.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5628.php">cisco-cbos-invalid-login(5628)</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml">CISCO:20001204 Multiple Vulnerabilities in CBOS</ref></refs><vuln_soft><prod name="Cisco Broadband Operating System" vendor="Cisco"><vers num="2.4.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0057" published="2001-02-16" seq="2001-0057" severity="Medium" type="CVE"><desc><descript source="cve">Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5629.php">cisco-cbos-icmp-echo(5629)</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml">CISCO:20001204 Multiple Vulnerabilities in CBOS</ref></refs><vuln_soft><prod name="Cisco Broadband Operating System" vendor="Cisco"><vers num="2.4.1" prev="1"/></prod><prod name="Cisco 6xx Routers" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0058" published="2001-02-16" seq="2001-0058" severity="Medium" type="CVE"><desc><descript source="cve">The Web interface to Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a URL that does not end in a space character.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5626.php">cisco-cbos-web-access(5626)</ref><ref adv="1" source="Cisco" url="http://www.cisco.com/warp/public/707/CBOS-multiple.shtml">CISCO:20001204 Multiple Vulnerabilities in CBOS</ref><ref source="OSVDB" url="http://www.osvdb.org/460">460</ref></refs><vuln_soft><prod name="Cisco Broadband Operating System" vendor="Cisco"><vers num="2.4.1" prev="1"/></prod><prod name="Cisco 6xx Routers" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0059" published="2001-02-12" seq="2001-0059" severity="Medium" type="CVE"><desc><descript source="cve">patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2127">bid 2127</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5789.php">solaris-patchadd-symlink(5789)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97720205217707&amp;w=2">BUGTRAQ:20001218 Solaris patchadd(1)  (3) symlink vulnerabilty</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0060" published="2001-02-12" seq="2001-0060" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in stunnel 3.8 and earlier allows attackers to execute arbitrary commands via a malformed ident username.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2128">bid 2128</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5807.php">stunnel-format-logfile(5807)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/151719">BUGTRAQ:20001218 Stunnel format bug</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0337.html">BUGTRAQ:20001209 Trustix Security Advisory - stunnel</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-129.html">RHSA-2000:129</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000363">CLA-2000:363</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-009">DSA-009</ref></refs><vuln_soft><prod name="Stunnel" vendor="Stunnel"><vers num="3.8"/><vers num="3.7"/><vers num="3.4a"/><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0061" published="2001-02-12" seq="2001-0061" severity="High" type="CVE"><desc><descript source="cve">procfs in FreeBSD and possibly other operating systems does not properly restrict access to per-process mem and ctl files, which allows local users to gain root privileges by forking a child process and executing a privileged process from the child, while the parent retains access to the child&apos;s address space.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2130">bid 2130</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc">FreeBSD-SA-00:77</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6106">procfs-elevate-privileges(6106)</ref><ref source="OSVDB" url="http://www.osvdb.org/1697">1697</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0062" published="2001-02-12" seq="2001-0062" severity="Low" type="CVE"><desc><descript source="cve">procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process&apos; own mem file, which causes the kernel to hang.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2131">bid 2131</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc">FreeBSD-SA-00:77</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6107">procfs-mmap-dos(6107)</ref><ref source="OSVDB" url="http://www.osvdb.org/1698">1698</ref><ref source="OSVDB" url="http://www.osvdb.org/6082">6082</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0063" published="2001-02-12" seq="2001-0063" severity="High" type="CVE"><desc><descript source="cve">procfs in FreeBSD and possibly other operating systems allows local users to bypass access control restrictions for a jail environment and gain additional privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2132">bid 2132</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:77.procfs.v1.1.asc">FreeBSD-SA-00:77</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6108">procfs-access-control-bo(6108)</ref><ref source="OSVDB" url="http://www.osvdb.org/1691">1691</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0064" published="2001-02-12" seq="2001-0064" severity="Medium" type="CVE"><desc><descript source="cve">Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a &quot;\r\n&quot; string.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2134">bid 2134</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0315.html">BUGTRAQ:20001219 def-2000-03: MDaemon 3.5.0 DoS</ref></refs><vuln_soft><prod name="MDaemon" vendor="Alt-N"><vers num="3.5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0065" published="2001-02-12" seq="2001-0065" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5775.php">bftpd-site-chown-bo(5775)</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0189.html">BUGTRAQ:20001213 Potential Buffer Overflow vulnerability in bftpd-1.0.13</ref></refs><vuln_soft><prod name="bftpd" vendor="Max-Wilhelm Bruker"><vers num="1.0.13"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0066" published="2001-02-16" seq="2001-0066" severity="High" type="CVE"><desc><descript source="cve">Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2004">bid 2004</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-11/0356.html">BUGTRAQ:20001126 [MSY] S(ecure)Locate heap corruption vulnerability</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001217a">DSA-005-1</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-085.php3">MDKSA-2000:085</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-128.html">RHSA-2000:128</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000369">CLA-2001:369</ref><ref source="TURBO" url="http://www.turbolinux.com/pipermail/tl-security-announce/2001-February/000144.html">TLSA2001002-1</ref><ref source="XF" url="http://xforce.iss.net/static/5594.php">slocate-heap-execute-code(5594)</ref></refs><vuln_soft><prod name="Secure Locate" vendor="Kevin Lindsay"><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.6"/><vers num="1.5"/><vers num="1.4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0067" published="2001-02-12" seq="2001-0067" severity="Low" type="CVE"><desc><descript source="cve">The installation of J-Pilot creates the .jpilot directory with the user&apos;s umask, which could allow local attackers to read other users&apos; PalmOS backup information if their umasks are not securely set.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?mid=150957&amp;end=2001-02-03&amp;fromthread=1&amp;start=2001-01-28&amp;threads=0&amp;list=1&amp;">BUGTRAQ:20001214 J-Pilot Permissions Vulnerability</ref><ref patch="1" source="Mandrake" url="http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-081.php3">MDKSA-2000:081</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5762.php">jpilot-perms(5762)</ref></refs><vuln_soft><prod name="jpilot" vendor="Judd Montgomery"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0068" published="2001-02-12" seq="2001-0068" severity="Low" type="CVE"><desc><descript source="cve">Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5784.php">mrj-runtime-malicious-applets(5784)</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0241.html">BUGTRAQ:20001215 Security Hole of MRJ 2.2.3 (Mac OS Runtime for Java) - Inconsistent Use of CODEBASE and ARCHIVE Attributes</ref></refs><vuln_soft><prod name="Mac OS Runtime" vendor="Apple"><vers edition="Java" num="2.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2001-0069" published="2001-02-12" seq="2001-0069" severity="Low" type="CVE"><desc><descript source="cve">dialog before 0.9a-20000118-3bis in Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><access/><env/></vuln_types><range><local/></range><refs><ref patch="1" source="Debian GNU/Linux" url="http://www.debian.org/security/2000/20001225">DSA-008-1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2151">bid 2151</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5809.php">dialog-symlink(5809)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2 sparc"/><vers num="2.2 powerpc"/><vers num="2.2 arm"/><vers num="2.2 alpha"/><vers num="2.2 68k"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0070" published="2001-02-12" seq="2001-0070" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2152">bid 2152</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5808.php">1stup-mail-server-bo</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0143.html">BUGTRAQ:20001226 1st Up Mail Server v4.1 Buffer Overflow Vulnerability</ref><ref patch="1" source="Upland Online" url="http://www.upland.co.uk/upland/page3c.htm"></ref></refs><vuln_soft><prod name="1st Up Mail Server" vendor="Upland Solutions"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0071" published="2001-02-12" seq="2001-0071" severity="Low" type="CVE"><desc><descript source="cve">gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.</descript></desc><loss_types><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2141">bid 2141</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/152197">20001220 Trustix Security Advisory - gnupg, ftpd-BSD</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2000-131.html">RHSA-2000:131-02</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5802.php">gnupg-detached-sig-modify</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3">MDKSA-2000-087</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001225b">DSA-010-1</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000368">CLA-2000:368</ref><ref source="OSVDB" url="http://www.osvdb.org/1699">1699</ref></refs><vuln_soft><prod name="GNU Privacy Guard" vendor="Gnu"><vers num="1.0.3b"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0072" published="2001-02-12" seq="2001-0072" severity="Medium" type="CVE"><desc><descript source="cve">gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2153">bid 2153</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-131.html">RHSA-2000:131</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-087.php3">MDKSA-2000-087</ref><ref source="DEBIAN" url="http://www.debian.org/security/2000/20001225b">DSA-010-1</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000368">CLA-2000:368</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/152197">20001220 Trustix Security Advisory - gnupg, ftpd-BSD</ref><ref source="XF" url="http://xforce.iss.net/static/5803.php">gnupg-reveal-private</ref><ref source="OSVDB" url="http://www.osvdb.org/1702">1702</ref></refs><vuln_soft><prod name="GNU Privacy Guard" vendor="Gnu"><vers num="1.0.3b"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0073" published="2001-02-12" seq="2001-0073" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2154">bid 2154</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/153188">BUGTRAQ:20001226 buffer overflow in libsecure (NSA Security-enhanced Linux)</ref></refs><vuln_soft><prod name="Security-Enhanced Linux" vendor="NSA"><vers num="slinux_2000-12-18"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0074" published="2001-02-12" seq="2001-0074" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2155">bid 2155</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/153007">BUGTRAQ:20001223 Technote</ref></refs><vuln_soft><prod name="Technote" vendor="Technote Inc"><vers num="Pro"/><vers num="2001"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0075" published="2001-02-12" seq="2001-0075" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/153212">BUGTRAQ:20001227 [Ksecurity Advisory] main.cgi in technote</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2156">bid 2156</ref></refs><vuln_soft><prod name="Technote" vendor="Technote Inc"><vers num="Pro"/><vers num="2001"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0076" published="2001-02-12" seq="2001-0076" severity="High" type="CVE"><desc><descript source="cve">register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2157">bid 2157</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0483.html">BUGTRAQ:20001228 Remote vulnerability in Ikonboard upto version 2.1.7b</ref><ref source="XF" url="http://xforce.iss.net/static/5819.php">http-cgi-ikonboard</ref></refs><vuln_soft><prod name="ikonboard" vendor="Ikonboard.com"><vers num="2.1.7b"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0077" published="2001-02-12" seq="2001-0077" severity="Medium" type="CVE"><desc><descript source="cve">The clustmon service in Sun Cluster 2.x does not require authentication, which allows remote attackers to obtain sensitive information such as system logs and cluster configurations.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html">BUGTRAQ:20001212 Two Holes in Sun Cluster 2.x</ref><ref source="XF" url="http://xforce.iss.net/static/6123.php">clustmon-no-authentication(6123)</ref></refs><vuln_soft><prod name="Sun Cluster" vendor="Sun"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0078" published="2001-02-12" seq="2001-0078" severity="Low" type="CVE"><desc><descript source="cve">in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0180.html">BUGTRAQ:20001212 Two Holes in Sun Cluster 2.x</ref><ref source="XF" url="http://xforce.iss.net/static/6125.php">ha-nfs-symlink(6125)</ref><ref source="OSVDB" url="http://www.osvdb.org/6437">6437</ref></refs><vuln_soft><prod name="Sun Cluster" vendor="Sun"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0079" published="2001-02-12" seq="2001-0079" severity="Low" type="CVE"><desc><descript source="cve">Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0174.html">BUGTRAQ:20001213 STM symlink Vulnerability</ref></refs><vuln_soft><prod name="Support Tools Manager" vendor="HP"><vers num="A.22.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0080" published="2001-02-12" seq="2001-0080" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH service with a non-SSH client, which generates a protocol mismatch error.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5760.php">cisco-catalyst-ssh-mismatch(5760)</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/catalyst-ssh-protocolmismatch-pub.shtml">CISCO:20001213 Cisco Catalyst SSH Protocol Mismatch Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/2117">2117</ref></refs><vuln_soft><prod name="Catalyst 4000" vendor="Cisco"><vers num=""/></prod><prod name="Catalyst 5000" vendor="Cisco"><vers num=""/></prod><prod name="Catalyst 6000" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2001-0081" published="2001-02-12" seq="2001-0081" severity="Medium" type="CVE"><desc><descript source="cve">swinit in nCipher does not properly disable the Operator Card Set recovery feature even when explicitly disabled by the user, which could allow attackers to gain access to application keys.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0152.html">20001212 nCipher Security Advisory: Operator Cards unexpectedly recoverable</ref><ref adv="1" patch="1" source="nCipher" url="http://active.ncipher.com/updates/advisory.txt">nCipher Security Advisory: Operator Cards unexpectedly recoverable</ref><ref source="CONFIRM" url="http://active.ncipher.com/updates/advisory.txt">http://active.ncipher.com/updates/advisory.txt</ref><ref source="XF" url="http://xforce.iss.net/static/5999.php">ncipher-recover-operator-cards(5999)</ref><ref source="OSVDB" url="http://www.osvdb.org/4849">4849</ref></refs><vuln_soft><prod name="nCipher" vendor="nCipher"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0082" published="2001-02-12" seq="2001-0082" severity="High" type="CVE"><desc><descript source="cve">Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0271.html">BUGTRAQ:20001218 FireWall-1 Fastmode Vulnerability</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0083" published="2001-02-12" seq="2001-0083" severity="Medium" type="CVE"><desc><descript source="cve">Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the &quot;Severed Windows Media Server Connection&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-097.asp">MS00-097</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5785.php">mediaservices-dropped-connection-dos(5785)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q281256">Q281256</ref></refs><vuln_soft><prod name="Windows Media Services" vendor="Microsoft"><vers num="4.0"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0084" published="2001-02-12" seq="2001-0084" severity="High" type="CVE"><desc><descript source="cve">GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2165">bid 2165</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0498.html">BUGTRAQ:20010102 gtk+ security hole.</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0027.html">BUGTRAQ:20010103 Claimed vulnerability in GTK_MODULES</ref><ref source="MISC" url="http://www.gtk.org/setuid.html">http://www.gtk.org/setuid.html</ref></refs><vuln_soft><prod name="GTK+" vendor="GTK"><vers num="1.2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0085" published="2001-02-12" seq="2001-0085" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2170">bid 2170</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5793.php">hpux-kermit-bo(5793)</ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2000-q4/0083.html">HPSBUX0012-135</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.20"/><vers num="10.10"/><vers num="10.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0086" published="2001-02-12" seq="2001-0086" severity="Medium" type="CVE"><desc><descript source="cve">CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0160.html">BUGTRAQ:20001212 Security Advisory: Subscribe Me Lite 1.0 - 2.0 Unix or 1.0 - 2.0 NT and below.</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2108">bid 2108</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5735.php">subscribemelite-gain-admin-access(5735)</ref></refs><vuln_soft><prod name="Subscribe Me Lite" vendor="CGI Script Center"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0087" published="2001-02-12" seq="2001-0087" severity="High" type="CVE"><desc><descript source="cve">itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2139">bid 2139</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0295.html">BUGTRAQ:20001219 itetris[v1.6.2] local root exploit (system()+../ protection)</ref><ref source="XF" url="http://xforce.iss.net/static/5795.php">itetris-svgalib-path</ref></refs><vuln_soft><prod name="itetris" vendor="Michael Glickman"><vers num="1.6.2"/><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0088" published="2001-02-16" seq="2001-0088" severity="High" type="CVE"><desc><descript source="cve">common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2047">bid 2047</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5625.php">phpweblog-bypass-authentication(5625)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0025.html">BUGTRAQ:20001202 Bypassing admin authentication in phpWebLog</ref></refs><vuln_soft><prod name="phpWebLog" vendor="Jason Hines"><vers num="0.4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0089" published="2001-02-16" seq="2001-0089" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE element in an HTML form, aka the &quot;File Upload via Form&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp">MS00-093</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5615.php">ie-form-file-upload(5615)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5" prev="1"/><vers num="5.01"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0090" published="2001-02-16" seq="2001-0090" severity="Medium" type="CVE"><desc><descript source="cve">The Print Templates feature in Internet Explorer 5.5 executes arbitrary custom print templates without prompting the user, which could allow an attacker to execute arbitrary ActiveX controls, aka the &quot;Browser Print Template&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2046">bid 2046</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp">MS00-093</ref><ref source="XF" url="http://xforce.iss.net/static/5614.php">ie-print-template(5614)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0091" published="2001-02-16" seq="2001-0091" severity="Low" type="CVE"><desc><descript source="cve">The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the &quot;Scriptlet Rendering&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1564">bid 1564</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp">MS00-093</ref><ref source="XF" url="http://xforce.iss.net/static/6085.php">ie-scriptlet-rendering-read-files(6085)</ref><ref source="OSVDB" url="http://www.osvdb.org/7820">7820</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5"/><vers num="5.01"/><vers num="5.0"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0092" published="2001-02-16" seq="2001-0092" severity="Low" type="CVE"><desc><descript source="cve">A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the &quot;Frame Domain Verification&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1224">bid 1224</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-093.asp">MS00-093</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6086">ie-frame-verification-read-files(6086)</ref><ref source="OSVDB" url="http://www.osvdb.org/7817">7817</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5"/><vers num="5.01"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0093" published="2001-02-12" seq="2001-0093" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="NetBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-017.txt.asc">NetBSD-SA2000-017</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0094" published="2001-02-12" seq="2001-0094" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in kdc_reply_cipher of libkrb (Kerberos 4 authentication library) in NetBSD 1.5 and FreeBSD 4.2 and earlier, as used in Kerberised applications such as telnetd and login, allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="NetBSD Security Advisory" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-017.txt.asc">Exploitable bugs in kerberised telnetd and libkrb</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:25.kerberosIV.asc">FreeBSD-SA-01:25</ref><ref source="XF" url="http://xforce.iss.net/static/5734.php">kerberos4-auth-packet-overflow(5734)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="1.5"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0095" published="2001-02-12" seq="2001-0095" severity="Low" type="CVE"><desc><descript source="cve">catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0313.html">BUGTRAQ:20001218 Catman file clobbering vulnerability Solaris 2.x</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5788.php">solaris-catman-symlink(5788)</ref><ref source="OSVDB" url="http://www.osvdb.org/6024">6024</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.7"/><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0096" published="2001-02-12" seq="2001-0096" severity="Medium" type="CVE"><desc><descript source="cve">FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the &quot;Malformed Web Form Submission&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS00-100.asp">MS00-100</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5823.php">iis-web-form-submit</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2001-0097" published="2001-02-12" seq="2001-0097" severity="Medium" type="CVE"><desc><descript source="cve">The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2140">bid 2140</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5798.php">infinite-interchange-dos</ref><ref source="Bugtraq" url="http://www.securityfocus.com/archive/1/152403">BUGTRAQ:20001221 Infinite InterChange DoS</ref></refs><vuln_soft><prod name="Infinite Interchange" vendor="Infinite"><vers num="3.61"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-04" name="CVE-2001-0098" published="2001-02-12" seq="2001-0098" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a &quot;..&quot;  string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0331.html">BUGTRAQ:20001219 def-2000-04: Bea WebLogic Server dotdot-overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2138">bid 2138</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5782.php">weblogic-dot-bo</ref></refs><vuln_soft><prod name="WebLogic Server" vendor="BEA Systems"><vers num="4.5.2 SP2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0099" published="2001-02-12" seq="2001-0099" severity="High" type="CVE"><desc><descript source="cve">bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html">BUGTRAQ:20001221 BS Scripts Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5796.php">bsguest-cgi-execute-commands</ref><ref patch="1" source="Stanback" url="http://www.stanback.net/"></ref><ref source="XF" url="http://xforce.iss.net/static/5796.php">bsguest-cgi-execute-commands</ref></refs><vuln_soft><prod name="bsguest.cgi" vendor="Brian Stanback"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0100" published="2001-02-12" seq="2001-0100" severity="High" type="CVE"><desc><descript source="cve">bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0390.html">BUGTRAQ:20001221 BS Scripts Vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5797.php">bslist-cgi-execute-commands</ref><ref patch="1" source="Stanback" url="http://www.stanback.net/"></ref></refs><vuln_soft><prod name="bslist.cgi" vendor="Brian Stanback"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0101" published="2001-02-12" seq="2001-0101" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref patch="1" source="TurboLinux Security" url="http://www.turbolinux.com/pipermail/tl-security-announce/2000-December/000027.html">TLSA2000024-1</ref><ref adv="1" source="Redhat" url="http://www.redhat.com/support/errata/RHBA-2000-106.html">RHBA-2000:106-04</ref><ref patch="1" source="XF" url="http://xforce.iss.net/static/7455.php">fetchmail-authenticate-gssapi(7455)</ref></refs><vuln_soft><prod name="fetchmail" vendor="Eric Raymond"><vers num="5.5.0.2" prev="1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.0"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2001-0102" published="2001-02-12" seq="2001-0102" severity="High" type="CVE"><desc><descript source="cve">&quot;Multiple Users&quot; Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users &amp; Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0497.html">BUGTRAQ:20001229 Mac OS 9 Multiple Users Control Panel Password Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5830.php">macos-multiple-users</ref></refs><vuln_soft><prod name="Mac OS" vendor="Apple"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-01-03" name="CVE-2001-0103" published="2001-02-12" seq="2001-0103" severity="Medium" type="CVE"><desc><descript source="cve">CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2107">bid 2107</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5744.php">coffeecup-ftp-weak-encryption(5744)</ref></refs><vuln_soft><prod name="CoffeeCup Direct FTP" vendor="CoffeeCup Software"><vers num="1.0"/></prod><prod name="CoffeeCup Free FTP" vendor="CoffeeCup Software"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0104" published="2001-02-12" seq="2001-0104" severity="High" type="CVE"><desc><descript source="cve">MDaemon Pro 3.5.1 and earlier allows local users to bypass the &quot;lock server&quot; security setting by pressing the Cancel button at the password prompt, then pressing the enter key.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2115">bid 2115</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5763.php">mdaemon-lock-bypass-password(5763)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/151156">20001214 Bypass MDaemon 3.5.1 &quot;Lock Server&quot; Protection</ref></refs><vuln_soft><prod name="MDaemon" vendor="Alt-N"><vers num="3.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0105" published="2001-02-12" seq="2001-0105" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the &quot;sys&quot; group.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5773.php">hp-top-sys-files(5773)</ref><ref patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2000-q4/0079.html">HPSBUX0012-134</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10"/><vers num="11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0106" published="2001-02-12" seq="2001-0106" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the &quot;swait&quot; state is used by a server.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2001-q1/0009.html">HPSBUX0101-136</ref><ref source="XF" url="http://xforce.iss.net/static/5904.php">hp-inetd-swait-dos(5904)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.04" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2001-0107" published="2001-03-12" seq="2001-0107" severity="Medium" type="CVE"><desc><descript source="cve">Veritas Backup agent on Linux allows remote attackers to cause a denial of service by establishing a connection without sending any data, which causes the process to hang.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2204">bid 2204</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958921407182&amp;w=2">BUGTRAQ:20010115 Veritas BackupExec (remote DoS)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958921407182&amp;w=2">20010115 Veritas BackupExec (remote DoS)</ref></refs><vuln_soft><prod name="Backup" vendor="Symantec Veritas"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0108" published="2001-03-12" seq="2001-0108" severity="Medium" type="CVE"><desc><descript source="cve">PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2206">bid 2206</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/156202">BUGTRAQ:20010112 PHP Security Advisory - Apache Module bugs</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97957961212852">20010112 PHP Security Advisory - Apache Module bugs</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-013.php3">MDKSA-2001:013</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000373">CLA-2001:373</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-020">DSA-020</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-136.html">RHSA-2000:136</ref><ref source="XF" url="http://xforce.iss.net/static/5940.php">php-htaccess-unauth-access(5940)</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/></prod><prod name="PHP" vendor="PHP"><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0109" published="2001-03-12" seq="2001-0109" severity="Low" type="CVE"><desc><descript source="cve">rctab in SuSE 7.0 and earlier allows local users to create or overwrite arbitrary files via a symlink attack on the rctmp temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2207">bid 2207</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0226.html">BUGTRAQ:20010113 Serious security flaw in SuSE rctab</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0272.html">20010117 Re: Serious security flaw in SuSE rctab</ref><ref source="XF" url="http://xforce.iss.net/static/5945.php">rctab-elevate-privileges(5945)</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0110" published="2001-03-12" seq="2001-0110" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2209">bid 2209</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0228.html">BUGTRAQ:20010114 Vulnerability in jaZip.</ref><ref patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-017">DSA-017-1 jazip: buffer overflow</ref><ref source="XF" url="http://xforce.iss.net/static/5942.php">jazip-display-bo(5942)</ref></refs><vuln_soft><prod name="JaZip" vendor="Iomega"><vers num="0.32.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0111" published="2001-03-12" seq="2001-0111" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in splitvt before 1.6.5 allows local users to execute arbitrary commands via the -rcfile command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2210">bid 2210</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958269320974&amp;w=2">BUGTRAQ:20010114 [MSY] Multiple vulnerabilities in splitvt</ref><ref patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-014">DSA-014-2 splitvt</ref><ref source="XF" url="http://xforce.iss.net/static/5948.php">splitvt-perserc-format-string(5948)</ref></refs><vuln_soft><prod name="splitvt" vendor="Sam Lantinga"><vers num="1.6.4"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2 sparc"/><vers num="2.2 powerpc"/><vers num="2.2 arm"/><vers num="2.2 alpha"/><vers num="2.2 68k"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0112" published="2001-03-12" seq="2001-0112" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2210">bid 2210</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958269320974&amp;w=2">BUGTRAQ:20010114 [MSY] Multiple vulnerabilities in splitvt</ref><ref patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-014">DSA-014-2</ref></refs><vuln_soft><prod name="splitvt" vendor="Sam Lantinga"><vers num="1.6.4" prev="1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2 sparc"/><vers num="2.2 powerpc"/><vers num="2.2 arm"/><vers num="2.2 alpha"/><vers num="2.2 68k"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0113" published="2001-03-12" seq="2001-0113" severity="High" type="CVE"><desc><descript source="cve">statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2211">bid 2211</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0248.html">BUGTRAQ:20010116 Vulnerabilities in OmniHTTPd default installation</ref></refs><vuln_soft><prod name="OmniHTTPD" vendor="Omnicron"><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0114" published="2001-03-12" seq="2001-0114" severity="Medium" type="CVE"><desc><descript source="cve">statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2211">bid 2211</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0248.html">20010116 Vulnerabilities in OmniHTTPd default installation</ref></refs><vuln_soft><prod name="OmniHTTPD" vendor="Omnicron"><vers num="2.0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0115" published="2001-03-12" seq="2001-0115" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in arp command in Solaris 7 and earlier allows local users to execute arbitrary commands via a long -f parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2193">bid 2193</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97957435729702&amp;w=2">BUGTRAQ:20010112 arp exploit</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97934312727101&amp;w=2">BUGTRAQ:20010111 Solaris Arp Vulnerability</ref><ref adv="1" patch="1" source="Sun Microsystems" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/200&amp;type=0&amp;nav=sec.sba">#00200</ref><ref source="XF" url="http://xforce.iss.net/static/5928.php">solaris-arp-bo(5928)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0116" published="2001-03-12" seq="2001-0116" severity="Low" type="CVE"><desc><descript source="cve">gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2188">bid 2188</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-006.php3">MDKSA-2001:006</ref><ref source="XF" url="http://xforce.iss.net/static/5917.php">linux-gpm-symlink(5917)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0117" published="2001-03-12" seq="2001-0117" severity="Low" type="CVE"><desc><descript source="cve">sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2191">bid 2191</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-008.php3">MDKSA-2001:008</ref><ref source="IMMUNIX" url="http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2000-70-028-01">IMNX-2000-70-028-01</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-116.html">RHSA-2001:116</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/579928">VU#579928</ref><ref source="XF" url="http://xforce.iss.net/static/5914.php">linux-diffutils-sdiff-symlink(5914)</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="1.0.1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Trustix Linux" vendor="Trustix"><vers num="1.2"/><vers num="1.1"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0118" published="2001-03-12" seq="2001-0118" severity="Low" type="CVE"><desc><descript source="cve">rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2195">bid 2195</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-005.php3">MDKSA-2001:005</ref><ref source="XF" url="http://xforce.iss.net/static/5925.php">rdist-symlink(5925)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0119" published="2001-03-12" seq="2001-0119" severity="Low" type="CVE"><desc><descript source="cve">getty_ps 2.0.7j allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2194">bid 2194</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-004.php3">MDKSA-2001:004</ref><ref source="XF" url="http://xforce.iss.net/static/5924.php">gettyps-symlink(5924)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0120" published="2001-03-12" seq="2001-0120" severity="Low" type="CVE"><desc><descript source="cve">useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2196">bid 2196</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-007.php3">MDKSA-2001:007</ref><ref source="XF" url="http://xforce.iss.net/static/5927.php">shadow-utils-useradd-symlink(5927)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0121" published="2001-03-12" seq="2001-0121" severity="Medium" type="CVE"><desc><descript source="cve">ImageCast Control Center 4.1.0 allows remote attackers to cause a denial of service (resource exhaustion or system crash) via a long string to port 12002.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0071.html">BUGTRAQ:20010108 def-2001-01: ImageCast IC3 Control Center DoS</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2174">bid 2174</ref><ref source="XF" url="http://xforce.iss.net/static/5901.php">storagesoft-imagecast-dos(5901)</ref></refs><vuln_soft><prod name="ImageCast IC3" vendor="StorageSoft"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2001-0122" published="2001-03-13" seq="2001-0122" severity="Medium" type="CVE"><desc><descript source="cve">Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a &quot;bad request&quot; error.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0079.html">BUGTRAQ:20010108 def-2001-02: IBM Websphere 3.52 Kernel Leak DoS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2175">bid 2175</ref><ref source="CONFIRM" url="http://www-4.ibm.com/software/webservers/security.html">http://www-4.ibm.com/software/webservers/security.html</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0061.html">20010307 def-2001-02: IBM HTTP Server Kernel Leak DoS (re-release)</ref><ref source="XF" url="http://xforce.iss.net/static/5900.php">ibm-websphere-dos(5900)</ref></refs><vuln_soft><prod name="IBM HTTP Server" vendor="IBM"><vers num="1.3.12.2"/></prod><prod name="Websphere Application Server" vendor="IBM"><vers num="3.52"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0123" published="2001-03-12" seq="2001-0123" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2177">bid 2177</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97905792214999&amp;w=2">BUGTRAQ:20010107 Cgisecurity.com Advisory #3.1</ref><ref source="CONFIRM" url="http://www.extropia.com/hacks/bbs_security.html">http://www.extropia.com/hacks/bbs_security.html</ref><ref source="XF" url="http://xforce.iss.net/static/5906.php">http-cgi-bbs-forum(5906)</ref><ref source="OSVDB" url="http://www.osvdb.org/3546">3546</ref></refs><vuln_soft><prod name="bbs_forum.cgi" vendor="Extropia"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0124" published="2001-03-12" seq="2001-0124" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in exrecover in Solaris 2.6 and earlier possibly allows local users to gain privileges via a long command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2179">bid 2179</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97908386502156&amp;w=2">BUGTRAQ:20010109 Solaris /usr/lib/exrecover buffer overflow</ref><ref source="XF" url="http://xforce.iss.net/static/5913.php">solaris-exrecover-bo(5913)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0125" published="2001-03-12" seq="2001-0125" severity="Low" type="CVE"><desc><descript source="cve">exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.</descript></desc><loss_types><int/></loss_types><vuln_types><exception/><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97846489313059&amp;w=2">BUGTRAQ:20001231 Advisory: exmh symlink vulnerability</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958594330100&amp;w=2">BUGTRAQ:20010112 exmh security vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5829.php">exmh-error-symlink(5829)</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-015.php3">MDKSA-2001:015</ref><ref adv="1" patch="1" source="" url="http://www.beedub.com/exmh/symlink.html"></ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-01/0543.html">FreeBSD-SA-01:17</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-022">DSA-022</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="1.0.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.0"/><vers num="7.1"/><vers num="6.0"/><vers num="6.1"/><vers num="7.2"/></prod><prod name="exmh" vendor="exmh"><vers num="2.2" prev="1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0126" published="2001-03-12" seq="2001-0126" severity="High" type="CVE"><desc><descript source="cve">Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97906670012796&amp;w=2">BUGTRAQ:20010109 Oracle XSQL servlet and xml-stylesheet allow</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98027700625521&amp;w=2">BUGTRAQ:20010123 Patch for Potential Vulnerability in Oracle XSQL Servlet</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98027700625521&amp;w=2">20010123 Patch for Potential Vulnerability in Oracle XSQL Servlet</ref><ref source="XF" url="http://xforce.iss.net/static/5905.php">oracle-xsql-execute-code(5905)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0127" published="2001-03-12" seq="2001-0127" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2214">bid 2214</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0236.html">BUGTRAQ:20010115 Flash plugin write-overflow</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/451096">VU#451096</ref></refs><vuln_soft><prod name="Flash" vendor="Oliver Debon"><vers num="0.4.9" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0128" published="2001-03-12" seq="2001-0128" severity="High" type="CVE"><desc><descript source="cve">Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5777.php">zope-calculate-roles(5777)</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-083.php3">MDKSA-2000:083</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:06.zope.asc">FreeBSD-SA-01:06</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/powertools/RHSA-2000-127.html">RHSA-2000:127-06</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2000/20001219">DSA-006-1 zope: privilege escalation</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000365">CLA-2000:365</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2000-127.html">RHSA-2000:127</ref><ref source="OSVDB" url="http://www.osvdb.org/6284">6284</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Linux" vendor="Red Hat"><vers num="6.1"/><vers num="6.2"/><vers num="7.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="4.2"/><vers num="5.0"/><vers num="5.1"/><vers num="6.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.2"/></prod><prod name="Zope" vendor="Zope"><vers num="2.2.4" prev="1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod><prod name="PowerTools" vendor="Linux"><vers num="6.1"/><vers num="6.2"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0129" published="2001-03-12" seq="2001-0129" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2217">bid 2217</ref><ref source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97975486527750&amp;w=2">BUGTRAQ:20010117 [pkc] remote heap overflow in tinyproxy</ref><ref patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-018">DSA-018-1 tinyproxy: remote nobody exploit</ref><ref source="XF" url="http://xforce.iss.net/static/5954.php">tinyproxy-remote-bo(5954)</ref></refs><vuln_soft><prod name="tinyproxy" vendor="tinyproxy"><vers num="1.3.3"/><vers num="1.3.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0130" published="2001-03-12" seq="2001-0130" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="SARC" url="http://service1.symantec.com/sarc/sarc.nsf/info/html/Lotus.Domino.Denial.of.Service.Malformed.HTML.Email.html">Alert-2001-001</ref><ref patch="1" source="Notes.net" url="http://www.notes.net/r5fixlist.nsf/6d4eae9850a5c2c28525690400551b57/b65bba0af4908187852569ee003c9d6e?OpenDocument">SPR # RTOA4L3QTQ</ref><ref source="XF" url="http://xforce.iss.net/static/6207.php">lotus-html-bo(6207)</ref></refs><vuln_soft><prod name="Domino R5 Client" vendor="Lotus"><vers num="5.04"/><vers num="5.05"/></prod><prod name="Domino R5 Server" vendor="Lotus"><vers num="5.04"/><vers num="5.05"/><vers num="5.06"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0131" published="2001-03-12" seq="2001-0131" severity="Low" type="CVE"><desc><descript source="cve">htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2182">bid 2182</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-021">DSA-021-1 apache: insecure tempfile bug, broken mod_rewrite</ref><ref source="XF" url="http://xforce.iss.net/static/5926.php">linux-apache-symlink(5926)</ref></refs><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num=""/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0132" published="2001-03-12" seq="2001-0132" severity="Low" type="CVE"><desc><descript source="cve">Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2213">bid 2213</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0235.html">BUGTRAQ:20010114 Trend Micro&apos;s VirusWall: Multiple vunerabilities</ref></refs><vuln_soft><prod name="InterScan VirusWall" vendor="Trend Micro"><vers num="3.6" prev="1"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0133" published="2001-03-12" seq="2001-0133" severity="High" type="CVE"><desc><descript source="cve">The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2212">bid 2212</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0235.html">BUGTRAQ:20010114 Trend Micro&apos;s VirusWall: Multiple vunerabilities</ref></refs><vuln_soft><prod name="InterScan VirusWall" vendor="Trend Micro"><vers num="3.6" prev="1"/><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0134" published="2001-03-12" seq="2001-0134" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2200">bid 2200</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97967435023835&amp;w=2">BUGTRAQ:20010116 iXsecurity.20001120.compaq-authbo.a</ref><ref patch="1" source="Compaq" url="http://www5.compaq.com/products/servers/management/agentsecurity.html">SSRT0705</ref></refs><vuln_soft><prod name="Insight Management Desktop Web Agents" vendor="Compaq"><vers num="3.7"/></prod><prod name="UNIX" vendor="Digital"><vers num="5.0"/><vers num="4.0g"/><vers num="4.0f"/></prod><prod name="Open SAN Manager" vendor="Compaq"><vers num="1.0"/></prod><prod name="Armada Insight Manager" vendor="Compaq"><vers num="4.20j"/><vers num="4.20"/></prod><prod name="Intelligent Cluster Administrator" vendor="Compaq"><vers num="2.1"/><vers num="1.0"/></prod><prod name="System Healthcheck" vendor="Compaq"><vers num="3.0"/></prod><prod name="Storage Allocation Reporter" vendor="Compaq"><vers num="1.0"/></prod><prod name="Insight Manager LC" vendor="Compaq"><vers num="1.50A"/><vers num="1.3c"/></prod><prod name="Survey Utility" vendor="Compaq"><vers num="2.33"/><vers num="2.18"/><vers num="2.17"/></prod><prod name="Management Agents" vendor="Compaq"><vers num="4.37E"/><vers num="4.36j"/><vers num="4.36E"/><vers num="4.35j"/><vers num="4.30j"/></prod><prod name="Compaq Foundation Agents" vendor="Compaq"><vers num="4.90"/><vers num="4.0"/><vers num="2.1"/><vers num="1.0"/></prod><prod name="Enterprise Volume Manager_Command Scripter" vendor="Compaq"><vers num="1.1"/><vers num="1.0"/></prod><prod name="SANWorks Resource Monitor" vendor="Compaq"><vers num="1.0"/></prod><prod name="Insight Manager XE" vendor="Compaq"><vers num="1.21"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0135" published="2001-03-12" seq="2001-0135" severity="Low" type="CVE"><desc><descript source="cve">The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2197">bid 2197</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97933458505857&amp;w=2">BUGTRAQ:20010112 UltraBoard cgi directory permission problem</ref></refs><vuln_soft><prod name="UltraBoard" vendor="UltraScripts"><vers num="2.11"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-16" name="CVE-2001-0136" published="2001-03-12" seq="2001-0136" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5801.php">proftpd-size-memory-leak(5801)</ref><ref source="Bugtraq" url="http://www.securityfocus.com/archive/1/152206">BUGTRAQ:20001220 ProFTPD 1.2.0 Memory leakage - denial of service</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0122.html">BUGTRAQ:20010109 Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0132.html">BUGTRAQ:20010110 Re: Memory leakage in ProFTPd leads to remote DoS (SIZE FTP); (Exploit Code)</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3">MDKSA-2001:021</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-029">DSA-029</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000380">CLA-2001:380</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html">20010213 Trustix Security Advisory - proftpd, kernel</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num=""/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num=""/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0137" published="2001-03-12" seq="2001-0137" severity="Medium" type="CVE"><desc><descript source="cve">Windows Media Player 7 allows remote attackers to execute malicious Java applets in Internet Explorer clients by enclosing the applet in a skin file named skin.wmz, then referencing that skin in the codebase parameter to an applet tag, aka the Windows Media Player Skins File Download&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2203">bid 2203</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958100816503&amp;w=2">BUGTRAQ:20010115 Windows Media Player 7 and IE java vulnerability - executing arbitrary programs</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-010.asp">MS01-010</ref><ref source="XF" url="http://xforce.iss.net/static/5937.php">win-mediaplayer-arbitrary-code(5937)</ref></refs><vuln_soft><prod name="Media Player" vendor="Microsoft"><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0138" published="2001-03-12" seq="2001-0138" severity="Low" type="CVE"><desc><descript source="cve">privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2189">bid 2189</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/linux/immunix/2001-q1/0010.html">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-001.php3">MDKSA-2001-001</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-016">DSA-016</ref><ref source="XF" url="http://xforce.iss.net/static/5915.php">linux-wuftpd-privatepw-symlink(5915)</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="1.0.1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2 sparc"/><vers num="2.2 powerpc"/><vers num="2.2 arm"/><vers num="2.2 alpha"/><vers num="2.2 68k"/><vers num="2.2"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0139" published="2001-03-12" seq="2001-0139" severity="Low" type="CVE"><desc><descript source="cve">inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2190">bid 2190</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/linux/immunix/2001-q1/0010.html">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref adv="1" patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-010.php3">MDKSA-2001:010</ref><ref adv="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-001.0.txt">CSSA-2001-001.0</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref><ref source="XF" url="http://xforce.iss.net/static/5916.php">linux-inn-symlink(5916)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="OpenLinux Desktop" vendor="Caldera"><vers num="2.3"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="OpenLinux eDesktop" vendor="Caldera"><vers num="2.4"/></prod><prod name="OpenLinux Eserver" vendor="Caldera"><vers num="2.3"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2 sparc"/><vers num="2.2 arm"/><vers num="2.2 alpha"/><vers num="2.2 68k"/><vers num="2.2"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0140" published="2001-03-12" seq="2001-0140" severity="Low" type="CVE"><desc><descript source="cve">arpwatch 2.1a4 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2183">bid 2183</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/linux/immunix/2001-q1/0010.html">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-002.php3">MDKSA-2001:002</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref><ref source="XF" url="http://xforce.iss.net/static/5922.php">tcpdump-arpwatch-symlink(5922)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-2001-0141" published="2001-03-12" seq="2001-0141" severity="Low" type="CVE"><desc><descript source="cve">mgetty 1.1.22 allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2187">bid 2187</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/linux/immunix/2001-q1/0010.html">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-009.php3">MDKSA-2001:009</ref><ref patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-011">DSA-011-1 mgetty: insecure tempfile handling</ref><ref patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-002.0.txt">CSSA-2001-002.0</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-050.html">RHSA-2001:050</ref><ref source="XF" url="http://xforce.iss.net/static/5918.php">linux-mgetty-symlink(5918)</ref></refs><vuln_soft><prod name="mgetty" vendor="Gert Doering"><vers num="1.1.22"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0142" published="2001-03-12" seq="2001-0142" severity="Low" type="CVE"><desc><descript source="cve">squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2184">bid 2184</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/linux/immunix/2001-q1/0010.html">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0212.html">BUGTRAQ:20010112 Trustix Security Advisory - diffutils squid</ref><ref adv="1" patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-003.php3">MDKSA-2001:003</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-019">DSA-019</ref><ref source="XF" url="http://xforce.iss.net/static/5921.php">squid-email-symlink(5921)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Trustix Linux" vendor="Trustix"><vers num="1.2"/><vers num="1.1"/></prod><prod name="Squid Web Proxy" vendor="National Science Foundation"><vers num="2.3 Stable4"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0143" published="2001-03-12" seq="2001-0143" severity="Low" type="CVE"><desc><descript source="cve">vpop3d program in linuxconf 1.23r and earlier allows local users to overwrite arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2186">bid 2186</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/linux/immunix/2001-q1/0010.html">BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-011.php3">MDKSA-2001:011</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916374410647&amp;w=2">20010110 Immunix OS Security update for lots of temp file problems</ref><ref source="XF" url="http://xforce.iss.net/static/5923.php">linuxconf-vpop3d-symlink(5923)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0144" published="2001-03-12" seq="2001-0144" severity="High" type="CVE"><desc><descript source="cve">CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2347">bid 2347</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98168366406903&amp;w=2">BUGTRAQ:20010208 [CORE SDI ADVISORY] SSH1 CRC-32 compensation attack detector</ref><ref adv="1" patch="1" source="Razor" url="http://razor.bindview.com/publish/advisories/adv_ssh1crc.html">Remote vulnerability in SSH daemon crc32 compensation attack detector</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2001-35.html">CA-2001-35</ref><ref source="OSVDB" url="http://www.osvdb.org/503">503</ref><ref source="OSVDB" url="http://www.osvdb.org/795">795</ref><ref source="XF" url="http://xforce.iss.net/static/6083.php">ssh-deattack-overwrite-memory(6083)</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.31"/><vers num="1.2.30"/><vers num="1.2.29"/><vers num="1.2.28"/><vers num="1.2.27"/><vers num="1.2.26"/><vers num="1.2.25"/><vers num="1.2.24"/></prod><prod name="OpenSSH" vendor="OpenBSD"><vers num="2.2"/><vers num="2.1.1"/><vers num="2.1"/><vers num="1.2.3"/><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0145" published="2001-05-03" seq="2001-0145" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-012.asp">MS01-012</ref><ref adv="1" patch="1" source="Atstake" url="http://www.atstake.com/research/advisories/2001/a022301-1.txt">A022301-1</ref></refs><vuln_soft><prod name="Outlook" vendor="Microsoft"><vers num="98"/><vers num="2000"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2001-0146" published="2001-06-02" seq="2001-0146" severity="Medium" type="CVE"><desc><descript source="cve">IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL&apos;s.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-014.asp">MS01-014</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/796584">VU#796584</ref><ref source="BID" url="http://www.securityfocus.com/bid/2440">2440</ref><ref source="BID" url="http://www.securityfocus.com/bid/2441">2441</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6171">iis-malformed-url-dos(6171)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6172">exchange-malformed-url-dos(6172)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="2000"/></prod><prod name="IIS" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0147" published="2001-05-03" seq="2001-0147" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Windows 2000 event viewer snap-in allows attackers to execute arbitrary commands via a malformed field that is improperly handled during the detailed view of event records.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-013.asp">MS01-013</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Professional"/><vers num="Server"/><vers num="Advanced Server"/><vers num="Datacenter Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0148" published="2001-06-02" seq="2001-0148" severity="High" type="CVE"><desc><descript source="cve">The WMP ActiveX Control in Windows Media Player 7 allows remote attackers to execute commands in Internet Explorer via javascript URLs, a variant of the &quot;Frame Domain Verification&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0000.html">31, 2001</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp">MS01-015</ref><ref source="XF" url="http://xforce.iss.net/static/6227.php">media-player-execute-commands(6227)</ref></refs><vuln_soft><prod name="Media Player" vendor="Microsoft"><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-04" name="CVE-2001-0149" published="2001-06-02" seq="2001-0149" severity="Medium" type="CVE"><desc><descript source="cve">Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetObject Javascript function and the htmlfile ActiveX object.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-09/0305.html">22,2000</ref><ref adv="1" patch="1" source="Neohapsis" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=96999020527583&amp;w=2"></ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp">MS01-015</ref><ref source="BID" url="http://www.securityfocus.com/bid/1718">1718</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5293">ie-getobject-expose-files(5293)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-04" name="CVE-2001-0150" published="2001-06-02" seq="2001-0150" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Unix (SFU) 2.0, which creates session transcripts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-015.asp">MS01-015</ref><ref source="BID" url="http://www.securityfocus.com/bid/2463">2463</ref><ref source="OSVDB" url="http://www.osvdb.org/7816">7816</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6230">ie-telnet-execute-commands(6230)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0151" published="2001-06-02" seq="2001-0151" severity="Medium" type="CVE"><desc><descript source="cve">IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-016.asp">MS01-016</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid/2453">bid 2453</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6205">iis-webdav-dos(6205)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:90">oval:org.mitre.oval:def:90</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0152" published="2001-05-03" seq="2001-0152" severity="Low" type="CVE"><desc><descript source="cve">The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-019.asp">MS01-019</ref></refs><vuln_soft><prod name="Plus" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0153" published="2001-05-03" seq="2001-0153" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in VB-TSQL debugger object (vbsdicli.exe) in Visual Studio 6.0 Enterprise Edition allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-018.asp">MS01-018</ref><ref adv="1" patch="1" source="" url="http://razor.bindview.com/publish/advisories/adv_vbtsql.html"></ref></refs><vuln_soft><prod name="Visual Studio" vendor="Microsoft"><vers edition="Enterprise" num="6.0"/></prod><prod name="Visual Basic" vendor="Microsoft"><vers edition="Enterprise" num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0154" published="2001-05-03" seq="2001-0154" severity="High" type="CVE"><desc><descript source="cve">HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-020.asp">MS01-020</ref><ref adv="1" source="" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98596775905044&amp;w=2"></ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2001-06.html">CA-2001-06</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-066.shtml">L-066</ref><ref source="BID" url="http://www.securityfocus.com/bid/2524">2524</ref><ref source="OSVDB" url="http://www.osvdb.org/7806">7806</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:141">oval:org.mitre.oval:def:141</ref><ref source="SECTRACK" url="http://securitytracker.com/id?1001197">1001197</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6306">ie-mime-execute-code(6306)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0155" published="2001-06-02" seq="2001-0155" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in VShell SSH gateway 1.0.1 and earlier allows remote attackers to execute arbitrary commands via a user name that contains format string specifiers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="atstake" url="http://www.atstake.com/research/advisories/2001/a021601-1.txt"></ref><ref source="CONFIRM" url="http://www.vandyke.com/products/vshell/security102.html">http://www.vandyke.com/products/vshell/security102.html</ref></refs><vuln_soft><prod name="Vshell" vendor="Van Dyke Technologies"><vers num="1.0.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0156" published="2001-06-02" seq="2001-0156" severity="Low" type="CVE"><desc><descript source="cve">VShell SSH gateway 1.0.1 and earlier has a default port forwarding rule of 0.0.0.0/0.0.0.0, which could allow local users conduct arbitrary port forwarding to other systems.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Atstake" url="http://www.atstake.com/research/advisories/2001/a021601-1.txt"></ref><ref source="CONFIRM" url="http://www.vandyke.com/products/vshell/security102.html">http://www.vandyke.com/products/vshell/security102.html</ref><ref source="XF" url="http://xforce.iss.net/static/6148.php">vshell-port-forwarding-rule(6148)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2402">2402</ref></refs><vuln_soft><prod name="Vshell" vendor="Van Dyke Technologies"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0157" published="2001-06-02" seq="2001-0157" severity="Medium" type="CVE"><desc><descript source="cve">Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even if the system lockout mechanism is enabled.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Atstake" url="http://www.atstake.com/research/advisories/2001/a030101-1.txt"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6196">palm-debug-bypass-password(6196)</ref></refs><vuln_soft><prod name="Palm OS" vendor="Palm"><vers num="3.5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2001-0160" published="2001-01-01" seq="2001-0160" severity="Medium" type="CVE"><desc><descript source="cve">Lucent/ORiNOCO WaveLAN cards generate predictable Initialization Vector (IV) values for the Wireless Encryption Protocol (WEP) which allows remote attackers to quickly compile information that will let them decrypt messages.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref></refs><vuln_soft><prod name="Lucent WaveLAN" vendor="Lucent"><vers num=""/></prod><prod name="ORiNOCO WaveLAN" vendor="ORiNOCO"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0161" published="2001-01-01" seq="2001-0161" severity="Medium" type="CVE"><desc><descript source="cve">Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref></refs><vuln_soft><prod name="Aironet" vendor="Cisco"><vers num="340-Series"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0162" published="2001-01-01" seq="2001-0162" severity="High" type="CVE"><desc><descript source="cve">WinCE 3.0.9348 generates predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MISC" url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref></refs><vuln_soft><prod name="Windows CE" vendor="Microsoft"><vers num="3.0.9348"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0163" published="2001-01-01" seq="2001-0163" severity="Medium" type="CVE"><desc><descript source="cve">Cisco AP340 base station produces predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MISC" url="http://www.cs.jhu.edu/~seny/pubs/wince802.pdf">http://www.cs.jhu.edu/~seny/pubs/wince802.pdf</ref></refs><vuln_soft><prod name="Aironet" vendor="Cisco"><vers num="AP340"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2001-0164" published="2001-06-02" seq="2001-0164" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Atstake" url="http://www.atstake.com/research/advisories/2001/a030701-1.txt"></ref><ref source="XF" url="http://xforce.iss.net/static/6233.php">netscape-directory-server-bo(6233)</ref></refs><vuln_soft><prod name="Netscape Directory Server" vendor="Netscape"><vers num="4.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0165" published="2001-05-03" seq="2001-0165" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long &quot;arg0&quot; (process name) argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2322">bid 2322</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0517.html">BUGTRAQ:20010131 [SPSadvisory#40]Solaris7/8 ximp40 shared library buffer overflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6039.php">solaris-ximp40-bo(6039)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0166" published="2001-03-26" seq="2001-0166" severity="High" type="CVE"><desc><descript source="cve">Macromedia Shockwave Flash plugin version 8 and earlier allows remote attackers to cause a denial of service via malformed tag length specifiers in a SWF file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0491.html">BUGTRAQ:20001229 Shockwave Flash buffer overflow</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5826.php">shockwave-flash-swf-bo(5826)</ref></refs><vuln_soft><prod name="Shockwave Flash Plugin" vendor="Macromedia"><vers num="8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2001-0167" published="2001-05-03" seq="2001-0167" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AT&amp;T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2305">bid 2305</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/6025.php">winvnc-client-bo(6025)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98088315825366&amp;w=2">BUGTRAQ:20010129 [CORE SDI ADVISORY] WinVNC client buffer overflow</ref></refs><vuln_soft><prod name="WinVNC" vendor="ATT"><vers num="3.3.3r7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2001-0168" published="2001-05-03" seq="2001-0168" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AT&amp;T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2306">bid 2306</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6026.php">winvnc-server-bo(6026)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=vnc-list&amp;m=98080763005455&amp;w=2">BUGTRAQ:20010129 [CORE SDI ADVISORY] WinVNC server buffer overflow</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/598581">VU#598581</ref></refs><vuln_soft><prod name="WinVNC" vendor="ATT"><vers num="3.3.3r7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0169" published="2001-03-26" seq="2001-0169" severity="Low" type="CVE"><desc><descript source="cve">When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2223">bid 2223</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5971.php">linux-glibc-preload-overwrite(5971)</ref><ref patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/157650">BUGTRAQ:20010121 Trustix Security Advisory - glibc</ref><ref adv="1" patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-012.php3?dis=7.2">MDKSA-2001:012</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2001-002.html">RHSA-2001:002-03</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_001_glibc_txt.html">SuSE-SA:2001:01</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-007.0.txt">CSSA-2001-007</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-039">DSA-039</ref><ref source="TURBO" url="http://archives.neohapsis.com/archives/linux/turbolinux/2001-q1/0004.html">TLSA2000021-2</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="1.0.1"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="Sparc" num="6.2"/><vers edition="i386" num="6.2"/><vers edition="Alpha" num="6.2"/><vers edition="Sparc" num="6.1"/><vers edition="i386" num="6.1"/><vers edition="Alpha" num="6.1"/><vers edition="Sparc" num="6.0"/><vers edition="i386" num="6.0"/><vers edition="Alpha" num="6.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/><vers num="7.0"/><vers num="6.1"/><vers num="6.0"/></prod><prod name="Turbolinux" vendor="TurboLinux"><vers num="6.1"/><vers num="6.0.5" prev="1"/></prod><prod name="Trustix Linux" vendor="Trustix"><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2001-0170" published="2001-03-26" seq="2001-0170" severity="Low" type="CVE"><desc><descript source="cve">glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variables when executing setuid/setgid programs, which could allow local users to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2181">bid 2181</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0131.html">BUGTRAQ:20010110 Glibc Local Root Exploit</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0186.html">BUGTRAQ:20010110 [slackware-security] glibc 2.2 local vulnerability on setuid binaries</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5907.php">linux-glibc-read-files(5907)</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2001-001.html">RHSA-2001:001-06</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="7.0"/><vers edition="Alpha" num="7.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="6.0"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0es"/><vers num="4.0"/><vers num="graficas"/><vers num="ecommerce"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.3"/></prod><prod name="Immunix" vendor="Immunix"><vers num="7.0 Beta"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0171" published="2001-05-03" seq="2001-0171" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2318">bid 2318</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6028.php">slimserve-httpd-dos(6028)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0505.html">BUGTRAQ:20010130 DOS Vulnerability in SlimServe HTTPd</ref></refs><vuln_soft><prod name="SlimServe" vendor="Whitsoft"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0172" published="2001-03-26" seq="2001-0172" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2180">bid 2180</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5910.php">suse-reiserfs-long-filenames(5910)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0127.html">BUGTRAQ:20010109 major security bug in reiserfs (may affect SuSE Linux)</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/></prod><prod name="ReiserFS" vendor="Hans Reiser"><vers num="3.5.28"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0173" published="2001-05-03" seq="2001-0173" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2329">bid 2329</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6033.php">crazywwwboard-qdecoder-bo(6033)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0486.html">BUGTRAQ:20010130 Nobreak Tecnologies CrazyWWWBoard Remote Buffer Overflow</ref></refs><vuln_soft><prod name="qDecoder" vendor="qDecoder"><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0.1"/><vers num="5.0"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.0.1"/><vers num="4.0"/></prod><prod name="CrazyWWWBoard" vendor="Nobreak Technologies"><vers num="3.0.1"/><vers num="2000.0px"/><vers num="2000.0LEpx"/><vers num="98PE"/><vers num="98"/><vers num="2000px"/><vers num="2000LEpx"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0174" published="2001-05-03" seq="2001-0174" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Trend Micro Virus Buster 2001 8.00 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a large &quot;To&quot; address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0500.html">BUGTRAQ:20010130 Security hole in Virus Buster 2001</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6034.php">virusbuster-mua-bo(6034)</ref><ref patch="1" source="Trend Micro" url="http://www.antivirus.com/download/"></ref><ref source="OSVDB" url="http://www.osvdb.org/6138">6138</ref></refs><vuln_soft><prod name="Virus Buster 2001" vendor="Trend Micro"><vers num="8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0175" published="2001-03-26" seq="2001-0175" severity="Medium" type="CVE"><desc><descript source="cve">The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2273">bid 2273</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5985.php">netscape-fasttrack-cache-dos(5985)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98035833331446&amp;w=2">BUGTRAQ:20010124 iPlanet FastTrack/Enterprise 4.1 DoS clarifications</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98021351718874&amp;w=2">BUGTRAQ:20010122 def-2001-05: Netscape Fasttrack Server Caching DoS</ref></refs><vuln_soft><prod name="FastTrack" vendor="Netscape"><vers num="4.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0176" published="2001-03-26" seq="2001-0176" severity="High" type="CVE"><desc><descript source="cve">The setuid doroot program in Voyant Sonata 3.x executes arbitrary command line arguments, which allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2125">bid 2125</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0278.html">BUGTRAQ:20001218 More Sonata Conferencing software vulnerabilities.</ref><ref source="XF" url="http://xforce.iss.net/static/5787.php">sonata-command-execute(5787)</ref></refs><vuln_soft><prod name="Sonata" vendor="Voyant Technologies"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0177" published="2001-03-26" seq="2001-0177" severity="Medium" type="CVE"><desc><descript source="cve">WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone.</descript></desc><loss_types><avail/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2178">bid 2178</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5909.php">conferenceroom-developer-dos(5909)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/155388">BUGTRAQ:20010110 Vulnerable: Conference Room Professional-Developer Edititon.</ref></refs><vuln_soft><prod name="ConferenceRoom" vendor="WebMaster"><vers num="1.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0178" published="2001-03-26" seq="2001-0178" severity="Low" type="CVE"><desc><descript source="cve">kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5995.php">kde2-kdesu-retrieve-passwords(5995)</ref><ref adv="1" patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-018.php3?dis=7.2">MDKSA-2001:018</ref><ref adv="1" patch="1" source="SuSE" url="http://www.suse.com/de/support/security/2001_002_kdesu_txt.txt">SuSE-SA:2001:02</ref><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-005.0.txt">CSSA-2001-005.0</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2320">bid 2320</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_002_kdesu_txt.html">SuSE-SA:2001:02</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="1.0.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.0"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="7.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="6.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="6.1"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="OpenLinux eDesktop" vendor="Caldera"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2001-0179" published="2001-05-03" seq="2001-0179" severity="Medium" type="CVE"><desc><descript source="cve">Allaire JRun 3.0 allows remote attackers to list contents of the WEB-INF directory, and the web.xml file in the WEB-INF directory, via a malformed URL that contains a &quot;.&quot;</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6008.php">allaire-jrun-webinf-dotslash(6008)</ref><ref adv="1" patch="1" source="Allaire" url="http://www.allaire.com/handlers/index.cfm?ID=19546&amp;Method=Full">ASB01-02</ref></refs><vuln_soft><prod name="JRun" vendor="Macromedia"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0180" published="2001-05-03" seq="2001-0180" severity="High" type="CVE"><desc><descript source="cve">Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the &quot;email&quot; parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/6027.php">guestserver-cgi-execute-commands(6027)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0471.html">BUGTRAQ:20010129 Remote Command Execution in guestserver.cgi + exploit</ref></refs><vuln_soft><prod name="Guestserver" vendor="Lars Ellingsen"><vers num="4.12" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0181" published="2001-03-26" seq="2001-0181" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2215">bid 2215</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5953.php">dhcp-format-string(5953)</ref><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-003.0.txt">CSSA-2001-003.0</ref></refs><vuln_soft><prod name="OpenLinux Desktop" vendor="Caldera"><vers num="2.3"/></prod><prod name="OpenLinux eDesktop" vendor="Caldera"><vers num="2.4"/></prod><prod name="OpenLinux eServer" vendor="Caldera"><vers num="2.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0182" published="2001-03-26" seq="2001-0182" severity="Medium" type="CVE"><desc><descript source="cve">FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2238">bid 2238</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5966.php">fw1-limited-license-dos(5966)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0298.html">BUGTRAQ:20010117 Licensing Firewall-1 DoS Attack</ref><ref source="OSVDB" url="http://www.osvdb.org/1733">1733</ref></refs><vuln_soft><prod name="Firewall-1" vendor="Checkpoint"><vers num="4.1 SP3"/><vers num="4.1 SP2"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0183" published="2001-03-26" seq="2001-0183" severity="High" type="CVE"><desc><descript source="cve">ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag in a TCP packet, which makes the packet appear to be part of an established connection.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2293">bid 2293</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5998.php">ipfw-bypass-firewall(5998)</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:08.ipfw.asc">FreeBSD-SA-01:08</ref><ref source="BUGTRAQ" url="http://www.security-express.com/archives/bugtraq/2001-01/0424.html">20010125 ecepass - proof of concept code for FreeBSD ipfw bypass</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-029.shtml">L-029</ref><ref source="OSVDB" url="http://www.osvdb.org/1743">1743</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5998">ipfw-bypass-firewall(5998)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0 alpha"/><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.1"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0184" published="2001-03-26" seq="2001-0184" severity="Low" type="CVE"><desc><descript source="cve">eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2278">bid 2278</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5981.php">eeye-iris-dos(5981)</ref><ref source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0343.html">BUGTRAQ:20010121 eEye Iris the Network traffic analyser DoS</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0352.html">BUGTRAQ:20010121 eEye Iris the Network traffic analyser DoS</ref></refs><vuln_soft><prod name="IRIS" vendor="EEye Digital Security"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0185" published="2001-03-26" seq="2001-0185" severity="Medium" type="CVE"><desc><descript source="cve">Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router&apos;s telnet program to connect to the router&apos;s IP address, which causes a crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/157952">BUGTRAQ:20010123 Make The Netopia R9100 Router To Crash</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2287">bid 2287</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6001.php">netopia-telnet-dos(6001)</ref></refs><vuln_soft><prod name="R9100 Router" vendor="Netopia"><vers num="4.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0186" published="2001-05-03" seq="2001-0186" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0061.html">BUGTRAQ:20010204 Vulnerability in Free Java Web Server</ref></refs><vuln_soft><prod name="Free Java Web Server" vendor="Free Java Web Server"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2001-0187" published="2001-03-26" seq="2001-0187" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2296">bid 2296</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6020.php">wuftp-debug-format-string(6020)</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-016">DSA-016-3 wu-ftpd: temp file creation and format string</ref><ref source="CONFIRM" url="ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch">ftp://ftp.wu-ftpd.org/pub/wu-ftpd/patches/apply_to_current/missing_format_strings.patch</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000443">CLA-2001:443</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.6"/><vers num="2.5"/><vers edition="academ" num="2.4.2 Beta9"/><vers edition="academ" num="2.4.2 Beta18"/><vers num="2.4.2 VR17"/><vers num="2.4.2 VR16"/><vers num="2.4.2 Beta18 VR9"/><vers num="2.4.2 Beta18 VR8"/><vers num="2.4.2 Beta18 VR7"/><vers num="2.4.2 Beta18 VR6"/><vers num="2.4.2 Beta18 VR5"/><vers num="2.4.2 Beta18 VR4"/><vers num="2.4.2 Beta18 VR15"/><vers num="2.4.2 Beta18 VR14"/><vers num="2.4.2 Beta18 VR13"/><vers num="2.4.2 Beta18 VR12"/><vers num="2.4.2 Beta18 VR11"/><vers num="2.4.2 Beta18 VR10"/><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0188" published="2001-03-26" seq="2001-0188" severity="Medium" type="CVE"><desc><descript source="cve">GoodTech FTP server 3.0.1.2.1.0 and earlier allows remote attackers to cause a denial of service via a flood of connections to the server, which causes it to crash.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2270">bid 2270</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5984.php">goodtech-ftp-dos(5984)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0350.html">BUGTRAQ:20010122 def-2001-03: GoodTech Systems FTP Connection DoS</ref></refs><vuln_soft><prod name="FTP Server 95_98" vendor="GoodTech"><vers num="3.0.1"/></prod><prod name="FTP Server NT_2000" vendor="GoodTech"><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0189" published="2001-03-26" seq="2001-0189" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .. (dot dot) attack in an HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2268">bid 2268</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5982.php">localweb2k-directory-traversal(5982)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0346.html">BUGTRAQ:20010119 LocalWEB2000 Directory Traversal Vulnerability</ref></refs><vuln_soft><prod name="LocalWEB2000" vendor="Intranet-Server"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0190" published="2001-03-26" seq="2001-0190" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in /usr/bin/cu in Solaris 2.8 and earlier, and possibly other operating systems, allows local users to gain privileges by executing cu with a long program name (arg0).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97983943716311&amp;w=2">BUGTRAQ:20010117 Solaris /usr/bin/cu Vulnerability</ref><ref patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98028642319440&amp;w=2">BUGTRAQ:20010123 Solaris /usr/bin/cu Vulnerability</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98028642319440&amp;w=2">20010123 Solaris /usr/bin/cu Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6224">cu-argv-bo(6224)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.6"/><vers num="2.7"/><vers num="2.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0191" published="2001-05-03" seq="2001-0191" severity="High" type="CVE"><desc><descript source="cve">gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0030.html">BUGTRAQ:20010202 Remote vulnerability in gnuserv/XEmacs</ref><ref patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2001-010.html">RHSA-2001:010-07</ref><ref patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2001-011.html">RHSA-2001:011-04</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-019.php3">MDKSA-2001:019</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6056">gnuserv-tcp-cookie-overflow(6056)</ref></refs><vuln_soft><prod name="gnuserv" vendor="Andy Norman"><vers num="3.11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0192" published="2001-05-03" seq="2001-0192" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0047.html">20010201 XMail CTRLServer remote buffer overflow vulnerability</ref><ref source="" url="http://xmailserver.org/XMail-Readme.txt"></ref></refs><vuln_soft><prod name="XMail" vendor="Davide Libenzi"><vers num="0.66" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0193" published="2001-05-03" seq="2001-0193" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2327">bid 2327</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-028">DSA-028-1 man-db: format string vulnerability</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98096782126481&amp;w=2">BUGTRAQ:20010131 SuSe / Debian man package format string vulnerability</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6059">man-i-format-string(6059)</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="7.0"/><vers num="6.4"/><vers num="6.3"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2 sparc"/><vers num="2.2 powerpc"/><vers num="2.2 arm"/><vers num="2.2 alpha"/><vers num="2.2 68k"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-2001-0194" published="2001-05-03" seq="2001-0194" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in httpGets function in CUPS 1.1.5 allows remote attackers to execute arbitrary commands via a long input line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-020.php3">MDKSA-2001:020</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6043">cups-httpgets-dos(6043)</ref><ref source="OSVDB" url="http://www.osvdb.org/6064">6064</ref></refs><vuln_soft><prod name="CUPS" vendor="Easy Software Products"><vers num="1.1.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2001-0195" published="2001-03-26" seq="2001-0195" severity="Low" type="CVE"><desc><descript source="cve">sash before 3.4-4 in Debian GNU/Linux does not properly clone /etc/shadow, which makes it world-readable and could allow local users to gain privileges via password cracking.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5994.php">linux-sash-shadow-readable(5994)</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-015">DSA-015-1 sash: broken maintainer script</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0196" published="2001-05-03" seq="2001-0196" severity="Medium" type="CVE"><desc><descript source="cve">inetd ident server in FreeBSD 4.x and earlier does not properly set group permissions, which allows remote attackers to read the first 16 bytes of files that are accessible by the wheel group.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2324">bid 2324</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:11.inetd.v1.1.asc">FreeBSD-SA-01:11</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6052">inetd-ident-read-files(6052)</ref><ref source="OSVDB" url="http://www.osvdb.org/1753">1753</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2"/><vers num="4.1.1"/><vers num="3.5.1"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0197" published="2001-03-26" seq="2001-0197" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2264">bid 2264</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0348.html">BUGTRAQ:20010121 [pkc] format bugs in icecast 1.3.8b2 and prior</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5978.php">icecast-format-string(5978)</ref><ref patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2001-004.html">RHSA-2001:004-04</ref><ref patch="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000374">CLSA-2001:374</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/><vers num="6.1"/><vers num="6.2"/><vers num="7.0"/></prod><prod name="Icecast" vendor="Icecast"><vers num="1.3.8 Beta2" prev="1"/><vers num="1.3.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2001-0198" published="2001-05-03" seq="2001-0198" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2328">bid 2328</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6040.php">quicktime-embedded-tag-bo(6040)</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98096678523370&amp;w=2">BUGTRAQ:20010131 [SPSadvisory#41]Apple Quick Time Plug-in Buffer Overflow</ref></refs><vuln_soft><prod name="Quicktime plugin" vendor="Apple"><vers edition="Japanese" num="4.1.2"/><vers num="4.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0199" published="2001-05-03" seq="2001-0199" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2335">bid 2335</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0064.html">BUGTRAQ:20010204 Vulnerability in SEDUM HTTP Server</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/651994">VU#651994</ref><ref source="OSVDB" url="http://www.osvdb.org/14797">14797</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6063">sedum-directory-traversal(6063)</ref></refs><vuln_soft><prod name="Sedum" vendor="Guido Frassetto"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0200" published="2001-05-03" seq="2001-0200" severity="Medium" type="CVE"><desc><descript source="cve">HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2336">bid 2336</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0052.html">BUGTRAQ:20010204 Web root exposure in HSWeb Webserver</ref></refs><vuln_soft><prod name="HSWeb" vendor="Heat-On Software"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0201" published="2001-03-26" seq="2001-0201" severity="High" type="CVE"><desc><descript source="cve">The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2230">bid 2230</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5972.php">postaci-sql-command-injection(5972)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0287.html">BUGTRAQ:20010117 Postaci allows arbitrary SQL query execution</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5972">postaci-sql-command-injection</ref></refs><vuln_soft><prod name="Postaci" vendor="Umut Gokbayrak"><vers num="1.1.3"/><vers num="1.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0202" published="2001-05-03" seq="2001-0202" severity="Medium" type="CVE"><desc><descript source="cve">Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2339">bid 2339</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0073.html">BUGTRAQ:20010205 Vulnerability in Picserver</ref></refs><vuln_soft><prod name="PicServer" vendor="Informs"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0203" published="2001-03-26" seq="2001-0203" severity="High" type="CVE"><desc><descript source="cve">Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2284">bid 2284</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5979.php">firebox-obtain-passphrase(5979)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0342.html">BUGTRAQ:20010120 Watchguard Firewall Elevated Privilege Vulnerability</ref></refs><vuln_soft><prod name="Firebox II" vendor="WatchGuard"><vers num="4.5"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0204" published="2001-06-02" seq="2001-0204" severity="Medium" type="CVE"><desc><descript source="cve">Watchguard Firebox II allows remote attackers to cause a denial of service by establishing multiple connections and sending malformed PPTP packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/162965">def-2001-07</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2369">2369</ref><ref source="XF" url="http://xforce.iss.net/static/6109.php">firebox-pptp-dos(6109)</ref></refs><vuln_soft><prod name="Firebox II" vendor="Watchguard"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0205" published="2001-05-03" seq="2001-0205" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting &quot;...&quot; into the requested pathname, a modified .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2343">bid 2343</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98148759123258&amp;w=2">BUGTRAQ:20010208 Vulnerability in AOLserver</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98168216003867&amp;w=2">BUGTRAQ:20010208 Vulnerability in AOLserver</ref></refs><vuln_soft><prod name="AOL Server" vendor="AOL"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0206" published="2001-06-02" seq="2001-0206" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0137.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2346">2346</ref></refs><vuln_soft><prod name="ServerWorx" vendor="Soft Lite"><vers num="3.00"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0207" published="2001-03-26" seq="2001-0207" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in bing allows remote attackers to execute arbitrary commands via a long hostname, which is copied to a small buffer after a reverse DNS lookup using the gethostbyaddr function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2279">bid 2279</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6036.php">linux-bing-bo(6036)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0330.html">BUGTRAQ:20010119 Buffer overflow in bing</ref><ref patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0333.html">BUGTRAQ:20010119 Buffer overflow in bing</ref></refs><vuln_soft><prod name="bing" vendor="Pierre Beyssac"><vers num="1.0.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0208" published="2001-06-02" seq="2001-0208" severity="Medium" type="CVE"><desc><descript source="cve">MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0205.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2359">2359</ref></refs><vuln_soft><prod name="Cobol" vendor="MicroFocus"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0209" published="2001-03-26" seq="2001-0209" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5965.php">shoutcast-description-bo(5965)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0305.html">20010118 Shoutcast Server Buffer Crashes Server</ref></refs><vuln_soft><prod name="DNAS" vendor="Shoutcast"><vers num="1.7.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0210" published="2001-06-02" seq="2001-0210" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/162259"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2361">2361</ref></refs><vuln_soft><prod name="Commerce.cgi" vendor="Carey Internet Service"><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0211" published="2001-06-02" seq="2001-0211" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0217.html"></ref><ref patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2362">2362</ref></refs><vuln_soft><prod name="WebSPIRS" vendor="SilverPlatter"><vers num="3.3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0212" published="2001-06-02" seq="2001-0212" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0218.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2367">2367</ref></refs><vuln_soft><prod name="Auktion" vendor="HIS"><vers num="1.62"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0213" published="2001-05-03" seq="2001-0213" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in pi program in PlanetIntra 2.5 allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6002.php">planetintra-pi-bo(6002)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0421.html">BUGTRAQ:200101125 [SAFER] Security Bulletin 010125.EXP.1.12</ref></refs><vuln_soft><prod name="Planet Intra" vendor="Planet Intra"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0214" published="2001-06-02" seq="2001-0214" severity="Medium" type="CVE"><desc><descript source="cve">Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0212.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2370">2370</ref></refs><vuln_soft><prod name="Way-board" vendor="Way"><vers num="CGI"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0215" published="2001-06-02" seq="2001-0215" severity="Medium" type="CVE"><desc><descript source="cve">ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0213.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2371"></ref><ref source="CONFIRM" url="http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html">http://www.roads.lut.ac.uk/lists/open-roads/2001/02/0001.html</ref><ref source="XF" url="http://xforce.iss.net/static/6097.php">roads-search-view-files(6097)</ref></refs><vuln_soft><prod name="ROADS" vendor="Martin Hamilton"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0216" published="2001-06-02" seq="2001-0216" severity="High" type="CVE"><desc><descript source="cve">PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0220.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2372"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6102">webpals-library-cgi-url(6102)</ref></refs><vuln_soft><prod name="WebPALS" vendor="mnSCU PALS"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0217" published="2001-06-02" seq="2001-0217" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0220.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2372"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6102">webpals-library-cgi-url(6102)</ref></refs><vuln_soft><prod name="WebPALS" vendor="mnSCU PALS"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0218" published="2001-05-03" seq="2001-0218" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in mars_nwe 0.99.pl19 allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2324">bid 2324</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6019.php">mars-nwe-format-string(6019)</ref><ref adv="1" patch="1" source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0081.html">FreeBSD-SA-01:20</ref><ref patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0456.html">FREEBSD:FreeBSD-SA-01:20</ref></refs><vuln_soft><prod name="Mars NWE" vendor="Martin Stover"><vers num="0.99 pl19"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0219" published="2001-03-26" seq="2001-0219" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in Support Tools Manager (xstm,cstm,stm) in HP-UX 11.11 and earlier allows local users to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2239">bid 2239</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5957.php">hp-stm-dos(5957)</ref><ref patch="1" source="HP" url="http://archives.neohapsis.com/archives/hp/2001-q1/0016.html">HPSBUX0101-137</ref><ref source="OSVDB" url="http://www.osvdb.org/6991">6991</ref><ref source="OSVDB" url="http://www.osvdb.org/7029">7029</ref><ref source="OSVDB" url="http://www.osvdb.org/7030">7030</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.11" prev="1"/><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0220" published="2001-06-02" seq="2001-0220" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0082.html"></ref></refs><vuln_soft><prod name="ko-helvis" vendor="ko-helvis"><vers num="1.8h2_1" prev="1"/></prod><prod name="ja-elvis" vendor="ja-elvis"><vers num="1.8.4_1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-14" name="CVE-2001-0221" published="2001-06-02" seq="2001-0221" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0079.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6073">ja-xklock-bo(6073)</ref></refs><vuln_soft><prod name="ja-xklock" vendor="FreeBSD"><vers num="2.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0222" published="2001-03-26" seq="2001-0222" severity="Low" type="CVE"><desc><descript source="cve">webmin 0.84 and earlier allows local users to overwrite and create arbitrary files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6011.php">linux-webmin-tmpfiles(6011)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2399">bid 2399</ref><ref patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-016.php3">MDKSA-2001:016</ref><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-004.0.txt">CSSA-2001-004.0</ref><ref source="XF" url="http://xforce.iss.net/static/6011.php">linux-webmin-tmpfiles</ref></refs><vuln_soft><prod name="Webmin" vendor="Webmin"><vers num="0.83"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0223" published="2001-03-26" seq="2001-0223" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in wwwwais allows remote attackers to execute arbitrary commands via a long QUERY_STRING (HTTP GET request).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5980.php">wwwwais-cgi-dos(5980)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97984174724339&amp;w=2">20010117 numerous holes</ref></refs><vuln_soft><prod name="wwwwais.25.c" vendor="spawar.navy.mil"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0224" published="2001-06-02" seq="2001-0224" severity="Medium" type="CVE"><desc><descript source="cve">Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0216.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2374">2374</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6093">muskat-empower-url-dir(6093)</ref></refs><vuln_soft><prod name="Muscat Empower" vendor="Brightstation"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0225" published="2001-06-02" seq="2001-0225" severity="High" type="CVE"><desc><descript source="cve">fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0127.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2349"></ref></refs><vuln_soft><prod name="Infobot" vendor="Lenzo"><vers num="0.44.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0226" published="2001-05-03" seq="2001-0226" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers tor ead arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0075.html">BUGTRAQ:20010205 Vulnerabilities in BiblioWeb Server</ref></refs><vuln_soft><prod name="BiblioWeb Server" vendor="Biblioscape"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0227" published="2001-05-03" seq="2001-0227" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0075.html">BUGTRAQ:20010205 Vulnerabilities in BiblioWeb Server</ref></refs><vuln_soft><prod name="BiblioWeb Server" vendor="Biblioscape"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0228" published="2001-05-03" seq="2001-0228" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0022.html">BUGTRAQ:20010202 GoAhead Web Server Directory Traversal Vulnerability</ref></refs><vuln_soft><prod name="GoAhead WebServer" vendor="GoAhead Software"><vers num="v.2.1"/><vers num="v.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-2001-0229" published="2001-05-03" seq="2001-0229" severity="High" type="CVE"><desc><descript source="cve">Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0112.html">BUGTRAQ:20010206 Security hole in ChiliSoft ASP on Linux.</ref></refs><vuln_soft><prod name="ChiliSoft" vendor="Sun"><vers num="3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-04" name="CVE-2001-0230" published="2001-06-02" seq="2001-0230" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in dc20ctrl before 0.4_1 in FreeBSD, and possibly other operating systems, allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2001-02/0083.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6077">dc20ctrl-port-bo(6077)</ref><ref source="OSVDB" url="http://www.osvdb.org/6081">6081</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="0.4_1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0231" published="2001-03-26" seq="2001-0231" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the &quot;t&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2172">bid 2172</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5898.php">newsdesk-cgi-read-files(5898)</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0042.html">BUGTRAQ:20010103 News Desk 1.2 CGI Vulnerbility</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/496064">VU#496064</ref></refs><vuln_soft><prod name="News Desk" vendor="ibrow"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0232" published="2001-03-26" seq="2001-0232" severity="Medium" type="CVE"><desc><descript source="cve">newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0042.html">BUGTRAQ:20010103 News Desk 1.2 CGI Vulnerbility</ref></refs><vuln_soft><prod name="News Desk" vendor="ibrow"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0233" published="2001-03-26" seq="2001-0233" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5962.php">micq-sprintf-remote-bo(5962)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0395.html">BUGTRAQ:20010124 patch Re: [PkC] Advisory #003: micq-0.4.6 remote buffer overflow</ref><ref patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2001-005.html">RHSA-2001:005-03</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-012">DSA-012-1 micq: remote buffer overflow</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:14.micq.asc">FreeBSD-SA-01:14</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0307.html">20010118 [PkC] Advisory #003: micq-0.4.6 remote buffer overflow</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/><vers num="6.1"/><vers num="6.2"/><vers num="7.0"/></prod><prod name="mICQ" vendor="Matthew Smith"><vers num="0.4.6" prev="1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0234" published="2001-05-03" seq="2001-0234" severity="High" type="CVE"><desc><descript source="cve">NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6010.php">newsdaemon-gain-admin-access(6010)</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0460.html">BUGTRAQ:20010126 NewsDaemon remote administrator access</ref><ref source="CONFIRM" url="http://sourceforge.net/forum/forum.php?forum_id=60570">http://sourceforge.net/forum/forum.php?forum_id=60570</ref></refs><vuln_soft><prod name="NewsDaemon" vendor="SourceForge"><vers num="0.21b"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0235" published="2001-03-26" seq="2001-0235" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in crontab allows local users to read crontab files of other users by replacing the temporary file that is being edited while crontab is running.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-024">DSA-024-1 cron: local insecure crontab handling</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:09.crontab.v1.1.asc">FreeBSD-SA-01:09</ref><ref source="BID" url="http://www.securityfocus.com/bid/2332">2332</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6225">crontab-read-files(6225)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0236" published="2001-05-03" seq="2001-0236" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris snmpXdmid SNMP to DMI mapper daemon allows remote attackers to execute arbitrary commands via a long &quot;indication&quot; event.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2417">BID:2417</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-05.html">http://www.cert.org/advisories/CA-2001-05.html</ref><ref adv="1" source="" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98462536724454&amp;w=2"></ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-065.shtml">L-065</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/207">00207</ref><ref source="XF" url="http://xforce.iss.net/static/6245.php">solaris-snmpxdmid-bo(6245)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0237" published="2001-06-27" seq="2001-0237" severity="Medium" type="CVE"><desc><descript source="cve">Memory leak in Microsoft 2000 domain controller allows remote attackers to cause a denial of service by repeatedly connecting to the Kerberos service and then disconnecting without sending any data.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98942093221908&amp;w=2">BUGTRAQ:20010509 def-2001-24: Windows 2000 Kerberos DoS</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-024.asp">MS:MS01-024</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/l-079.shtml">L-079</ref><ref source="XF" url="http://xforce.iss.net/static/6506.php">win2k-kerberos-dos(6506)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2707">2707</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Server"/><vers num="Advanced Server"/><vers num="Datacenter Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0238" published="2001-07-02" seq="2001-0238" severity="High" type="CVE"><desc><descript source="cve">Microsoft Data Access Component Internet Publishing Provider 8.103.2519.0 and earlier allows remote attackers to bypass Security Zone restrictions via WebDAV requests.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-022.asp">MS01-022</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-074.shtml">L-074</ref><ref source="XF" url="http://xforce.iss.net/static/6405.php">ms-dacipp-webdav-access(6405)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num=""/><vers num="SE"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Windows ME" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0239" published="2001-07-02" seq="2001-0239" severity="High" type="CVE"><desc><descript source="cve">Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/176912">SX-20010320-2</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/179986">BUGTRAQ:20010427 Microsoft ISA Server Vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/177160">SX-20010320-2b</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-021.asp">MS01-021</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2600">bid2600</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-073.shtml">L-073</ref><ref source="XF" url="http://xforce.iss.net/static/6383.php">isa-web-proxy-dos(6383)</ref></refs><vuln_soft><prod name="ISA Server" vendor="Microsoft"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0240" published="2001-06-27" seq="2001-0240" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-028.asp">MS:MS01-028</ref><ref source="XF" url="http://xforce.iss.net/static/6571.php">word-rtf-macro-execution(6571)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2753">2753</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="97"/><vers num="2000"/><vers edition="Japanese" num="98"/><vers edition="Mac" num="98"/><vers edition="Mac" num="2001"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0241" published="2001-06-27" seq="2001-0241" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98874912915948&amp;w=2">BUGTRAQ:20010501 Windows 2000 IIS 5.0 Remote buffer overflow vulnerability (Remote SYSTEM Level Access)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-023.asp">MS:MS01-023</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2674">BID:2674</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2001-10.html">CA-2001-10</ref><ref source="XF" url="http://xforce.iss.net/static/6485.php">iis-isapi-printer-bo(6485)</ref><ref source="OSVDB" url="http://www.osvdb.org/3323">3323</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1068">oval:org.mitre.oval:def:1068</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="Server"/><vers num="Professional"/><vers num="Datacenter Server"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0242" published="2001-06-27" seq="2001-0242" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the &quot;.ASX Buffer Overrun&quot; vulnerability as discussed in MS:MS00-090.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-029.asp">MS:MS01-029</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2677">BID:2677</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/181419">20010502 Microsoft Media Player ASX Parser buffer overflow vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/183906">20010506 Re: Microsoft Media Player ASX Parser buffer overflow vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/2686">2686</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/187528">VU#187528</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5574">mediaplayer-asx-bo(5574)</ref></refs><vuln_soft><prod name="Media Player" vendor="Microsoft"><vers num="6.4"/><vers num="6.3"/><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0243" published="2001-06-27" seq="2001-0243" severity="Medium" type="CVE"><desc><descript source="cve">Windows Media Player 7 and earlier stores Internet shortcuts in a user&apos;s Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Internet Zone, which allows remote attackers to read certain files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-029.asp">MS:MS01-029</ref><ref source="XF" url="http://xforce.iss.net/static/6584.php">mediaplayer-html-shortcut(6584)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2765">2765</ref></refs><vuln_soft><prod name="Media Player" vendor="Microsoft"><vers num="6.4"/><vers num="7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2001-0244" published="2001-06-27" seq="2001-0244" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Index Server 2.0 allows remote attackers to execute arbitrary commands via a long search parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-025.asp">MS:MS01-025</ref><ref source="BID" url="http://www.securityfocus.com/bid/2709">2709</ref><ref source="XF" url="http://xforce.iss.net/static/6517.php">winnt-indexserver-search-bo(6517)</ref></refs><vuln_soft><prod name="Index Server" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2001-0245" published="2001-06-27" seq="2001-0245" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Index Server 2.0 in Windows NT 4.0, and Indexing Service in Windows 2000, allows remote attackers to read server-side include files via a malformed search request, aka a new variant of the &quot;Malformed Hit-Highlighting&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-025.asp">MS:MS01-025</ref><ref source="XF" url="http://xforce.iss.net/static/6518.php">win-indexserver-view-files(6518)</ref></refs><vuln_soft><prod name="Index Server" vendor="Microsoft"><vers num="2.0"/></prod><prod name="Indexing Service" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0246" published="2001-06-27" seq="2001-0246" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the &quot;Frame Domain Verification&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-027.asp">MS:MS01-027</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0247" published="2001-06-18" seq="2001-0247" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Network Associates" url="http://www.pgp.com/research/covert/advisories/048.asp">NAI:20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-07.html">CERT:CA-2001-07</ref><ref patch="1" source="NetBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc">NETBSD:NetBSD-SA2000-018</ref><ref adv="1" patch="1" source="FreeBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0466.html">FREEBSD:FreeBSD-SA-01:33</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2548">018.txt.asc</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/048.asp">20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0466.html">FreeBSD-SA-01:33</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20010802-01-P">20010802-01-P</ref><ref source="XF" url="http://xforce.iss.net/static/6332.php">ftp-glob-expansion(6332)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.2.8"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.2"/></prod><prod name="Kerberos 5" vendor="MIT"><vers num="1.2.2"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1.1"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.8"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.5"/><vers num="1.4.3"/><vers num="1.4.2"/><vers num="1.4.1"/><vers num="1.4"/><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.5.8"/><vers num="6.5.7"/><vers num="6.5.6"/><vers num="6.5.5"/><vers num="6.5.4"/><vers num="6.5.3m"/><vers num="6.5.3f"/><vers num="6.5.3"/><vers num="6.5.2m"/><vers num="6.5.11"/><vers num="6.5.10"/><vers num="6.5.1"/><vers num="6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0248" published="2001-06-18" seq="2001-0248" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Network Associates" url="http://www.pgp.com/research/covert/advisories/048.asp">NAI:20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-07.html">CERT:CA-2001-07</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2552">BID:2552</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/048.asp">20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref><ref source="XF" url="http://xforce.iss.net/static/6332.php">ftp-glob-expansion(6332)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.30"/><vers num="10.20"/><vers num="10.10"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0249" published="2001-06-18" seq="2001-0249" severity="High" type="CVE"><desc><descript source="cve">Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Network Associates" url="http://www.pgp.com/research/covert/advisories/048.asp">NAI:20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-07.html">CERT:CA-2001-07</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2550">BID:2550</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/048.asp">20010409 Globbing Vulnerabilities in Multiple FTP Daemons</ref><ref source="XF" url="http://xforce.iss.net/static/6332.php">ftp-glob-expansion(6332)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers num="7.0"/><vers num="2.6"/><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0250" published="2001-06-02" seq="2001-0250" severity="Medium" type="CVE"><desc><descript source="cve">The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0396.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2285">Bugtraq id 2285</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5997.php">netscape-enterprise-list-directories(5997)</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0251" published="2001-06-02" seq="2001-0251" severity="Medium" type="CVE"><desc><descript source="cve">The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0422.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2294">Bugtraq id 2294</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/6003.php">netscape-enterprise-revlog-dos(6003)</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0252" published="2001-06-02" seq="2001-0252" severity="Medium" type="CVE"><desc><descript source="cve">iPlanet (formerly Netscape) Enterprise Server 4.1 allows remote attackers to cause a denial of service via a long HTTP GET request that contains many &quot;/../&quot; (dot dot) sequences.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/157641"></ref><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98035833331446&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2282">Bugtraq id 2282</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5983.php">netscape-enterprise-dot-dos(5983)</ref></refs><vuln_soft><prod name="iPlanet Enterprise Server" vendor="iPlanet"><vers num="4.1SP5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0253" published="2001-06-02" seq="2001-0253" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0463.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2314">Bugtraq id 2314</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6012.php">hyperseek-cgi-reveal-info(6012)</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/146704">VU#146704</ref></refs><vuln_soft><prod name="HyperSeek" vendor="iWeb Systems"><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0254" published="2001-06-02" seq="2001-0254" severity="Medium" type="CVE"><desc><descript source="cve">FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the &quot;pwd&quot; command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98021181215325&amp;w=2"></ref></refs><vuln_soft><prod name="FTP++ Server" vendor="Fastream"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0255" published="2001-06-02" seq="2001-0255" severity="Medium" type="CVE"><desc><descript source="cve">FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the &quot;ls&quot; command and including the drive letter name (e.g. C:) in the requested pathname.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98021181215325&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2267">Bugtraq id 2267</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5977.php">fastream-ftp-path-disclosure(5977)</ref></refs><vuln_soft><prod name="Fastream FTP++ Server" vendor="Fastream"><vers num="2.0"/></prod><prod name="Fastream FTP Server" vendor="Fastream"><vers num="2.0Beta 11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0256" published="2001-06-02" seq="2001-0256" severity="High" type="CVE"><desc><descript source="cve">FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98021181215325&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2261">Bugtraq id 2261</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5976.php">fastream-ftp-server-dos(5976)</ref></refs><vuln_soft><prod name="FTP++ Server" vendor="Fastream"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0257" published="2001-06-02" seq="2001-0257" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Easycom/Safecom Print Server Web service, version 404.590 and earlier, allows remote attackers to execute arbitrary commands via (1) a long URL or (2) a long HTTP header field such as &quot;Host:&quot;.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0375.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2291">Bugtraq id 2291</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5988.php">easycom-safecom-url-bo(5988)</ref></refs><vuln_soft><prod name="Easycom_Safecom Print Server" vendor="I-Data International"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0258" published="2001-06-02" seq="2001-0258" severity="Medium" type="CVE"><desc><descript source="cve">The Easycom/Safecom Print Server (firmware 404.590) PrintGuide server allows remote attackers to cause a denial of service via a large number of connections that send null characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0375.html"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5989.php">easycom-safecom-url-bo(5988)</ref></refs><vuln_soft><prod name="Easycom_Safecom Print Server" vendor="I-Data International"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0259" published="2001-06-02" seq="2001-0259" severity="Low" type="CVE"><desc><descript source="cve">ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user&apos;s private key file.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0262.html"></ref><ref adv="1" source="SSH" url="http://www.ssh.com/products/ssh/patches/secureRPCvulnerability.html">SSH1 Secure RPC Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2222">Bugtraq id 2222</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5963.php">ssh-rpc-private-key(5963)</ref></refs><vuln_soft><prod name="SSH Daemon" vendor="SSH Communications Security"><vers num="1.2.30"/><vers num="1.2.29"/><vers num="1.2.28"/><vers num="1.2.27"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0260" published="2001-06-02" seq="2001-0260" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long &quot;RCPT TO&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0360.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/5993.php">lotus-domino-smtp-bo(5993)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2283">Bugtraq id 2283</ref><ref source="OSVDB" url="http://www.osvdb.org/3321">3321</ref></refs><vuln_soft><prod name="Domino Mail Server" vendor="Lotus"><vers num="5.0.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0261" published="2001-06-02" seq="2001-0261" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97992179925715&amp;w=2"></ref><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98027311214976&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2243">Bugtraq id 2243</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5973.php">win2k-efs-recover-data(5973)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0262" published="2001-07-02" seq="2001-0262" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2001/a041301-1.txt">ATSTAKE:A041301-1</ref></refs><vuln_soft><prod name="SmartDownload" vendor="Netscape"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0263" published="2001-06-18" seq="2001-0263" severity="High" type="CVE"><desc><descript source="cve">Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the &quot;show relative paths&quot; option is not enabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2001/a040301-1.txt">ATSTAKE:A040301-1</ref><ref source="BID" url="http://online.securityfocus.com/bid/2537">2537</ref><ref source="XF" url="http://xforce.iss.net/static/6330.php">bpftp-obtain-credentials(6330)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2537">2537</ref></refs><vuln_soft><prod name="G6 FTP Server" vendor="Gene6"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0264" published="2001-06-18" seq="2001-0264" severity="Medium" type="CVE"><desc><descript source="cve">Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2001/a040301-1.txt">ATSTAKE:A040301-1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2534">BID:2534</ref></refs><vuln_soft><prod name="G6 FTP Server" vendor="Gene6"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2001-0265" published="2001-06-18" seq="2001-0265" severity="Low" type="CVE"><desc><descript source="cve">ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2001/a040901-1.txt">ATSTAKE:A040901-1</ref><ref source="XF" url="http://xforce.iss.net/static/6643.php">pgp-armor-code-execution(6643)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2556">2556</ref><ref source="OSVDB" url="http://www.osvdb.org/1782">1782</ref></refs><vuln_soft><prod name="PGP" vendor="PGP"><vers num="5"/><vers num="7.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0266" published="2001-05-03" seq="2001-0266" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in Software Distributor SD-UX in HP-UX 11.0 and earlier allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2001-q1/0069.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/6033">6033</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0267" published="2001-05-03" seq="2001-0267" severity="High" type="CVE"><desc><descript source="cve">NM debug in HP MPE/iX 6.5 and earlier does not properly handle breakpoints, which allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2001-q1/0050.html">HPSBMP0102-008</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6226">hp-nmdebug-gain-privileges(6226)</ref><ref source="OSVDB" url="http://www.osvdb.org/6032">6032</ref></refs><vuln_soft><prod name="MPE iX" vendor="HP"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2001-0268" published="2001-05-03" seq="2001-0268" severity="High" type="CVE"><desc><descript source="cve">The i386_set_ldt system call in NetBSD 1.5 and earlier, and OpenBSD 2.8 and earlier, when the USER_LDT kernel option is enabled, does not validate a call gate target, which allows local users to gain root privileges by creating a segment call gate in the Local Descriptor Table (LDT) with a target that specifies an arbitrary kernel address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/netbsd/2001-q1/0093.html">NetBSD Security Advisory 2001-002</ref><ref adv="1" patch="1" source="OpenBSD" url="http://www.openbsd.org/errata.htmluserldt">022: SECURITY FIX: Mar 2, 2001</ref><ref source="CALDERA" url="http://archives.neohapsis.com/archives/linux/caldera/2001-q4/0014.html">CSSA-2001-SCO.35</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0353.html">20010219 Re: your mail</ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html#userldt">20010302 The USER_LDT kernel option allows an attacker to gain access to privileged areas of kernel memory.</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/358960">VU#358960</ref><ref source="BID" url="http://www.securityfocus.com/bid/2739">2739</ref><ref source="OSVDB" url="http://www.osvdb.org/6141">6141</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6222">user-ldt-validation(6222)</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.8" prev="1"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0269" published="2001-05-03" seq="2001-0269" severity="High" type="CVE"><desc><descript source="cve">pam_ldap authentication module in Solaris 8 allows remote attackers to bypass authentication via a NULL password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0344.html"></ref><ref source="XF" url="http://xforce.iss.net/static/6440.php">solaris-pamldap-bypass-authentication(6440)</ref><ref source="OSVDB" url="http://www.osvdb.org/6030">6030</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0270" published="2001-05-03" seq="2001-0270" severity="Medium" type="CVE"><desc><descript source="cve">Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0349.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2400">Bugtraq id 2400</ref></refs><vuln_soft><prod name="ForeThought" vendor="Marconi"><vers num="6.2"/></prod><prod name="ASX-1000" vendor="Marconi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0271" published="2001-05-03" seq="2001-0271" severity="High" type="CVE"><desc><descript source="cve">mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0347.html"></ref><ref source="BID" url="http://www.securityfocus.com/bid/2391">
2391</ref></refs><vuln_soft><prod name="mailnews.cgi" vendor="mailnews.cgi"><vers num="1.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0272" published="2001-05-03" seq="2001-0272" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0259.html"></ref></refs><vuln_soft><prod name="sendtemp.pl" vendor="W3.org"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0273" published="2001-05-03" seq="2001-0273" severity="Low" type="CVE"><desc><descript source="cve">pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0367.html"></ref><ref adv="1" source="CERT-VN" url="http://www.kb.cert.org/vuls/id/566640">VU#566640</ref><ref source="BID" url="http://www.securityfocus.com/bid/2405">2405</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6135">pgp4pine-expired-keys(6135)</ref></refs><vuln_soft><prod name="pgp4pine" vendor="Holger Lamm"><vers num="1.75.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0274" published="2001-05-03" seq="2001-0274" severity="High" type="CVE"><desc><descript source="cve">kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0276.html"></ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0536.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6112">kicq-execute-commands(6112)</ref></refs><vuln_soft><prod name="KICQ" vendor="KICQ"><vers num="1.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0275" published="2001-05-03" seq="2001-0275" severity="Low" type="CVE"><desc><descript source="cve">Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0346.html"></ref></refs><vuln_soft><prod name="Netsuite Web Server" vendor="Moby"><vers num="1.02"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0276" published="2001-05-03" seq="2001-0276" severity="Medium" type="CVE"><desc><descript source="cve">ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98263019502565&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2390">Bugtraq id 2390</ref><ref source="CONFIRM" url="http://www.badblue.com/p010219.htm">http://www.badblue.com/p010219.htm</ref><ref source="XF" url="http://xforce.iss.net/static/6130.php">badblue-ext-reveal-path(6130)</ref></refs><vuln_soft><prod name="BadBlue" vendor="Working Resources Inc."><vers num="1.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0277" published="2001-05-03" seq="2001-0277" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98263019502565&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2392">Bugtraq id 2392</ref></refs><vuln_soft><prod name="BadBlue" vendor="Working Resources Inc."><vers num="1.2.7"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0278" published="2001-05-03" seq="2001-0278" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in linkeditor in HP MPE/iX 6.5 and earlier allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2001-q1/0050.html">HP:HPSBMP0102-009</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6223">hp-linkeditor-gain-privileges(6223)</ref></refs><vuln_soft><prod name="MPE iX" vendor="HP"><vers num="6.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0279" published="2001-05-03" seq="2001-0279" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0414.html"></ref><ref adv="1" patch="1" source="Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-024.php3">MDKSA-2001:024</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-031"></ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000381">CLA-2001:381</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-018.html">RHSA-2001:018</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-019.html">RHSA-2001:019</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0437.html">20010225 [slackware-security] buffer overflow in sudo fixed</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0427.html">20010226 Trustix Security Advisory - sudo</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="1.0.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/><vers num="7.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0280" published="2001-05-03" seq="2001-0280" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0413.html"></ref><ref source="XF" url="http://xforce.iss.net/static/6149.php">mercur-expn-bo(6149)</ref><ref source="OSVDB" url="http://www.osvdb.org/6027">6027</ref></refs><vuln_soft><prod name="MERCUR" vendor="Atrium Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0281" published="2001-05-03" seq="2001-0281" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0379.html"></ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0282" published="2001-05-03" seq="2001-0282" severity="High" type="CVE"><desc><descript source="cve">SEDUM 2.1 HTTP server allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0419.html"></ref><ref adv="1" source="Securiteam.com" url="http://www.securiteam.com/exploits/Sedum_HTTP_Server_vulnerable_to_directory_traversal.html"></ref></refs><vuln_soft><prod name="Sedum" vendor="Guido Frassetto"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0283" published="2001-05-03" seq="2001-0283" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0523.html"></ref></refs><vuln_soft><prod name="SunFTP" vendor="Sun"><vers num="build 9"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0284" published="2001-05-03" seq="2001-0284" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata.htmlipsec_ah"></ref><ref source="OPENBSD" url="http://www.openbsd.org/errata.html#ipsec_ah">20010302 Insufficient checks in the IPSEC AH IPv4 option handling code can lead to a buffer overrun in the kernel.</ref><ref source="OSVDB" url="http://www.osvdb.org/6026">6026</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0285" published="2001-05-03" seq="2001-0285" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html"></ref></refs><vuln_soft><prod name="HTTP Server" vendor="a1webserver"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0286" published="2001-05-03" seq="2001-0286" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html"></ref></refs><vuln_soft><prod name="HTTP Server" vendor="a1webserver"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-27" name="CVE-2001-0287" published="2001-05-03" seq="2001-0287" severity="Low" type="CVE"><desc><descript source="cve">VERITAS Cluster Server (VCS) 1.3.0 on Solaris allows local users to cause a denial of service (system panic) via the -L option to the lltstat command.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Veritas" url="http://seer.support.veritas.com/docs/234326.htm"></ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0528.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/6025">6025</ref></refs><vuln_soft><prod name="Cluster Server" vendor="Symantec Veritas"><vers num="1.3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0288" published="2001-05-03" seq="2001-0288" severity="High" type="CVE"><desc><descript source="cve">Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/ios-tcp-isn-random-pub.shtml"></ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0289" published="2001-05-03" seq="2001-0289" severity="Medium" type="CVE"><desc><descript source="cve">Joe text editor 2.8 searches the current working directory (CWD) for the .joerc configuration file, which could allow local users to gain privileges of other users by placing a Trojan Horse .joerc file into a directory, then waiting for users to execute joe from that directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0490.html"></ref><ref adv="1" patch="1" source="Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-026.php3">MDKSA-2001:026</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-041"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-024.html">RHSA-2001:024</ref></refs><vuln_soft><prod name="Joe" vendor="Joseph Allen"><vers num="2.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0290" published="2001-05-03" seq="2001-0290" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0031.html"></ref></refs><vuln_soft><prod name="Mailman" vendor="Gnu"><vers num="2.0.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0291" published="2001-05-03" seq="2001-0291" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in post-query sample CGI program allows remote attackers to execute arbitrary commands via an HTTP POST request that contains at least 10001 parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0003.html"></ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0292" published="2001-05-03" seq="2001-0292" severity="High" type="CVE"><desc><descript source="cve">PHP-Nuke 4.4.1a allows remote attackers to modify a user&apos;s email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0525.html"></ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="4.4.1a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0293" published="2001-05-03" seq="2001-0293" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2426">BID:2426</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0508.html"></ref></refs><vuln_soft><prod name="FtpXQ" vendor="Datawizard"><vers num="2.0.93"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0294" published="2001-05-03" seq="2001-0294" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0511.html"></ref></refs><vuln_soft><prod name="TYPSoft FTP Server" vendor="TYPSoft"><vers num="0.85"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0295" published="2001-05-03" seq="2001-0295" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a &quot;dir *./../..&quot; command.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2444">BID:2444</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98390925726814&amp;w=2"></ref><ref source="" url="http://support.jgaa.com/?cmd=ShowArticle&amp;ID=31"></ref><ref source="OSVDB" url="http://www.osvdb.org/874">874</ref></refs><vuln_soft><prod name="War FTPD" vendor="Jarle Aase"><vers num="1.67b04"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0296" published="2001-05-03" seq="2001-0296" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0531.html"></ref></refs><vuln_soft><prod name="WFTPD Pro" vendor="Texas Imperial Software"><vers num="3.00"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0297" published="2001-05-03" seq="2001-0297" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2415">BID:2415</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/165523"></ref></refs><vuln_soft><prod name="Simple Server" vendor="Dattaraj Rao"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0298" published="2001-05-03" seq="2001-0298" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2425">BID:2425</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/165671">20010227 WebReflex 1.55 HTTPd DoS</ref></refs><vuln_soft><prod name="WebReflex" vendor="Sapio Design Ltd"><vers num="1.55"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0299" published="2001-06-02" seq="2001-0299" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97535202912588&amp;w=2"></ref><ref adv="1" patch="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97603879517777&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2054">Bugtraq id 2054</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5640">nokia-ip440-bo(5640)</ref><ref source="OSVDB" url="http://www.osvdb.org/6020">6020</ref></refs><vuln_soft><prod name="IP440" vendor="Nokia"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0300" published="2001-06-02" seq="2001-0300" severity="Low" type="CVE"><desc><descript source="cve">oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2000-12/0434.html"></ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/610904">VU#610904</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/5804">oracle-oidldap-write-permission(5804)</ref></refs><vuln_soft><prod name="oidldapd" vendor="Oracle"><vers num="2.1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0301" published="2001-05-03" seq="2001-0301" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Analog before 4.16 allows remote attackers to execute arbitrary commands by using the ALIAS command to construct large strings.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0264.html">SECURITY ADVISORY 13th February 2001</ref><ref adv="1" patch="1" source="Analog" url="http://www.analog.cx/security2.html">security2</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/redhat/2001-q1/0056.html">RHSA-2001:017-03</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-033">DSA-033-1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2377">Bugtraq id 2377</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6105">analog-alias-bo(6105)</ref><ref source="OSVDB" url="http://www.osvdb.org/1762">1762</ref></refs><vuln_soft><prod name="Analog" vendor="Stephen Turner"><vers num="4.90 Beta2" prev="1"/><vers num="4.15" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-23" name="CVE-2001-0302" published="2001-05-03" seq="2001-0302" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0316.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2381">Bugtraq id 2381</ref></refs><vuln_soft><prod name="Pi3Web" vendor="Pi3"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-23" name="CVE-2001-0303" published="2001-05-03" seq="2001-0303" severity="Medium" type="CVE"><desc><descript source="cve">tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0316.html"></ref><ref adv="1" patch="1" source="BID" url="http://www.securityfocus.com/bid/2381">2381</ref></refs><vuln_soft><prod name="Pi3Web" vendor="Pi3"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0304" published="2001-05-03" seq="2001-0304" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a &quot;\..&quot; (dot dot) in a URL request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98229372610440&amp;w=2"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2384">Bugtraq id 2384</ref></refs><vuln_soft><prod name="Resin" vendor="Caucho Technology"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0305" published="2001-05-03" seq="2001-0305" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0324.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2385">Bugtraq id 2385</ref></refs><vuln_soft><prod name="ES.One" vendor="Thinking Arts"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0306" published="2001-05-03" seq="2001-0306" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0332.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2386">Bugtraq id 2386</ref></refs><vuln_soft><prod name="WEBactive" vendor="ITAfrica"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-14" name="CVE-2001-0307" published="2001-05-03" seq="2001-0307" severity="High" type="CVE"><desc><descript source="cve">Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0314.html"></ref><ref source="" url="http://www.geocities.com/gzhangx/websrv/docs/security.html"></ref></refs><vuln_soft><prod name="Java HTTP Server" vendor="Bajie"><vers num="0.79" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2008-02-14" name="CVE-2001-0308" published="2001-05-03" seq="2001-0308" severity="High" type="CVE"><desc><descript source="cve">UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0314.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2388">Bugtraq id 2388</ref><ref source="" url="http://www.geocities.com/gzhangx/websrv/docs/security.html"></ref></refs><vuln_soft><prod name="Java HTTP Server" vendor="Bajie"><vers num="0.79" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0309" published="2001-06-02" seq="2001-0309" severity="Medium" type="CVE"><desc><descript source="cve">inetd in Red Hat 6.2 does not properly close sockets for internal services such as chargen, daytime, echo, etc., which allows remote attackers to cause a denial of service via a series of connections to the internal services.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2001-006.html">RHSA-2001:006-03</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6380">inetd-internal-socket-dos(6380)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0310" published="2001-06-02" seq="2001-0310" severity="Low" type="CVE"><desc><descript source="cve">sort in FreeBSD 4.1.1 and earlier, and possibly other operating systems, uses predictable temporary file names and does not properly handle when the temporary file already exists, which causes sort to crash and possibly impacts security-sensitive scripts.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/6038.php">sort-temp-file-abort(6038)</ref><ref source="FREEBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:13.sort.asc">FreeBSD-SA-01:13</ref><ref source="BID" url="http://www.securityfocus.com/bid/3960">3960</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1.1"/><vers num="3.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-14" name="CVE-2001-0311" published="2001-06-02" seq="2001-0311" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack client.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><range><local/></range><refs><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0102-142">HPSBUX0102-142</ref><ref source="HPBUG" url="http://archives.neohapsis.com/archives/hp/2001-q1/0022.html">PHSS_22914</ref><ref source="HPBUG" url="http://archives.neohapsis.com/archives/hp/2001-q1/0023.html">PHSS_22915</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6434">omniback-unauthorized-access(6434)</ref></refs><vuln_soft><prod name="OmniBackII" vendor="HP"><vers num="A.03.50"/></prod><prod name="HP-UX" vendor="HP"><vers num="11" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0312" published="2001-06-02" seq="2001-0312" severity="Medium" type="CVE"><desc><descript source="cve">IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere&apos;s host aliases list, which will bypass WebSphere processing.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-01/0446.html"></ref></refs><vuln_soft><prod name="WebSphere plugin" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0313" published="2001-06-02" seq="2001-0313" severity="Medium" type="CVE"><desc><descript source="cve">Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the network.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98053139231392&amp;w=2"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6004.php">borderware-ping-dos(6004)</ref></refs><vuln_soft><prod name="Firewall Server" vendor="BorderWare"><vers num="6.1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0314" published="2001-06-02" seq="2001-0314" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL in a link.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98053366805491&amp;w=2"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6009.php">aol-malformed-url-dos(6009)</ref></refs><vuln_soft><prod name="AOL Server" vendor="AOL"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0315" published="2001-06-02" seq="2001-0315" severity="High" type="CVE"><desc><descript source="cve">The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6013.php">mirc-bypass-password(6013)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98053777917287&amp;w=2">20010125 mIRC allows password protection to be bypassed</ref></refs><vuln_soft><prod name="mIRC" vendor="Khaled Mardam-Bey"><vers num="5.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0316" published="2001-05-03" seq="2001-0316" severity="Medium" type="CVE"><desc><descript source="cve">Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/caldera/2001-q1/0009.html">CSSA-2001-009.0</ref><ref adv="1" patch="1" source="Caldera" url="http://www.caldera.com/support/security/advisories/CSSA-2001-009.0.txt">CSSA-2001-009.0</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/2364">BID 2364</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-013.html">RHSA-2001:013</ref><ref source="BID" url="http://www.securityfocus.com/bid/2364">2364</ref><ref source="OSVDB" url="http://www.osvdb.org/6017">6017</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6079">linux-sysctl-read-memory(6079)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0317" published="2001-05-03" seq="2001-0317" severity="Low" type="CVE"><desc><descript source="cve">Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0267.html"></ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/caldera/2001-q1/0009.html">CSSA-2001-009.0</ref><ref adv="1" patch="1" source="Caldera" url="http://www.caldera.com/support/security/advisories/CSSA-2001-009.0.txt">CSSA-2001-009.0</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-013.html">RHSA-2001:013</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6080">linux-ptrace-modify-process(6080)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-26" name="CVE-2001-0318" published="2001-06-02" seq="2001-0318" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-029">DSA-029-2 proftpd</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0117.html"></ref><ref adv="1" patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-021.php3">MDKSA-2001:021</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97916525715657&amp;w=2">20010110 proftpd 1.2.0rc2 -- example of bad coding</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000380">CLA-2001:380</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6433">proftpd-format-string(6433)</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.2.0 rc2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0319" published="2001-05-03" seq="2001-0319" severity="High" type="CVE"><desc><descript source="cve">orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0072.html"></ref><ref adv="1" source="IBM" url="http://www-4.ibm.com/software/webservers/commerce/netcomletter.html"></ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/2350">Bugtraq id 2350</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6067">ibm-netcommerce-reveal-information(6067)</ref></refs><vuln_soft><prod name="Net.Commerce Hosting Server" vendor="IBM"><vers num="3.2"/><vers num="3.1.2"/><vers num="3.1.1"/></prod><prod name="WebSphere Commerce Suite Pro" vendor="IBM"><vers num="4.1.1"/><vers num="4.1"/></prod><prod name="WebSphere Commerce Suite Start" vendor="IBM"><vers num="4.1.1"/><vers num="4.1"/></prod><prod name="WebSphere Commerce Suite MarketPlace" vendor="IBM"><vers num="4.1"/></prod><prod name="Net.Commerce Start" vendor="IBM"><vers num="3.2"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/></prod><prod name="Net.Commerce" vendor="IBM"><vers num="3.0"/><vers num="2.0"/></prod><prod name="WebSphere Commerce Suite Service Provider" vendor="IBM"><vers num="3.2"/><vers num="3.1.2"/></prod><prod name="Net.Commerce Pro" vendor="IBM"><vers num="3.2"/><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0320" published="2001-05-03" seq="2001-0320" severity="High" type="CVE"><desc><descript source="cve">bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0425.html"></ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="4.4"/><vers num="4.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0321" published="2001-05-03" seq="2001-0321" severity="Medium" type="CVE"><desc><descript source="cve">opendir.php script in PHP-Nuke allows remote attackers to read arbitrary files by specifying the filename as an argument to the requesturl parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0214.html"></ref><ref source="XF" url="http://xforce.iss.net/static/6512.php">phpnuke-opendir-read-files(6512)</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0322" published="2001-06-02" seq="2001-0322" severity="Medium" type="CVE"><desc><descript source="cve">MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958685100219&amp;w=2"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2202">Bugtraq id 2202</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5938.php">ie-mshtml-dos(5938)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2000"/></prod><prod name="Outlook Express" vendor="Microsoft"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0323" published="2001-06-02" seq="2001-0323" severity="Medium" type="CVE"><desc><descript source="cve">The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing &quot;ICMP Fragmentation needed but Don&apos;t Fragment (DF) set&quot; packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=97958349623450&amp;w=2"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/5975.php">icmp-pmtu-dos(5975)</ref></refs></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0324" published="2001-05-03" seq="2001-0324" severity="Low" type="CVE"><desc><descript source="cve">Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/win2ksecadvice/2001-q1/0060.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2340">Bugtraq id 2340</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0325" published="2001-05-03" seq="2001-0325" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0031.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2342">Bugtraq id 2342</ref></refs><vuln_soft><prod name="RTP" vendor="QNX"><vers num="5.60"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-07" name="CVE-2001-0326" published="2001-05-03" seq="2001-0326" severity="High" type="CVE"><desc><descript source="cve">Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the &lt;&lt;ALL FILES&gt;&gt; FilePermission.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0255.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6438">oracle-jvm-file-permissions(6438)</ref><ref source="OSVDB" url="http://www.osvdb.org/5706">5706</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.7 r3"/></prod><prod name="Application Server 9iAS" vendor="Oracle"><vers num="Release 1.0.2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2001-0327" published="2001-07-02" seq="2001-0327" severity="Medium" type="CVE"><desc><descript source="cve">iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2001/a041601-1.txt">ATSTAKE:A041601-1</ref><ref source="CONFIRM" url="http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html">http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/276767">VU#276767</ref><ref source="OSVDB" url="http://www.osvdb.org/5704">5704</ref></refs><vuln_soft><prod name="iPlanet Web Server" vendor="iPlanet"><vers num="4.1 Enterprise" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0328" published="2001-06-27" seq="2001-0328" severity="Medium" type="CVE"><desc><descript source="cve">TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-09.html">CERT:CA-2001-09</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20030201-01-P">20030201-01-P</ref><ref source="SREASON" url="http://securityreason.com/securityalert/57">57</ref><ref source="SECUNIA" url="http://secunia.com/advisories/8044">8044</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0329" published="2001-06-27" seq="2001-0329" severity="High" type="CVE"><desc><descript source="cve">Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2001/a043001-1.txt">ATSTAKE:A043001-1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2670">BID:2670</ref><ref source="CONFIRM" url="http://www.mozilla.org/projects/bugzilla/security2_12.html">http://www.mozilla.org/projects/bugzilla/security2_12.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/1199">1199</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.8"/><vers num="2.6"/><vers num="2.4"/><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0330" published="2001-06-27" seq="2001-0330" severity="High" type="CVE"><desc><descript source="cve">Bugzilla 2.10 allows remote attackers to access sensitive information, including the database username and password, via an HTTP request for the globals.pl file, which is normally returned by the web server without being executed.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="@Stake" url="http://www.atstake.com/research/advisories/2001/a043001-1.txt">ATSTAKE:A043001-1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2671">BID:2671</ref><ref source="XF" url="http://xforce.iss.net/static/6489.php">bugzilla-gobalpl-gain-information(6489)</ref></refs><vuln_soft><prod name="Bugzilla" vendor="Mozilla"><vers num="2.8"/><vers num="2.6"/><vers num="2.4"/><vers num="2.10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0331" published="2001-06-27" seq="2001-0331" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Embedded Support Partner (ESP) daemon (rpc.espd) in IRIX 6.5.8 and earlier allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise76.php">ISS:20010509 Remote Buffer Overflow Vulnerability in IRIX Embedded Support Partner Infrastructure</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20010501-01-P">20010501-01-P</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/258632">VU#258632</ref><ref source="BID" url="http://www.securityfocus.com/bid/2714">2714</ref><ref source="OSVDB" url="http://www.osvdb.org/1822">1822</ref><ref source="XF" url="http://xforce.iss.net/static/6502.php">irix-espd-bo(6502)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.5.5"/><vers num="6.5.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0332" published="2001-06-27" seq="2001-0332" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the &quot;Frame Domain Verification&quot; vulnerability.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98609031517525&amp;w=2">BUGTRAQ:20010330 Security bug in Internet Explorer - MSScriptControl.ScriptControl</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-027.asp">MS:MS01-027</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0333" published="2001-06-27" seq="2001-0333" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and &quot;\&quot; characters twice.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98992056521300&amp;w=2">BUGTRAQ:20010515 NSFOCUS SA2001-02 : Microsoft IIS CGI Filename Decode Error Vulnerability</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp">MS:MS01-026</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2001-12.html">CA-2001-12</ref><ref source="XF" url="http://xforce.iss.net/static/6534.php">iis-url-decoding(6534)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2708">2708</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1018">oval:org.mitre.oval:def:1018</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1051">oval:org.mitre.oval:def:1051</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:37">oval:org.mitre.oval:def:37</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:78">oval:org.mitre.oval:def:78</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0334" published="2001-06-27" seq="2001-0334" severity="Medium" type="CVE"><desc><descript source="cve">FTP service in IIS 5.0 and earlier allows remote attackers to cause a denial of service via a wildcard sequence that generates a long string when it is expanded.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp">MS:MS01-026</ref><ref source="XF" url="http://xforce.iss.net/static/6535.php">iis-ftp-wildcard-dos(6535)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0335" published="2001-06-27" seq="2001-0335" severity="Medium" type="CVE"><desc><descript source="cve">FTP service in IIS 5.0 and earlier allows remote attackers to enumerate Guest accounts in trusted domains by preceding the username with a special sequence of characters.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp">MS:MS01-026</ref><ref source="XF" url="http://xforce.iss.net/static/6545.php">iis-ftp-domain-authentication(6545)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2719">2719</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0336" published="2001-06-27" seq="2001-0336" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft MS00-060 patch for IIS 5.0 and earlier introduces an error which allows attackers to cause a denial of service via a malformed request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp">MS:MS01-026</ref><ref source="XF" url="http://xforce.iss.net/static/6858.php">iis-crosssitescripting-patch-dos(6858)</ref><ref source="OSVDB" url="http://www.osvdb.org/5693">5693</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0337" published="2001-06-27" seq="2001-0337" severity="Medium" type="CVE"><desc><descript source="cve">The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-026.asp">MS:MS01-026</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0338" published="2001-06-27" seq="2001-0338" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.5 and earlier does not properly validate digital certificates when Certificate Revocation List (CRL) checking is enabled, which could allow remote attackers to spoof trusted web sites, aka the &quot;Server certificate validation vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Microsoft&#xa;Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-027.asp">MS:MS01-027</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-087.shtml">L-087</ref><ref source="XF" url="http://xforce.iss.net/static/6555.php">ie-crl-certificate-spoofing(6555)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2735">2735</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.01"/><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0339" published="2001-06-27" seq="2001-0339" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the &quot;Web page spoofing vulnerability.&quot;</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-027.asp">MS:MS01-027</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-087.shtml">L-087</ref><ref source="XF" url="http://xforce.iss.net/static/6556.php">ie-html-url-spoofing(6556)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2737">2737</ref><ref source="OSVDB" url="http://www.osvdb.org/5694">5694</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1096">oval:org.mitre.oval:def:1096</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2001-0340" published="2001-07-21" seq="2001-0340" severity="High" type="CVE"><desc><descript source="cve">An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user&apos;s mailbox via a message attachment that contains HTML code, which is executed automatically.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-030.asp">MS01-030</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-091.shtml">L-091</ref><ref source="XF" url="http://xforce.iss.net/static/6652.php">exchange-owa-script-execution(6652)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-24" name="CVE-2001-0341" published="2001-07-21" seq="2001-0341" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99348216322147&amp;w=2">SA2001-03</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-035.asp">MS01-035</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2906">bid2906</ref><ref source="XF" url="http://xforce.iss.net/static/6730.php">frontpage-ext-rad-bo(6730)</ref><ref source="OSVDB" url="http://www.osvdb.org/577">577</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="Workstation 4.0 SP6a"/><vers num="Workstation 4.0 SP6"/><vers num="Workstation 4.0 SP5"/><vers num="Workstation 4.0 SP4"/><vers num="Workstation 4.0 SP3"/><vers num="Workstation 4.0 SP2"/><vers num="Workstation 4.0 SP1"/><vers num="Workstation 4.0"/><vers num="Terminal Server 4.0 SP6"/><vers num="Terminal Server 4.0 SP5"/><vers num="Terminal Server 4.0 SP4"/><vers num="Terminal Server 4.0 SP3"/><vers num="Terminal Server 4.0 SP2"/><vers num="Terminal Server 4.0 SP1"/><vers num="Terminal Server 4.0"/><vers num="Server 4.0 SP6a"/><vers num="Server 4.0 SP6"/><vers num="Server 4.0 SP5"/><vers num="Server 4.0 SP4"/><vers num="Server 4.0 SP3"/><vers num="Server 4.0 SP2"/><vers num="Server 4.0 SP1"/><vers num="Server 4.0"/><vers num="Enterprise Server 4.0 SP6a"/><vers num="Enterprise Server 4.0 SP6"/><vers num="Enterprise Server 4.0 SP5"/><vers num="Enterprise Server 4.0 SP4"/><vers num="Enterprise Server 4.0 SP3"/><vers num="Enterprise Server 4.0 SP2"/><vers num="Enterprise Server 4.0 SP1"/><vers num="Enterprise Server 4.0"/></prod><prod name="FrontPage 2000 Server Extensions" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="Server SP2"/><vers num="Server SP1"/><vers num="Server"/><vers num="Professional SP2"/><vers num="Professional SP1"/><vers num="Professional"/><vers num="Datacenter Server SP2"/><vers num="Datacenter Server SP1"/><vers num="Datacenter Server"/><vers num="Advanced Server SP2"/><vers num="Advanced Server SP1"/><vers num="Advanced Server"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2001-0344" published="2001-07-21" seq="2001-0344" severity="High" type="CVE"><desc><descript source="cve">An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms01-032.asp">MS01-032</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-095.shtml">L-095</ref><ref source="XF" url="http://xforce.iss.net/static/6684.php">mssql-cached-connection-access(6684)</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:71">oval:org.mitre.oval:def:71</ref></refs><vuln_soft><prod name="SQL Server" vendor="Microsoft"><vers num="7.0"/><vers num="2000 Gold"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0345" published="2001-07-21" seq="2001-0345" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows 2000 telnet service allows attackers to prevent idle Telnet sessions from timing out, causing a denial of service by creating a large number of idle sessions.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp">MS01-031</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&amp;id=2843">bid 2843</ref><ref source="BID" url="http://www.securityfocus.com/bid/2843">2843</ref><ref source="XF" url="http://xforce.iss.net/static/6667.php">win2k-telnet-idle-sessions-dos(6667)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0346" published="2001-07-21" seq="2001-0346" severity="Medium" type="CVE"><desc><descript source="cve">Handle leak in Microsoft Windows 2000 telnet service allows attackers to cause a denial of service by starting a large number of sessions and terminating them.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp">MS01-031</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/cgi-bin/vulns-items.pl?section=info&amp;id=2844">bid 2844</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp">MS01-031</ref><ref source="XF" url="http://xforce.iss.net/static/6668.php">win2k-telnet-handle-leak-dos(6668)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0347" published="2001-07-21" seq="2001-0347" severity="High" type="CVE"><desc><descript source="cve">Information disclosure vulnerability in Microsoft Windows 2000 telnet service allows remote attackers to determine the existence of user accounts such as Guest, or log in to the server without specifying the domain name, via a malformed userid.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp">MS01-031</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-092.shtml">L-092</ref><ref source="BID" url="http://www.securityfocus.com/bid/2847">2847</ref><ref source="XF" url="http://xforce.iss.net/static/6665.php">win2k-telnet-domain-authentication(6665)</ref><ref source="OSVDB" url="http://www.osvdb.org/5686">5686</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0348" published="2001-07-21" seq="2001-0348" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command that contains a backspace.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp">MS01-031</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/bid=2838">bid 2838</ref><ref source="BINDVIEW" url="http://razor.bindview.com/publish/advisories/adv_mstelnet.html">20010608 Range checking fault condition in Microsoft Windows 2000 Telnet server</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-092.shtml">L-092</ref><ref source="XF" url="http://xforce.iss.net/static/6666.php">win2k-telnet-username-dos(6666)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0349" published="2001-07-21" seq="2001-0349" severity="High" type="CVE"><desc><descript source="cve">Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp">MS01-031</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/587587">VU#587587</ref><ref source="BID" url="http://www.securityfocus.com/bid/2849">2849</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6664">win2k-telnet-pipe-privileges(6664)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0350" published="2001-07-21" seq="2001-0350" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp">MS01-031</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6664">win2k-telnet-pipe-privileges(6664)</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0351" published="2001-07-21" seq="2001-0351" severity="Low" type="CVE"><desc><descript source="cve">Microsoft Windows 2000 telnet service allows a local user to make a certain system call that allows the user to terminate a Telnet session and cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-031.asp">MS01-031</ref><ref adv="1" patch="1" source="Security Focus" url="http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&amp;id=2846">bid 2846</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-092.shtml">L-092</ref><ref source="XF" url="http://xforce.iss.net/static/6669.php">win2k-telnet-system-call-dos(6669)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2846">2846</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0352" published="2001-07-21" seq="2001-0352" severity="Medium" type="CVE"><desc><descript source="cve">SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise84.php">Wired-side SNMP WEP key exposure in 802.11b Access Points</ref></refs><vuln_soft><prod name="AirConnect AP-4111" vendor="3Com"><vers num=""/></prod><prod name="41X1 Access Point" vendor="Symbol"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0353" published="2001-07-21" seq="2001-0353" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the line printer daemon (in.lpd) for Solaris 8 and earlier allows local and remote attackers to gain root privileges via a &quot;transfer job&quot; routine.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/6718.php">solaris-lpd-bo(6718)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise80.php">Remote Buffer Overflow Vulnerability in Solaris Print Protocol Daemon</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/206">00206</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2001-15.html">CA-2001-15</ref><ref source="BID" url="http://www.securityfocus.com/bid/2894">2894</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers edition="x86" num="2.6"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers num="8.0"/><vers edition="x86" num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0354" published="2001-07-02" seq="2001-0354" severity="Medium" type="CVE"><desc><descript source="cve">TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/178061">BUGTRAQ:20010420 CheckBO Win9x memo overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2634">bid2634</ref></refs><vuln_soft><prod name="CheckBo" vendor="TheNet"><vers num="1.56"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0355" published="2001-06-27" seq="2001-0355" severity="Medium" type="CVE"><desc><descript source="cve">Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAmisGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98185226715517&amp;w=2"></ref></refs><vuln_soft><prod name="Groupwise" vendor="Novell"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2001-0357" published="2001-08-22" seq="2001-0357" severity="High" type="CVE"><desc><descript source="cve">FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98433523520344&amp;w=2"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/6242.php">formmail-anonymous-flooding(6242)</ref></refs><vuln_soft><prod name="FormMail" vendor="Matt Wright"><vers num="1.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0358" published="2001-06-27" seq="2001-0358" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0111.html"></ref><ref adv="1" source="X-force" url="http://xforce.iss.net/static/6221.php">6221</ref><ref adv="1" source="X-force" url="http://xforce.iss.net/static/6218.php">6218</ref></refs><vuln_soft><prod name="Half-Life" vendor="Sierra"><vers num="1573" prev="1"/></prod><prod name="Half-Life" vendor="Valve Software"><vers num="1573" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0359" published="2001-06-27" seq="2001-0359" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0111.html"></ref><ref adv="1" source="X-force" url="http://xforce.iss.net/static/6220.php">6220</ref></refs><vuln_soft><prod name="Half-Life" vendor="Sierra"><vers num="1573" prev="1"/></prod><prod name="Half-Life Dedicated Server" vendor="Valve Software"><vers num="1573" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0360" published="2001-06-27" seq="2001-0360" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitary files via a .. (dot dot) attack in the helpon parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0124.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2471">bid 2471</ref><ref adv="1" patch="1" source="X-force" url="http://xforce.iss.net/static/6216.php">6216</ref></refs><vuln_soft><prod name="Ikonboard" vendor="Ikonboard.com"><vers num="2.1.7b" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.0" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="4.9" CVSS_score="4.0" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:N)" CVSS_version="2.0" modified="2008-05-19" name="CVE-2001-0361" published="2001-06-27" seq="2001-0361" severity="Medium" type="CVE"><desc><descript source="cve">Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a &quot;Bleichenbacher attack&quot; on PKCS#1 version 1.5.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Core" url="http://www.core-sdi.com/advisories/ssh1_sessionkey_recovery.htm">CORE-20010116</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2344">bid 2344</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98158450021686&amp;w=2">20010207 [CORE SDI ADVISORY] SSH1 session key recovery vulnerability</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-047.shtml">L-047</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:24.ssh.asc">FreeBSD-SA-01:24</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-023">DSA-023</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-027">DSA-027</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-086">DSA-086</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/adv004_ssh.html">SuSE-SA:2001:04</ref><ref source="XF" url="http://xforce.iss.net/static/6082.php">ssh-session-key-recovery(6082)</ref><ref source="OSVDB" url="http://www.osvdb.org/2116">2116</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.31" prev="1"/></prod><prod name="OpenSSH" vendor="OpenBSD"><vers num="2.1.1"/><vers num="2.1"/><vers num="1.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0364" published="2001-06-27" seq="2001-0364" severity="Medium" type="CVE"><desc><descript source="cve">SSH Communications Security sshd 2.4 for Windows allows remote attackers to create a denial of service via a large number of simultaneous connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98467799732241&amp;w=2">USSR-2001001</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2477">bid 2477</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6241.php">6241</ref></refs><vuln_soft><prod name="SSH2" vendor="SSH Communications Security"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0365" published="2001-06-27" seq="2001-0365" severity="High" type="CVE"><desc><descript source="cve">Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the &apos;Use Microsoft Viewer&apos; and &apos;allow executables in HTML content&apos; options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code within IMG tags.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98503741910995&amp;w=2"></ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6262.php">6262</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2490">2490</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num="5.1" prev="1"/><vers num="5.0.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0366" published="2001-06-27" seq="2001-0366" severity="High" type="CVE"><desc><descript source="cve">saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/180498">BUGTRAQ:20010429 SAP R/3 Web Application Server Demo for Linux: root exploit</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2662">BID:2662</ref><ref source="CONFIRM" url="ftp://ftp.sap.com/pub/linuxlab/saptools/README.saposcol">ftp://ftp.sap.com/pub/linuxlab/saptools/README.saposcol</ref><ref source="XF" url="http://xforce.iss.net/static/6487.php">linux-sap-execute-code(6487)</ref></refs><vuln_soft><prod name="saposcol" vendor="SAP"><vers edition="lINUX" num="1.3"/><vers edition="Linux" num="1.2"/><vers edition="Linux" num="1.1"/><vers edition="Linux" num="1.0"/></prod><prod name="SAP R/3 Web Application Server Demo" vendor="SAP"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0367" published="2001-06-27" seq="2001-0367" severity="Medium" type="CVE"><desc><descript source="cve">Mirabilis ICQ WebFront Plug-in ICQ2000b Build 3278 allows a remote attacker to create a denial of service via HTTP URL requests containing a large number of % characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98847544303438&amp;w=2">BUGTRAQ:20010428 Mirabilis ICQ WebFront Plug-in Denial of Service</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2664">BID:2664</ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="2000.0b Build3278"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0368" published="2001-06-27" seq="2001-0368" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in BearShare 2.2.2 and earlier allows a remote attacker to read certain files via a URL containing a series of . characters, a variation of the .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/180644">BUGTRAQ:20010430 A Serious Security Vulnerability Found in BearShare (Directory Traversal)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2672">BID:2672</ref><ref source="XF" url="http://xforce.iss.net/static/6481.php">bearshare-dot-download-files(6481)</ref><ref source="OSVDB" url="http://www.osvdb.org/1810">1810</ref></refs><vuln_soft><prod name="BearShare" vendor="Free Peers"><vers num="2.2.2" prev="1"/><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0369" published="2001-06-27" seq="2001-0369" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98511407131984&amp;w=2"></ref><ref adv="1" patch="1" source="X-force" url="http://xforce.iss.net/static/6258.php">6258</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num="MU02"/><vers num="R4.20MU06"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0370" published="2001-06-27" seq="2001-0370" severity="Medium" type="CVE"><desc><descript source="cve">fcheck prior to 2.57.59 calls the file signature checking program insecurely, which can allow a local user to run arbitrary commands via a file name that contains shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98521301510554&amp;w=2"></ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6256.php">6256</ref></refs><vuln_soft><prod name="Fcheck" vendor="Michael A. Gumienny"><vers num="2.57.59" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2001-0371" published="2001-06-18" seq="2001-0371" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the UFS and EXT2FS file systems in FreeBSD 4.2 and earlier, and possibly other operating systems, makes deleted data available to user processes before it is zeroed out, which allows a local user to access otherwise restricted information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="FreeBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-03/0403.html">FREEBSD:FreeBSD-SA-01:30</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/6268.php">XF:ufs-ext2fs-data-disclosure</ref><ref source="OSVDB" url="http://www.osvdb.org/5682">5682</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-27" name="CVE-2001-0372" published="2001-06-18" seq="2001-0372" severity="High" type="CVE"><desc><descript source="cve">Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0337.html">BUGTRAQ:20010323 FW: Akopia Interchange E-commerce Package Demo Files Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2499">BID:2499</ref><ref source="ISS X-Force" url="http://xforce.iss.net/static/6273.php">XF:akopia-interchange-gain-access</ref><ref source="CONFIRM" url="http://lists.akopia.com/pipermail/interchange-announce/2001/000009.html">http://lists.akopia.com/pipermail/interchange-announce/2001/000009.html</ref></refs><vuln_soft><prod name="Akopia Interchange" vendor="Akopia"><vers num="4.6.3" prev="1"/><vers num="4.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0373" published="2001-06-18" seq="2001-0373" severity="Low" type="CVE"><desc><descript source="cve">The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2501">BID:2501</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6275.php">XF:win-userdmp-insecure-permission</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0336.html">20010323 NT crash dump files insecure by default</ref><ref source="OSVDB" url="http://www.osvdb.org/5683">5683</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0374" published="2001-06-18" seq="2001-0374" severity="High" type="CVE"><desc><descript source="cve">The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to bypass access restrictions via the management port, 2301.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Compaq" url="http://www.compaq.com/products/servers/management/mgtsw-advisory.html">COMPAQ:SSRT0715</ref><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q1/0779.html">BUGTRAQ:20010322 Compaq Insight Manager Proxy Vuln</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/6264.php">XF:compaq-wbm-bypass-proxy</ref></refs><vuln_soft><prod name="Web-Enabled Management" vendor="Compaq"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2001-0375" published="2001-06-18" seq="2001-0375" severity="Medium" type="CVE"><desc><descript source="cve">Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98658271707833&amp;w=2">BUGTRAQ:20010406 PIX Firewall 5.1 DoS Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/6353">Cisco PIX denial of service due to multiple TACACS+ requests</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2551">Cisco PIX TACACS+ Denial of Service Vulnerability</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/707/pixfirewall-authen-flood-pub.shtml">20011003 Cisco PIX Firewall Authentication Denial of Service Vulnerability</ref></refs><vuln_soft><prod name="PIX Firewall" vendor="Cisco"><vers num="515"/><vers num="520"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0376" published="2001-06-18" seq="2001-0376" severity="High" type="CVE"><desc><descript source="cve">SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys.  This allows a remote attacker to brute force attack the pre-shared keys with significantly less resources than if the full 128 byte IKE pre-shared keys were used.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0403.html">BUGTRAQ:20010327 SonicWall IKE pre-shared key length bug and security concern</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6304.php"> XF:sonicwall-ike-shared-keys</ref></refs><vuln_soft><prod name="SOHO2" vendor="SonicWALL"><vers num="6.0.0"/></prod><prod name="TELE2" vendor="SonicWALL"><vers num="6.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2001-0377" published="2001-06-18" seq="2001-0377" severity="Medium" type="CVE"><desc><descript source="cve">Infradig Inframail prior to 3.98a allows a remote attacker to create a denial of service via a malformed POST request which includes a space followed by a large string.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0428.html">20010328 Inframail Denial of Service Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/6297.php">inframail-post-dos</ref><ref source="OSVDB" url="http://www.osvdb.org/5685">5685</ref></refs><vuln_soft><prod name="Inframail" vendor="Infradig"><vers num="3.97a" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0378" published="2001-06-27" seq="2001-0378" severity="Low" type="CVE"><desc><descript source="cve">readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local attacker to recover potentially sensitive information via readline history files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/openbsd/2001-03/1627.html"></ref><ref patch="1" source="OpenBSD" url="ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.8/common/024_readline.patch"></ref><ref source="XF" url="http://xforce.iss.net/static/6586.php">bsd-readline-permissions(6586)</ref><ref source="OSVDB" url="http://www.osvdb.org/5680">5680</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0379" published="2001-06-18" seq="2001-0379" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="IT Resource Center" url="http://archives.neohapsis.com/archives/hp/2001-q1/0101.html">HP:HPSBUX0103-147</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/249224">VU#249224</ref><ref source="XF" url="http://xforce.iss.net/static/6282.php">hp-newgrp-additional-privileges(6282)</ref><ref source="OSVDB" url="http://www.osvdb.org/5681">5681</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.11"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0380" published="2001-06-18" seq="2001-0380" severity="Medium" type="CVE"><desc><descript source="cve">Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string &apos;ILMI&apos;.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0364.html">BUGTRAQ:200103 ILMI community in olicom/crosscomm routers</ref></refs><vuln_soft><prod name="XLT-F" vendor="Crosscom Olicom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2001-0381" published="2001-06-27" seq="2001-0381" severity="Medium" type="CVE"><desc><descript source="cve">The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0252.html"></ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0274.html"></ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0311.html"></ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-017.0.txt">CSSA-2001-017.0</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-063.html">RHSA-2001:063</ref><ref source="BID" url="http://www.securityfocus.com/bid/2673">2673</ref><ref source="OSVDB" url="http://www.osvdb.org/11966">11966</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6558">openpgp-private-key-disclosure(6558)</ref></refs><vuln_soft><prod name="OpenPGP" vendor="PGP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0382" published="2001-06-18" seq="2001-0382" severity="High" type="CVE"><desc><descript source="cve">Computer Associates CCC\Harvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/ntbugtraq/2001-q2/0001.html">NTBUGTRAQ:20010327 CA CCC\Harvest exploit</ref></refs><vuln_soft><prod name="CCC_Harvest" vendor="Computer Associates"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0383" published="2001-06-18" seq="2001-0383" severity="Medium" type="CVE"><desc><descript source="cve">banners.php in PHP-Nuke 4.4 and earlier allows remote attackers to modify banner ad URLs by directly calling the Change operation, which does not require authentication.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0017.html">BUGTRAQ:20010401 Php-nuke exploit</ref><ref source="CONFIRM" url="http://phpnuke.org/download.php?dcategory=Fixes">http://phpnuke.org/download.php?dcategory=Fixes</ref><ref source="XF" url="http://xforce.iss.net/static/6342.php">php-nuke-url-redirect(6342)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2544">2544</ref></refs><vuln_soft><prod name="PHP-Nuke" vendor="Francisco Burzi"><vers num="4.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0384" published="2001-07-02" seq="2001-0384" severity="Low" type="CVE"><desc><descript source="cve">ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2606">bid2606</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176709">20010414 Re: Reliant Unix 5.43 / 5.44 ICMP port unreachable problem</ref></refs><vuln_soft><prod name="Reliant UNIX" vendor="Siemens"><vers num="5.45" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0385" published="2001-07-02" seq="2001-0385" severity="Medium" type="CVE"><desc><descript source="cve">GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0281.html">BUGTRAQ:20010417 Advisory for GoAhead Webserver v2.1</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2607">bid 2607</ref><ref patch="1" source="GoAhead.com" url="news://news.goahead.com/goahead.public.webserver"></ref><ref source="OSVDB" url="http://www.osvdb.org/6664">6664</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6400">goahead-aux-dos(6400)</ref></refs><vuln_soft><prod name="GoAhead Webserver" vendor="GoAhead Software"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0386" published="2001-07-02" seq="2001-0386" severity="Medium" type="CVE"><desc><descript source="cve">AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/177156">ADV-0103</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2608">bid2608</ref><ref source="XF" url="http://xforce.iss.net/static/6395.php">analogx-simpleserver-aux-dos(6395)</ref><ref source="OSVDB" url="http://www.osvdb.org/3781">3781</ref></refs><vuln_soft><prod name="SimpleServer WWW" vendor="AnalogX"><vers num="1.0.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0387" published="2001-07-02" seq="2001-0387" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in hfaxd in HylaFAX before 4.1.b2_2 allows local users to gain privileges via the -q command line argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2574">bid2574</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0236.html">BUGTRAQ:20010415 **SECURITY ADVISORY** - HylaFAX format string vulnerability</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/175963">BUGTRAQ:20010412 HylaFAX vulnerability</ref><ref adv="1" patch="1" source="S.u.S.E." url="http://lists.suse.com/archives/suse-security-announce/2001-Apr/0005.html">SuSE-SA:2001:15</ref><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-041.php3">MDKSA-2001:041</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0606.html">FreeBSD-SA-01:34</ref><ref source="XF" url="http://xforce.iss.net/static/6377.php">hylafax-hfaxd-format-string(6377)</ref><ref source="OSVDB" url="http://www.osvdb.org/5679">5679</ref></refs><vuln_soft><prod name="Hylafax" vendor="Hylafax"><vers num="4.1 beta3"/><vers num="4.1 beta2"/><vers num="4.1 beta1"/><vers num="4.0 pl2"/><vers num="4.0 pl1"/><vers num="4.0 pl0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2001-0388" published="2001-06-27" seq="2001-0388" severity="High" type="CVE"><desc><descript source="cve">time server daemon timed allows remote attackers to cause a denial of service via malformed packets.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:28.timed.asc">01:28</ref><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-034.php3">2001:034</ref><ref adv="1" patch="1" source="SuSE security announcement" url="http://www.suse.de/de/support/security/2001_007_nkitserv.txt">2001:07</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6228.php">6228</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_007_nkitserv.html">SuSE-SA:2001:07</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1" prev="1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.1"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.0"/><vers num="7.1"/><vers num="6.0"/><vers num="6.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-21" name="CVE-2001-0389" published="2001-07-02" seq="2001-0389" severity="Medium" type="CVE"><desc><descript source="cve">IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2587">bid2587</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/176100">20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more.</ref></refs><vuln_soft><prod name="Net.Commerce" vendor="IBM"><vers num="3.1.2"/></prod><prod name="WebSphere Application Server" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-21" name="CVE-2001-0390" published="2001-07-02" seq="2001-0390" severity="Medium" type="CVE"><desc><descript source="cve">IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="Security Focus" url="http://www.securityfocus.com/archive/1/176100">BUGTRAQ:20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more.</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2588">bid2588</ref></refs><vuln_soft><prod name="Net.Commerce Hosting Server" vendor="IBM"><vers num="3.1.2"/><vers num="3.1.1"/></prod><prod name="Net.Commerce" vendor="IBM"><vers num="3.1.2"/><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0"/><vers num="2.0"/></prod><prod name="WebSphere Application Server" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0391" published="2001-07-02" seq="2001-0391" severity="Medium" type="CVE"><desc><descript source="cve">Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2622">2622</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0277.html">20010417 Advisory for Xitami 2.4d7, 2.5d4</ref></refs><vuln_soft><prod name="Xitami" vendor="Imatix"><vers edition="Windows" num="2.5d4"/><vers edition="Windows" num="2.4d7"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0392" published="2001-06-18" seq="2001-0392" severity="Medium" type="CVE"><desc><descript source="cve">Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98633100728473&amp;w=2">BUGTRAQ:20010403 def-2001-17: Navision Financials Server DoS</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2539">BID:2539</ref></refs><vuln_soft><prod name="Financials Server" vendor="Navision"><vers num="2.60" prev="1"/><vers num="2.50"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0393" published="2001-06-18" seq="2001-0393" severity="Medium" type="CVE"><desc><descript source="cve">Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98637870623514&amp;w=2">BUGTRAQ:20010404 Re: def-2001-17: Navision Financials Server DoS</ref></refs><vuln_soft><prod name="Financials Server" vendor="Navision"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0394" published="2001-08-22" seq="2001-0394" severity="Medium" type="CVE"><desc><descript source="cve">Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0425.html">def-2001-15</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6295.php">website-pro-remote-dos(6295)</ref><ref source="OSVDB" url="http://www.osvdb.org/5669">5669</ref></refs><vuln_soft><prod name="WebSite Pro" vendor="OReilly"><vers num="3.0.37"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0395" published="2001-07-02" seq="2001-0395" severity="High" type="CVE"><desc><descript source="cve">Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0170.html">BUGTRAQ:20010410 Console 3200 telnetd problem.</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2578">bid2578</ref></refs><vuln_soft><prod name="ConsoleServer" vendor="Lightwave"><vers num="3200"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0396" published="2001-07-02" seq="2001-0396" severity="Medium" type="CVE"><desc><descript source="cve">The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0170.html">BUGTRAQ:20010410 Console 3200 telnetd problem.</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2578">bid2578</ref></refs><vuln_soft><prod name="ConsoleServer" vendor="Lightwave"><vers num="3200"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0397" published="2001-06-18" seq="2001-0397" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0454.html">BUGTRAQ:20010329 Silent Runner Collector - HELO buffer overflow vulnerability</ref></refs><vuln_soft><prod name="Silent Runner Collector SRC" vendor="Silent Runner"><vers num="1.6.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2001-0398" published="2001-06-18" seq="2001-0398" severity="High" type="CVE"><desc><descript source="cve">The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT!  to misrepresent the attachment&apos;s type with a different icon.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0013.html">BUGTRAQ:20010402 ~..~!guano</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2530">BID:2530</ref></refs><vuln_soft><prod name="The Bat" vendor="RITLabs"><vers num="1.49"/><vers num="1.48"/><vers num="1.47"/><vers num="1.46"/><vers num="1.45"/><vers num="1.44"/><vers num="1.43"/><vers num="1.42f"/><vers num="1.42"/><vers num="1.41"/><vers num="1.39"/><vers num="1.36"/><vers num="1.35"/><vers num="1.34"/><vers num="1.33"/><vers num="1.32"/><vers num="1.31"/><vers num="1.22"/><vers num="1.21"/><vers num="1.19"/><vers num="1.18"/><vers num="1.17"/><vers num="1.15"/><vers num="1.14"/><vers num="1.101"/><vers num="1.1"/><vers num="1.043"/><vers num="1.041"/><vers num="1.039"/><vers num="1.037"/><vers num="1.036"/><vers num="1.035"/><vers num="1.032"/><vers num="1.031"/><vers num="1.029"/><vers num="1.028"/><vers num="1.015"/><vers num="1.011"/><vers num="1.0 build1349"/><vers num="1.0 build1336"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0399" published="2001-06-18" seq="2001-0399" severity="Medium" type="CVE"><desc><descript source="cve">Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2533">BID:2533</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98633597813833&amp;w=2">BUGTRAQ:20010403 CHINANSL Security Advisory(CSA-200111)</ref></refs><vuln_soft><prod name="Resin" vendor="Caucho Technology"><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0400" published="2001-07-02" seq="2001-0400" severity="High" type="CVE"><desc><descript source="cve">nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters (&quot;`&quot;) in the email address.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/175506">BUGTRAQ:20010410 CGI - nph-maillist.pl vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2563">bid2563</ref></refs><vuln_soft><prod name="nph-maillist" vendor="Matt Tourtillott"><vers num="3.5"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0401" published="2001-06-18" seq="2001-0401" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0394.html">BUGTRAQ:20010327 Solaris /usr/bin/tip Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6284.php">XF:solaris-tip-bo</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0" prev="1"/><vers num="7.0"/><vers num="2.6"/><vers num="2.5.1"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-05-11" name="CVE-2001-0402" published="2001-06-18" seq="2001-0402" severity="High" type="CVE"><desc><descript source="cve">IPFilter 3.4.16 and earlier does not include sufficient session information in its cache, which allows remote attackers to bypass access restrictions by sending fragmented packets to a restricted port after sending unfragmented packets to an unrestricted port.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98679734015538&amp;w=2">BUGTRAQ:20010408 A fragmentation attack against IP Filter</ref><ref adv="1" patch="1" source="FreeBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0338.html">FREEBSD:FreeBSD-SA-01:32</ref><ref source="XF" url="http://xforce.iss.net/static/6331.php">ipfilter-access-ports(6331)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.1" prev="1"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.8"/></prod><prod name="IPFilter" vendor="Darren Reed"><vers num="3.4.16" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0403" published="2001-06-18" seq="2001-0403" severity="High" type="CVE"><desc><descript source="cve">/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0326.html">BUGTRAQ:20010323 [ Hackerslab bug_paper ] SunOS application perfmon vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/6267.php">XF:solaris-perfmon-create-files</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0404" published="2001-06-18" seq="2001-0404" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98583089425166&amp;w=2">BUGTRAQ:20010328 CHINANSL Security Advisory(CSA-200106)</ref></refs><vuln_soft><prod name="JavaServer Web Dev Kit" vendor="Sun"><vers num="1.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-08-17" name="CVE-2001-0405" published="2001-07-02" seq="2001-0405" severity="High" type="CVE"><desc><descript source="cve">ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0271.html">20010416 Tempest Security Techonologies -- Advisory #01/2001 -- Linux IPTables</ref><ref adv="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2001-052.html">RHSA-2001:052</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2602">bid2602</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-084.html">RHSA-2001:084</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-071.php3">MDKSA-2001:071</ref><ref source="XF" url="http://xforce.iss.net/static/6390.php">linux-netfilter-iptables(6390)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.4.3"/><vers num="2.4.2"/><vers num="2.4.1"/><vers num="2.4.0 test1"/><vers num="2.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0406" published="2001-07-02" seq="2001-0406" severity="Low" type="CVE"><desc><descript source="cve">Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0305.html">BUGTRAQ:20010417 Samba 2.0.8 security fix</ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-048">DSA-048-3</ref><ref adv="1" patch="1" source="Caldera" url="http://www.caldera.com/support/security/advisories/CSSA-2001-015.0.txt">CSSA-2001-015.0</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0319.html">TSLSA-2001-0005</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0326.html">PROGENY-SA-2001-05</ref><ref source="FREEBSD" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0608.html">FreeBSD-SA-01:36</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-040.php3">MDKSA-2001:040</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/670568">VU#670568</ref><ref source="BID" url="http://www.securityfocus.com/bid/2617">2617</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000395">CLA-2001:395</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="2.0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-03-28" name="CVE-2001-0407" published="2001-06-27" seq="2001-0407" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0237.html"></ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0396.html"></ref><ref source="XF" url="http://xforce.iss.net/static/6617.php">mysql-dot-directory-traversal(6617)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2522">2522</ref></refs><vuln_soft><prod name="MySQL" vendor="MySQL"><vers num="3.23.36" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0408" published="2001-06-18" seq="2001-0408" severity="Medium" type="CVE"><desc><descript source="cve">vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing malicious VIM control codes.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2510">BID:2510</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/support/errata/RHSA-2001-008.html">REDHAT:RHSA-2001:008</ref><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-014.0.txt">CALDERA:CSSA-2001-014.0</ref><ref source="MANDRAKE" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-035.php3">MDKSA-2001:035</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_012_vim.html">SuSE-SA:2001:12</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98593106111968&amp;w=2">20010329 Immunix OS Security update for vim</ref><ref source="XF" url="http://xforce.iss.net/static/6259.php">vim-elevate-privileges(6259)</ref></refs><vuln_soft><prod name="VIM" vendor="VIM Development Group"><vers num="5.7"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0409" published="2001-06-18" seq="2001-0409" severity="Low" type="CVE"><desc><descript source="cve">vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="S.u.S.E" url="http://www.suse.de/de/support/security/2001_012_vim.txt">SUSE:SuSE-SA:2001:12</ref><ref adv="1" patch="1" source="Caldera" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-014.0.txt">CALDERA:CSSA-2001-014.0</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_012_vim.html">SuSE-SA:2001:12</ref><ref source="XF" url="http://xforce.iss.net/static/6628.php">vim-tmp-symlink(6628)</ref></refs><vuln_soft><prod name="VIM" vendor="VIM Development Group"><vers num="5.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0410" published="2001-06-18" seq="2001-0410" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long &quot;From&quot; header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98593642520755&amp;w=2">BUGTRAQ:20010330 Virus Buster 2001(ver8.02) Buffer Overflow</ref></refs><vuln_soft><prod name="Virus Buster 2001" vendor="Trend Micro"><vers num="8.02"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0411" published="2001-06-18" seq="2001-0411" severity="Medium" type="CVE"><desc><descript source="cve">Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98658209505849&amp;w=2">BUGTRAQ:20010406 Reliant Unix 5.43 / 5.44 ICMP port unreachable problem</ref></refs><vuln_soft><prod name="Reliant UNIX" vendor="Siemens"><vers num="5.44"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0412" published="2001-06-18" seq="2001-0412" severity="High" type="CVE"><desc><descript source="cve">Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/arrowpoint-useraccnt-debug-pub.shtml">CISCO:20010404 Cisco Content Services Switch User Account Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/2559">2559</ref><ref source="XF" url="http://xforce.iss.net/static/6322.php">cisco-css-elevate-privileges(6322)</ref><ref source="OSVDB" url="http://www.osvdb.org/1784">1784</ref></refs><vuln_soft><prod name="Cisco Content Services" vendor="Cisco"><vers num="11050"/><vers num="11150"/><vers num="11800"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0413" published="2001-06-18" seq="2001-0413" severity="Medium" type="CVE"><desc><descript source="cve">BinTec X4000 Access router, and possibly other versions, allows remote attackers to cause a denial of service via a SYN port scan, which causes the router to hang.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98644414226344&amp;w=2">BUGTRAQ:20010404 BinTec X4000 Access Router DoS Vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98659862317070&amp;w=2">BUGTRAQ:20010406 X4000 DoS: Details and workaround</ref><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0145.html">BUGTRAQ:20010410 BinTec Router DoS: Workaround and Details</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98697054804197&amp;w=2">20010409 BINTEC X1200</ref><ref source="XF" url="http://xforce.iss.net/static/6323.php">bintec-x4000-nmap-dos(6323)</ref></refs><vuln_soft><prod name="X1200" vendor="BinTec"><vers num=""/></prod><prod name="X4000" vendor="BinTec"><vers num="5.1.6 Patch 10"/></prod><prod name="X1000" vendor="BinTec"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0414" published="2001-06-18" seq="2001-0414" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2540">BID:2540</ref><ref adv="1" patch="1" source="MandrakeSoft" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-036.php3">MANDRAKE:MDKSA-2001:036</ref><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98651866104663&amp;w=2">DEBIAN:DSA-045</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98642418618512&amp;w=2">20010404 ntpd =&lt; 4.0.99k remote buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98654963328381&amp;w=2">20010405 Re: ntpd =&lt; 4.0.99k remote buffer overflow]</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-045.html">RHSA-2001:045</ref><ref source="CALDERA" url="http://www.calderasystems.com/support/security/advisories/CSSA-2001-013.0.txt">CSSA-2001-013</ref><ref source="NETBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2001-004.txt.asc">NetBSD-SA2001-004</ref><ref source="SUSE" url="http://lists.suse.com/archives/suse-security-announce/2001-Apr/0000.html">SuSE-SA:2001:10</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000392">CLA-2001:392</ref><ref source="FREEBSD" url="ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:31.ntpd.asc">FreeBSD-SA-01:31</ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/sse073.ltr">SSE073</ref><ref source="SCO" url="ftp://ftp.sco.com/SSE/sse074.ltr">SSE074</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98679815917014&amp;w=2">20010408 [slackware-security] buffer overflow fix for NTP</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98684202610470&amp;w=2">20010409 PROGENY-SA-2001-02: ntpd remote buffer overflow</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98684532921941&amp;w=2">20010409 ntpd - new Debian 2.2 (potato) version is also vulnerable</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98659782815613&amp;w=2">20010406 Immunix OS Security update for ntp and xntp3</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98683952401753&amp;w=2">20010409 ntp-4.99k23.tar.gz is available</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0314.html">20010418 IBM MSS Outside Advisory Redistribution: IBM AIX: Buffer Overflow Vulnerability in (x)ntp</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0127.html">20010409 [ESA-20010409-01] xntp buffer overflow</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0225.html">20010413 PROGENY-SA-2001-02A: [UPDATE] ntpd remote buffer overflow</ref><ref source="OSVDB" url="http://www.osvdb.org/805">805</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3831">oval:org.mitre.oval:def:3831</ref><ref source="XF" url="http://xforce.iss.net/static/6321.php">ntpd-remote-bo(6321)</ref></refs><vuln_soft><prod name="ntpd" vendor="Dave Mills"><vers num="4.0.99k" prev="1"/><vers num="4.0.99j"/><vers num="4.0.99i"/><vers num="4.0.99h"/><vers num="4.0.99g"/><vers num="4.0.99f"/><vers num="4.0.99e"/><vers num="4.0.99d"/><vers num="4.0.99c"/><vers num="4.0.99b"/><vers num="4.0.99a"/><vers num="4.0.99"/></prod><prod name="xntp3" vendor="Dave Mills"><vers num="5.93e"/><vers num="5.93d"/><vers num="5.93c"/><vers num="5.93b"/><vers num="5.93a"/><vers num="5.93"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0415" published="2001-06-27" seq="2001-0415" severity="Medium" type="CVE"><desc><descript source="cve">REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0275.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2495">2495</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6276.php">6276</ref></refs><vuln_soft><prod name="RediPlus" vendor="Redi"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0416" published="2001-06-27" seq="2001-0416" severity="Low" type="CVE"><desc><descript source="cve">sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Debian" url="http://www.debian.org/security/2001/dsa-038">DSA-038-1</ref><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA-2001-027.html">RHSA-2001:027-02</ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98477491130367&amp;w=2">IMNK-2001-70-008-01</ref><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-030.php3">MDKSA-2001:030</ref><ref adv="1" patch="1" source="Conectiva Linux Announcement" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000390">CLSA-2001:390</ref><ref source="XF" url="http://xforce.iss.net/static/6201.php">sgmltools-symlink</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_016_sgmltool_txt.html">SuSE-SA:2001:16</ref><ref source="BID" url="http://www.securityfocus.com/bid/2683">2683</ref><ref source="BID" url="http://www.securityfocus.com/bid/2506">2506</ref></refs><vuln_soft><prod name="sgml-tools" vendor="Debian"><vers num="1.0.9.15"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="6.0"/><vers num="6.1"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Immunix" vendor="Immunix"><vers num="6.2"/><vers num="7.0 Beta"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0417" published="2001-06-27" seq="2001-0417" severity="Low" type="CVE"><desc><descript source="cve">Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0078.html"></ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-025.html">RHSA-2001:025</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num=""/></prod><prod name="Kerberos 4" vendor="MIT"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-2001-0418" published="2001-07-02" seq="2001-0418" severity="Medium" type="CVE"><desc><descript source="cve">content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0223.html">BUGTRAQ:20010413 Exploitable NCM.at - Content Management System</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2584">bid2584</ref></refs><vuln_soft><prod name="NCM Content Management System" vendor="NCM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0419" published="2001-07-02" seq="2001-0419" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98692227816141&amp;w=2">BUGTRAQ:20010410 Oracle Application Server shared library buffer overflow</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2569">bid2569</ref></refs><vuln_soft><prod name="Oracle Application Server" vendor="Oracle"><vers num="4.0.82"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0420" published="2001-06-18" seq="2001-0420" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0128.html">BUGTRAQ:20010409 talkback.cgi vulnerability may allow users to read any file</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2547">BID:2547</ref></refs><vuln_soft><prod name="TalkBack" vendor="Way to the Web"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0421" published="2001-07-02" seq="2001-0421" severity="Medium" type="CVE"><desc><descript source="cve">FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2601">bid2601</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/177200">20010417 Re: SUN SOLARIS 5.6/5.7 FTP Globbing Exploit !</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers num="8.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0422" published="2001-07-02" seq="2001-0422" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0158.html">BUGTRAQ:20010410 Solaris Xsun buffer overflow vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2561">bid2561</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:555">oval:org.mitre.oval:def:555</ref><ref source="XF" url="http://xforce.iss.net/static/6343.php">solaris-xsun-home-bo(6343)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="8.0"/><vers num="7.0"/><vers num="2.6"/><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2001-0423" published="2001-07-02" seq="2001-0423" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary code via a long TZ (timezone) environmental variable, a different vulnerability than CAN-2002-0093.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0217.html">BUGTRAQ:20010412 Solaris ipcs vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2581">bid2581</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/6369">Solaris ipcs utility buffer overflow</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0424" published="2001-07-02" seq="2001-0424" severity="High" type="CVE"><desc><descript source="cve">BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98744422105430&amp;w=2">BUGTRAQ:20010415 BubbleMon 1.31</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2609">bid2609</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="BubbleMon" vendor="Timecop"><vers num="1.31"/><vers num="1.3"/><vers num="1.23"/><vers num="1.22"/><vers num="1.21test1"/><vers num="1.21"/><vers num="1.2test1"/><vers num="1.2"/><vers num="1.1test7"/><vers num="1.1test6"/><vers num="1.1test5"/><vers num="1.1test4"/><vers num="1.1test3"/><vers num="1.1test2"/><vers num="1.1test1"/><vers num="1.1"/><vers num="1.0pl9"/><vers num="1.0pl8"/><vers num="1.0pl7"/><vers num="1.0pl6"/><vers num="1.0pl4"/><vers num="1.0pl3"/><vers num="1.0pl2"/><vers num="1.0pl1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-04-27" name="CVE-2001-0425" published="2001-06-27" seq="2001-0425" severity="High" type="CVE"><desc><descript source="cve">AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/163942"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2393">2393</ref></refs><vuln_soft><prod name="Adcycle" vendor="Adcycle"><vers num="0.77"/><vers num="0.78b"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0426" published="2001-07-02" seq="2001-0426" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0203.html">BUGTRAQ:20010411 [LSD] Solaris kcsSUNWIOsolf.so and  dtsession vulnerabilities</ref><ref adv="1" source="Security Focus" url="http://securityfocus/bid/2603">bid2603</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="8.0"/><vers num="8.0"/><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:N/I:N/A:C)" CVSS_version="2.0" modified="2008-08-20" name="CVE-2001-0427" published="2001-06-18" seq="2001-0427" severity="High" type="CVE"><desc><descript source="cve">Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via a flood of invalid login requests to (1) the SSL service, or (2) the telnet service, which do not properly disconnect the user after several failed login attempts.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/vpn3k-telnet-vuln-pub.shtml">CISCO:20010328 VPN3000 Concentrator TELNET Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/6298.php">cisco-vpn-telnet-dos(6298)</ref><ref source="OSVDB" url="http://www.osvdb.org/5643">5643</ref></refs><vuln_soft><prod name="Cisco VPN" vendor="Cisco"><vers num="3000"/><vers num="3005"/><vers num="3015"/><vers num="3030"/><vers num="3060"/><vers num="3080"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0428" published="2001-07-02" seq="2001-0428" severity="Medium" type="CVE"><desc><descript source="cve">Cisco VPN 3000 series concentrators before 2.5.2(F) allow remote attackers to cause a denial of service via an IP packet with an invalid IP option.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/vpn3k-ipoptions-vuln-pub.shtml">CSCds92460</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2573">bid2573</ref><ref source="XF" url="http://xforce.iss.net/static/6360.php">cisco-vpn-ip-dos(6360)</ref><ref source="OSVDB" url="http://www.osvdb.org/1786">1786</ref></refs><vuln_soft><prod name="VPN 3000 Concentrator" vendor="Cisco"><vers num="2.5.2(D)"/><vers num="2.5.2(C)"/><vers num="2.5.2(B)"/><vers num="2.5.2(A)"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0429" published="2001-07-02" seq="2001-0429" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Catalyst 5000 series switches 6.1(2) and earlier will forward an 802.1x frame on a Spanning Tree Protocol (STP) blocked port, which causes a network storm and a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/cat5k-8021x-vuln-pub.shtml">CSCdt62732</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2604">bid2604</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-072.shtml">L-072</ref><ref source="XF" url="http://xforce.iss.net/static/6379.php">cisco-catalyst-8021x-dos(6379)</ref></refs><vuln_soft><prod name="Catalyst 2900" vendor="Cisco"><vers num="6.1.2"/><vers num="5.5.6"/><vers num="4.5.11"/></prod><prod name="Catalyst 5000" vendor="Cisco"><vers num="6.1(2)"/><vers num="6.1(1c)"/><vers num="5.5(6)"/><vers num="5.5(4b)"/><vers num="4.5(11)"/><vers num="4.5.10"/></prod></vuln_soft></entry><entry CVSS_base_score="3.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="4.9" CVSS_score="3.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0430" published="2001-07-02" seq="2001-0430" severity="Low" type="CVE"><desc><descript source="cve">Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vendor/2001-q2/0005.html">DSA-046-1</ref><ref source="XF" url="http://xforce.iss.net/static/6388.php">exuberant-ctags-symlink(6388)</ref><ref source="OSVDB" url="http://www.osvdb.org/5642">5642</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/><vers num="3.2.4" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2001-0431" published="2001-07-02" seq="2001-0431" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in iPlanet Web Server Enterprise Edition 4.x.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="iPlanet" url="http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html">BUGTRAQ:20010417 iPlanet Web Server 4.x Product Alert</ref></refs><vuln_soft><prod name="iPlanet Web Server" vendor="iPlanet"><vers num="4.x Enterprise"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0432" published="2001-07-02" seq="2001-0432" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0218.html">BUGTRAQ:20010413 Trend Micro Interscan VirusWall 3.01 vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2579">bid2579</ref></refs><vuln_soft><prod name="InterScan VirusWall" vendor="Trend Micro"><vers num="3.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0433" published="2001-06-18" seq="2001-0433" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98655083231635&amp;w=2">BUGTRAQ:20010405 Savant 3.0 Denial Of Service</ref></refs><vuln_soft><prod name="Savant WebServer" vendor="Micheal Lamont"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0434" published="2001-07-02" seq="2001-0434" severity="Medium" type="CVE"><desc><descript source="cve">The LogDataListToFile ActiveX function used in (1) Knowledge Center and (2) Back web components of Compaq Presario computers allows remote attackers to modify arbitrary files and cause a denial of service.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Compaq" url="http://ftp.support.compaq.com/patches/.new/html/SSRT0716-01.shtml">SSRT0716</ref><ref source="XF" url="http://xforce.iss.net/static/6355.php">compaq-activex-dos(6355)</ref></refs><vuln_soft><prod name="Presario" vendor="Compaq"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2001-0435" published="2001-07-02" seq="2001-0435" severity="Medium" type="CVE"><desc><descript source="cve">The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the &quot;Cache passphrase while logged on&quot; option and capturing the passphrases of other share holders as they authenticate.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98691775527457&amp;w=2">WSIR-01/02-03</ref></refs><vuln_soft><prod name="PGP" vendor="PGP"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0436" published="2001-07-02" seq="2001-0436" severity="High" type="CVE"><desc><descript source="cve">dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0269.html">QDAV-5-2000-5</ref><ref patch="1" source="DCScripts" url="http://www.dcscripts.com/FAQ/sec_2001_03_31.html"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2611">bid2611</ref><ref source="XF" url="http://xforce.iss.net/static/6392.php">dcforum-az-expr(6392)</ref><ref source="OSVDB" url="http://www.osvdb.org/3862">3862</ref></refs><vuln_soft><prod name="DCForum" vendor="DCScripts"><vers num="6.0"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="DCForum 2000" vendor="DCScripts"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0437" published="2001-07-02" seq="2001-0437" severity="Medium" type="CVE"><desc><descript source="cve">upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0269.html">QDAV-5-2001-1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2611">bid2611</ref><ref adv="1" patch="1" source="Dcscripts" url="http://www.dcscripts.com/FAQ/sec_2001_03_31.html"></ref><ref source="XF" url="http://xforce.iss.net/static/6393.php">dcforum-az-file-upload(6393)</ref></refs><vuln_soft><prod name="DCForum" vendor="DCScripts"><vers num="6.0"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="DCForum 2000" vendor="DCScripts"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0438" published="2001-07-02" seq="2001-0438" severity="Low" type="CVE"><desc><descript source="cve">Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0337.html">BUGTRAQ:20010418 Hole in Netopia&apos;s Mac OS X Timbuktu</ref></refs><vuln_soft><prod name="Timbuktu Mac" vendor="Netopia"><vers num="Initial"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0439" published="2001-07-02" seq="2001-0439" severity="High" type="CVE"><desc><descript source="cve">licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref patch="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000389">CLSA-2001:389</ref><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3">MDKSA-2001:032</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html">FreeBSD-SA-01:35</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6261.php">6261</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-022.html">RHSA-2001:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-023.html">RHSA-2001:023</ref><ref source="OSVDB" url="http://www.osvdb.org/5641">5641</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="1.0.1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="7.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num="4.0"/><vers num="4.0es"/><vers num="4.1"/><vers num="4.2"/><vers num="5.0"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.5.1"/><vers num="4.2"/></prod><prod name="LICQ" vendor="LICQ"><vers num="1.0.2" prev="1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0440" published="2001-07-02" seq="2001-0440" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Conectiva" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000389">CLSA-2001:389</ref><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-032.php3">MDKSA-2001:032</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0607.html">FreeBSD-SA-01:35</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-022.html">RHSA-2001:022</ref><ref source="REDHAT" url="http://www.redhat.com/support/errata/RHSA-2001-023.html">RHSA-2001:023</ref><ref source="XF" url="http://xforce.iss.net/static/6645.php">licq-logging-bo(6645)</ref><ref source="OSVDB" url="http://www.osvdb.org/5601">5601</ref></refs><vuln_soft><prod name="Conectiva Linux" vendor="Conectiva"><vers num="4.0"/><vers num="4.0es"/><vers num="4.1"/><vers num="4.2"/><vers num="5.0"/><vers num="prg graficos"/><vers num="ecommerce"/><vers num="5.1"/><vers num="6.0"/></prod><prod name="LICQ" vendor="LICQ"><vers num="1.0.2" prev="1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0441" published="2001-06-27" seq="2001-0441" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-040">DSA-040-1</ref><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-028.php3">MDKSA-2001-028</ref><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA-2001-028.html">RHSA-2001:028-02</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2001-04/0610.html">FreeBSD-SA-01:37</ref><ref source="BID" url="http://www.securityfocus.com/bid/2493">2493</ref><ref source="XF" url="http://xforce.iss.net/static/6213.php">slrn-wrapping-bo</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000383">CLA-2001:383</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98471253131191&amp;w=2">20010316 Immunix OS Security update for slrn</ref></refs><vuln_soft><prod name="Mandrake Corporate Server" vendor="MandrakeSoft"><vers num="1.0.1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="6.2"/><vers num="7.0"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="6.0"/><vers num="6.1"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0442" published="2001-06-27" seq="2001-0442" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Mercury MTA POP3 server for NetWare 1.48 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long APOP command.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0378.html">BUGTRAQ:20010421 Mercury for NetWare POP3 server vulnerable to remote buffer overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2641">BID:2641</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/179217">20010424 Re: Mercury for NetWare POP3 server vulnerable to remote buffer overflow</ref><ref source="XF" url="http://www.iss.net/security_center/static/6444.php">mercury-mta-bo(6444)</ref></refs><vuln_soft><prod name="Mercury_NLM" vendor="David Harris"><vers num="1.47"/><vers num="1.46"/><vers num="1.45"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0443" published="2001-07-02" seq="2001-0443" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0227.html">BUGTRAQ:20010413 QPC POPd Buffer Overflow Vulnerability</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/2618">2618</ref></refs><vuln_soft><prod name="QVT Term Plus" vendor="QPC Software"><vers num="5.0"/></prod><prod name="QVT Net" vendor="QPC Software"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0444" published="2001-07-02" seq="2001-0444" severity="Low" type="CVE"><desc><descript source="cve">Cisco CBOS 2.3.0.053 sends output of the &quot;sh nat&quot; (aka &quot;show nat&quot;) command to the terminal of the next user who attempts to connect to the router via telnet, which could allow that user to obtain sensitive information.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0380.html">BUGTRAQ:20010420 Bug in Cisco CBOS v2.3.0.053</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2635">bid2635</ref><ref source="XF" url="http://xforce.iss.net/static/6453.php">cisco-cbos-gain-information(6453)</ref><ref source="OSVDB" url="http://www.osvdb.org/1796">1796</ref></refs><vuln_soft><prod name="CBOS" vendor="Cisco"><vers num="2.4.1"/><vers num="2.3.053"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0446" published="2001-06-18" seq="2001-0446" severity="Medium" type="CVE"><desc><descript source="cve">IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98583082225053&amp;w=2">BUGTRAQ:20010328 CHINANSL Security Advisory(CSA-200107)</ref></refs><vuln_soft><prod name="WebSphere Commerce Suite" vendor="IBM"><vers num="4.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0447" published="2001-06-18" seq="2001-0447" severity="High" type="CVE"><desc><descript source="cve">Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing &quot;%2e&quot; (dot dot) characters.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/171418">BUGTRAQ:20010326 602Pro Lansuite Denial Of Service 1.0.34</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2514">BID:2514</ref></refs><vuln_soft><prod name="602Pro LAN SUITE" vendor="Software602"><vers num="2000a 2000.0.1.34"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0448" published="2001-06-18" seq="2001-0448" severity="Medium" type="CVE"><desc><descript source="cve">Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/171418">BUGTRAQ:20010326 602Pro Lansuite Denial Of Service 1.0.34</ref></refs><vuln_soft><prod name="602Pro LAN SUITE" vendor="Software602"><vers num="2000a 1.0.34" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-2001-0449" published="2001-06-27" seq="2001-0449" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in WinZip 8.0 allows attackers to execute arbitrary commands via a long file name that is processed by the /zipandemail command line option.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/166211">def-2001-09</ref><ref adv="1" source="X-Force" url="http://xforce.iss.net/static/6191.php">6191</ref></refs><vuln_soft><prod name="WinZip" vendor="WinZip"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0450" published="2001-06-27" seq="2001-0450" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0533.html"></ref><ref adv="1" source="Transsoft Ltd." url="http://www.ftp-broker.com/cgibin/Pageexe.exe?H=4143&amp;P=0&amp;C=0"></ref><ref adv="1" source="X-Force" url="http://xforce.iss.net/static/6190.php">6190</ref><ref adv="1" source="X-Force" url="http://xforce.iss.net/static/6189.php">6189</ref></refs><vuln_soft><prod name="Broker FTP Server" vendor="TransSoft"><vers num="5.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0451" published="2001-06-27" seq="2001-0451" severity="High" type="CVE"><desc><descript source="cve">INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6202.php">6202</ref></refs><vuln_soft><prod name="IndexU" vendor="Sentraweb"><vers num="2.0Beta"/><vers num="1.1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0452" published="2001-06-27" seq="2001-0452" severity="Medium" type="CVE"><desc><descript source="cve">BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a &quot;CD *&quot; command followed by an ls command.</descript></desc><loss_types><conf/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/180506">BUGTRAQ:20010428 Vulnerabilities in BRS WebWeaver</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2676">BID:2676</ref><ref source="CONFIRM" url="http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html">http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html</ref></refs><vuln_soft><prod name="WebWeaver" vendor="BRS"><vers num="0.62 beta"/><vers num="0.61 beta"/><vers num="0.60 beta"/><vers num="0.52 beta"/><vers num="0.51 beta"/><vers num="0.50 beta"/><vers num="0.49 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0453" published="2001-06-27" seq="2001-0453" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0519.html">BUGTRAQ:20010428 Vulnerabilities in BRS WebWeaver</ref><ref source="Security Focus" url="http://www.securityfocus.com/bid/2675">BID:2675</ref><ref source="CONFIRM" url="http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html">http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html</ref></refs><vuln_soft><prod name="WebWeaver" vendor="BRS"><vers num="0.62 beta"/><vers num="0.61 beta"/><vers num="0.60 beta"/><vers num="0.52 beta"/><vers num="0.51 beta"/><vers num="0.50 beta"/><vers num="0.49 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0454" published="2001-06-27" seq="2001-0454" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-02/0532.html"></ref><ref adv="1" source="X-Force" url="http://xforce.iss.net/static/6186.php">6186</ref></refs><vuln_soft><prod name="SlimServe" vendor="WhitSoft"><vers num="1.1a" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0455" published="2001-06-27" seq="2001-0455" severity="High" type="CVE"><desc><descript source="cve">Cisco Aironet 340 Series wireless bridge before 8.55 does not properly disable access to the web interface, which allows remote attackers to modify its configuration.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/Aironet340-pub.shtml">GMT-0800</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6200.php">6200</ref><ref source="OSVDB" url="http://www.osvdb.org/5597">5597</ref></refs><vuln_soft><prod name="Aironet 340" vendor="Cisco"><vers num="8.55" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0456" published="2001-06-27" seq="2001-0456" severity="High" type="CVE"><desc><descript source="cve">postinst installation script for Proftpd in Debian 2.2 does not properly change the &quot;run as uid/gid root&quot; configuration when the user enables anonymous access, which causes the server to run at a higher privilege than intended.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-032">DSA-032-1</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6208.php">6208</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0457" published="2001-06-27" seq="2001-0457" severity="Medium" type="CVE"><desc><descript source="cve">man2html before 1.5-22 allows remote attackers to cause a denial of service (memory exhaustion).</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-035">DSA-035-1</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6211.php">6211</ref><ref source="OSVDB" url="http://www.osvdb.org/5631">5631</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0458" published="2001-06-27" seq="2001-0458" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/2001/dsa-034">DSA-034-01</ref><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-027.php3">MDKSA-2001:027</ref><ref adv="1" patch="1" source="SuSE" url="http://www.suse.de/de/support/security/2001_008_eperl.txt">SuSE-SA:2001:08</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2464">2464</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6198.php">6198</ref><ref source="SUSE" url="http://www.novell.com/linux/security/advisories/2001_008_eperl.html">SuSE-SA:2001:08</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.3"/><vers num="6.4"/><vers num="7.0"/><vers num="7.1"/></prod><prod name="ePerl" vendor="Ralf S. Engelschall"><vers num="2.2.13"/><vers num="2.2.12"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.1"/><vers num="7.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0459" published="2001-06-27" seq="2001-0459" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m option, or (3) -f option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="X-Force" url="http://xforce.iss.net/static/6204.php">6204</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98408897106411&amp;w=2">20010308 ascdc Buffer Overflow Vulnerability</ref></refs><vuln_soft><prod name="ascdc" vendor="Rob Malda"><vers num="0.3"/></prod><prod name="Afterstep" vendor="Afterstep.org"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0460" published="2001-06-27" seq="2001-0460" severity="Medium" type="CVE"><desc><descript source="cve">Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/167406">dev-2001-01</ref><ref adv="1" source="X-Force" url="http://xforce.iss.net/static/6214.php">6214</ref></refs><vuln_soft><prod name="WEBsweeper" vendor="Baltimore Technologies"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0461" published="2001-06-27" seq="2001-0461" severity="High" type="CVE"><desc><descript source="cve">template.cgi in Free On-Line Dictionary of Computing (FOLDOC) allows remote attackers to read files and execute commands via shell metacharacters in the argument to template.cgi.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0109.html"></ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6217.php">6217</ref><ref source="CONFIRM" url="http://wombat.doc.ic.ac.uk/foldoc/index.html">http://wombat.doc.ic.ac.uk/foldoc/index.html</ref><ref source="OSVDB" url="http://www.osvdb.org/5591">5591</ref></refs><vuln_soft><prod name="FOLDOC" vendor="Denis Howe"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0462" published="2001-06-27" seq="2001-0462" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0426.html">BUGTRAQ:20010424 Advisory for perl webserver</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2648">BID:2648</ref><ref source="XF" url="http://xforce.iss.net/static/6451.php">perl-webserver-directory-traversal(6451)</ref></refs><vuln_soft><prod name="Perl Web Server" vendor="Spencer Christensen"><vers num="0.3"/><vers num="0.2"/><vers num="0.1"/><vers num="0.0.9"/><vers num="0.0.4"/><vers num="0.0.3"/><vers num="0.0.2"/><vers num="0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-03" name="CVE-2001-0463" published="2001-06-27" seq="2001-0463" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0506.html">BUGTRAQ:20010427 PerlCal (CGI) show files vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2663">BID:2663</ref><ref source="" url="http://www.perlcal.com/calendar/docs/bugs.txt"></ref><ref source="XF" url="http://xforce.iss.net/static/6480.php">perlcal-calmake-directory-traversal(6480)</ref></refs><vuln_soft><prod name="PerlCal" vendor="Acme Labs"><vers num="2.95"/><vers num="2.9e"/><vers num="2.9d"/><vers num="2.9c"/><vers num="2.9b"/><vers num="2.9a"/><vers num="2.9"/><vers num="2.80"/><vers num="2.7"/><vers num="2.6"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.18"/><vers num="2.13"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0464" published="2001-07-02" seq="2001-0464" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98761402029302&amp;w=2">def-2000-18</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2628">bid2628</ref></refs><vuln_soft><prod name="CyberScheduler" vendor="CrossWind"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0465" published="2001-06-18" seq="2001-0465" severity="Medium" type="CVE"><desc><descript source="cve">TurboTax saves passwords in a temporary file when a user imports investment tax information from a financial institution, which could allow local users to obtain sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98653594732053&amp;w=2">BUGTRAQ:20010405</ref><ref source="CONFIRM" url="http://www.turbotax.com/atr/update/">http://www.turbotax.com/atr/update/</ref><ref source="XF" url="http://xforce.iss.net/static/6622.php">turbotax-save-passwords(6622)</ref></refs><vuln_soft><prod name="Turbo Tax" vendor="Intuit"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0466" published="2001-06-18" seq="2001-0466" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98633176230748&amp;w=2">BUGTRAQ:20010403 new advisory</ref></refs><vuln_soft><prod name="uStorekeeper Online Shopping System" vendor="Microburst"><vers num="1.61"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0467" published="2001-06-27" seq="2001-0467" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a \... (modified dot dot) in an HTTP URL request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/178935">BUGTRAQ:20010423 Vulnerability in Viking Web Server</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2643">BID:2643</ref><ref source="CONFIRM" url="http://www.robtex.com/files/viking/beta/chglog.txt">http://www.robtex.com/files/viking/beta/chglog.txt</ref><ref source="XF" url="http://xforce.iss.net/static/6450.php">viking-dot-directory-traversal(6450)</ref></refs><vuln_soft><prod name="Viking Server" vendor="RobTex"><vers num="1.0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0468" published="2001-06-27" seq="2001-0468" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0163.html"></ref><ref adv="1" source="X-Force" url="http://xforce.iss.net/static/6234.php">6234</ref></refs><vuln_soft><prod name="FTPFS" vendor="Linux"><vers num="0.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0469" published="2001-06-27" seq="2001-0469" severity="Medium" type="CVE"><desc><descript source="cve">rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/freebsd/2001-03/0163.html">FreeBSD-SA-01:29</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2473">2473</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6229.php">6229</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="4.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0470" published="2001-06-27" seq="2001-0470" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0160.html"></ref><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0181.html"></ref><ref adv="1" source="X-Force" url="http://xforce.iss.net/static/6239.php">6239</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="5.8"/><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-2001-0471" published="2001-06-27" seq="2001-0471" severity="High" type="CVE"><desc><descript source="cve">SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/160648"></ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2345">2345</ref></refs><vuln_soft><prod name="SSH Daemon" vendor="SSH Communications Security"><vers num="1.2.30" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0472" published="2001-06-27" seq="2001-0472" severity="Medium" type="CVE"><desc><descript source="cve">Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0243.html"></ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6250.php">6250</ref></refs><vuln_soft><prod name="HSLCTF" vendor="IBM"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-15" name="CVE-2001-0473" published="2001-06-27" seq="2001-0473" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-031.php3">MDKSA-2001:031</ref><ref adv="1" patch="1" source="Redhat" url="http://www.redhat.com/support/errata/RHSA-2001-029.html">RHSA-2001:029</ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98473109630421&amp;w=2">IMNX-2001-70-006-01</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0246.html"></ref><ref adv="1" patch="1" source="X-force" url="http://xforce.iss.net/static/6235.php">6235</ref><ref source="CONECTIVA" url="http://distro.conectiva.com.br/atualizacoes/?id=a&amp;anuncio=000385">CLA-2001:385</ref><ref source="OSVDB" url="http://www.osvdb.org/5615">5615</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.2"/><vers num="6.0"/><vers num="6.1"/><vers num="6.2"/><vers num="7.0"/></prod><prod name="Conectiva Linux" vendor="Conectiva"><vers num=""/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="6.0"/><vers num="6.1"/><vers num="7.0"/><vers num="7.1"/><vers num="7.2"/></prod><prod name="Mutt" vendor="Mutt"><vers num="1.2.5" prev="1"/></prod><prod name="Immunix" vendor="Immunix"><vers num="6.2"/><vers num="7.0 Beta"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-14" name="CVE-2001-0474" published="2001-06-27" seq="2001-0474" severity="Low" type="CVE"><desc><descript source="cve">Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Linux-Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-029.php3">MDKSA-2001:029</ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6231.php">6231</ref></refs><vuln_soft><prod name="Mesa" vendor="Brian Paul"><vers num="3.3-14" prev="1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="7.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0475" published="2001-06-27" seq="2001-0475" severity="High" type="CVE"><desc><descript source="cve">index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0180.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2474">2474</ref><ref adv="1" patch="1" source="Vbulletin" url="http://www.vbulletin.com/forum/showthread.php?s=b20af207b5b908ecf7a4ecf56fbe3cd3&amp;threadid=10839"></ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6237.php">6237</ref></refs><vuln_soft><prod name="vBulletin" vendor="Jelsoft"><vers num="1.1.5" prev="1"/><vers num="2.0 beta 2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-06-15" name="CVE-2001-0476" published="2001-06-27" seq="2001-0476" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0233.html"></ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2492">2492</ref><ref patch="1" source="Aspseek" url="http://www.aspseek.org/changes.html"></ref><ref adv="1" patch="1" source="X-Force" url="http://xforce.iss.net/static/6248.php">6248</ref></refs><vuln_soft><prod name="ASPseek" vendor="SWsoft"><vers num="1.0.3" prev="1"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-2001-0477" published="2001-06-27" seq="2001-0477" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in WebCalendar 0.9.26 allows remote command execution.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0392.html">BUGTRAQ:20010423 (SRPRE00004) WebCalendar 0.9.26</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2639">BID:2639</ref></refs><vuln_soft><prod name="WebCalendar" vendor="WebCalendar"><vers num="0.9.8"/><vers num="0.9.26"/><vers num="0.9.25"/><vers num="0.9.24"/><vers num="0.9.23"/><vers num="0.9.22"/><vers num="0.9.21"/><vers num="0.9.20"/><vers num="0.9.19"/><vers num="0.9.16"/><vers num="0.9.15"/><vers num="0.9.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0478" published="2001-06-27" seq="2001-0478" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0396.html">BUGTRAQ:20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2642">BID:2642</ref></refs><vuln_soft><prod name="phpMyAdmin" vendor="phpMyAdmin"><vers num="2.2.0" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0479" published="2001-06-27" seq="2001-0479" severity="High" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0396.html">BUGTRAQ:20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2640">BID:2640</ref><ref source="CONFIRM" url="http://www.greatbridge.org/project/phppgadmin/cvs/checkout.php/phpPgAdmin/ChangeLog?r=1.13">http://www.greatbridge.org/project/phppgadmin/cvs/checkout.php/phpPgAdmin/ChangeLog?r=1.13</ref></refs><vuln_soft><prod name="phpPgAdmin" vendor="phpPgAdmin"><vers num="2.2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0480" published="2001-06-27" seq="2001-0480" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in Alex&apos;s FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0523.html">BUGTRAQ:20010428 Vulnerabilities in Alex&apos;s FTP Server</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2668">BID:2668</ref></refs><vuln_soft><prod name="Alex&apos;s FTP Server" vendor="Alex Linde"><vers num="0.7"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0481" published="2001-06-27" seq="2001-0481" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-043.php3">MANDRAKE:MDKSA-2001:043</ref><ref source="XF" url="http://xforce.iss.net/static/6494.php">linux-rpmdrake-temp-file(6494)</ref><ref source="OSVDB" url="http://www.osvdb.org/5612">5612</ref></refs><vuln_soft><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="8.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0482" published="2001-06-18" seq="2001-0482" severity="High" type="CVE"><desc><descript source="cve">Configuration error in Argus PitBull LX allows root users to bypass specified access control restrictions and cause a denial of service or execute arbitrary commands by modifying kernel variables such as MaxFiles, MaxInodes, and ModProbePath in /proc/sys via calls to sysctl.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0475.html">BUGTRAQ:20010330 Serious Pitbull LX Vulnerability</ref><ref source="XF" url="http://xforce.iss.net/static/6623.php">pitbull-lx-modify-kernel(6623)</ref></refs><vuln_soft><prod name="PitBull LX" vendor="Argus Systems"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-22" name="CVE-2001-0483" published="2001-06-18" seq="2001-0483" severity="High" type="CVE"><desc><descript source="cve">Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-03/0359.html">BUGTRAQ:20010324 Raptor 6.5 http vulnerability</ref><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/archive/1/171953">BUGTRAQ:20010327 RE: Raptor 6.5 http vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2517">BID:2517</ref></refs><vuln_soft><prod name="Raptor Firewall" vendor="Symantec"><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0484" published="2001-06-27" seq="2001-0484" severity="Medium" type="CVE"><desc><descript source="cve">Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0482.html">BUGTRAQ:20010425 Tektronix (Xerox) PhaserLink 850 Webserver Vulnerability (NEW)</ref><ref source="XF" url="http://xforce.iss.net/static/6482.php">tektronix-phaserlink-webserver-backdoor(6482)</ref></refs><vuln_soft><prod name="PhaserLink" vendor="Tektronix"><vers num="850"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-13" name="CVE-2001-0485" published="2001-06-27" seq="2001-0485" severity="High" type="CVE"><desc><descript source="cve">Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0475.html">BUGTRAQ:20010426 IRIX /usr/lib/print/netprint local root symbols exploit.</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/xforce/xfdb/6473">IRIX netprint -n allows attacker to access shared library</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2656">IRIX &amp;#39;netprint&amp;#39; Arbitrary Shared Library Usage Vulnerability</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0502.html">20010427 Re: IRIX /usr/lib/print/netprint local root symbols exploit.</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/20010701-01-P">20010701-01-P</ref><ref source="OSVDB" url="http://www.osvdb.org/8571">8571</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0486" published="2001-07-02" seq="2001-0486" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port 353.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0020.html">VULN-DEV:20010402</ref><ref adv="1" patch="1" source="TheAimsGroup" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98779821207867&amp;w=2">HI200101</ref><ref adv="1" patch="1" source="Novell" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/2959062.htm">2959062</ref><ref patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-05/0000.html">BUGTRAQ:20010501 Re: Proof of concept DoS against novell border manager enterprise edition 3.5</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2623">bid2623</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=98865027328391&amp;w=2">20010429 Proof of concept DoS against novell border manager enterprise</ref><ref source="XF" url="http://xforce.iss.net/static/6429.php">bordermanager-vpn-syn-dos(6429)</ref></refs><vuln_soft><prod name="BorderManager" vendor="Novell"><vers num="3.6" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0487" published="2001-06-27" seq="2001-0487" severity="Medium" type="CVE"><desc><descript source="cve">AIX SNMP server snmpd allows remote attackers to cause a denial of service via a RST during the TCP connection.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/aix/2001-q2/0005.html">AIXAPAR:IY17630</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IY17630&amp;apar=only">IY17630</ref><ref source="XF" url="http://www.iss.net/security_center/static/6996.php">aix-snmpd-rst-dos(6996)</ref><ref source="OSVDB" url="http://www.osvdb.org/5611">5611</ref></refs><vuln_soft><prod name="AIX SNMP" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0488" published="2001-06-27" seq="2001-0488" severity="Low" type="CVE"><desc><descript source="cve">pcltotiff in HP-UX 10.x has unnecessary set group id permissions, which allows local users to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/hp/2001-q2/0018.html">HP:HPSBUX0104-149</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2646">BID:2646</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX0104-149">HPSBUX0104-149</ref><ref source="XF" url="http://xforce.iss.net/static/6447.php">hp-pcltotiff-insecure-permissions(6447)</ref><ref source="OSVDB" url="http://www.osvdb.org/2188">2188</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.26"/><vers num="10.20"/><vers num="10.10"/><vers num="10.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0489" published="2001-06-27" seq="2001-0489" severity="High" type="CVE"><desc><descript source="cve">Format string vulnerability in gftp prior to 2.0.8 allows remote malicious FTP servers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/linux/redhat/2001-q2/0043.html">REDHAT:RHSA-2001:053</ref><ref adv="1" patch="1" source="Neohapsis" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0509.html">MANDRAKE:MDKSA-2001-044</ref><ref source="VULN-DEV" url="http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0231.html">20010417 gftp exploitable?</ref><ref source="DEBIAN" url="http://www.debian.org/security/2001/dsa-057">DSA-057</ref><ref source="BID" url="http://www.securityfocus.com/bid/2657">2657</ref><ref source="XF" url="http://xforce.iss.net/static/6478.php">gftp-format-string(6478)</ref><ref source="OSVDB" url="http://www.osvdb.org/1805">1805</ref></refs><vuln_soft><prod name="gFTP" vendor="gFTP"><vers num="2.0.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0490" published="2001-06-27" seq="2001-0490" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0518.html">BUGTRAQ:20010429 Winamp 2.6x / 2.7x buffer overflow</ref></refs><vuln_soft><prod name="Winamp" vendor="NullSoft"><vers num="2.6x"/><vers num="2.7x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0491" published="2001-06-27" seq="2001-0491" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0465.html">BUGTRAQ:20010425 Vulnerabilities in RaidenFTPD Server</ref><ref source="XF" url="http://xforce.iss.net/static/6455.php">raidenftpd-dot-directory-traversal(6455)</ref></refs><vuln_soft><prod name="RaidenFTPD" vendor="Team JohnLong"><vers num="2.1 build 947"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0492" published="2001-06-27" seq="2001-0492" severity="Medium" type="CVE"><desc><descript source="cve">Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0427.html">BUGTRAQ:20010424 Advisory for Netcruiser</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2650">BID:2650</ref><ref source="XF" url="http://xforce.iss.net/static/6468.php">netcruiser-server-path-disclosure(6468)</ref></refs><vuln_soft><prod name="NetCruiser Web Server" vendor="NetCruiser Software"><vers num="0.1.2.8" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0493" published="2001-06-27" seq="2001-0493" severity="Medium" type="CVE"><desc><descript source="cve">Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0428.html">BUGTRAQ:20010424 Advisory for Small HTTP Server</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/2649">BID:2649</ref><ref source="CONFIRM" url="http://home.lanck.net/mf/srv/index.htm">http://home.lanck.net/mf/srv/index.htm</ref><ref source="XF" url="http://xforce.iss.net/static/6446.php">small-http-aux-dos(6446)</ref></refs><vuln_soft><prod name="Small HTTP server" vendor="Max Feoktistov"><vers num="2.03"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0494" published="2001-06-27" seq="2001-0494" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0433.html">BUGTRAQ:20010424 IPSwitch IMail 6.06 SMTP Remote System Access Vulnerability</ref><ref source="CONFIRM" url="http://ipswitch.com/Support/IMail/news.html">http://ipswitch.com/Support/IMail/news.html</ref><ref source="XF" url="http://xforce.iss.net/static/6445.php">ipswitch-imail-smtp-bo(6445)</ref><ref source="OSVDB" url="http://www.osvdb.org/5610">5610</ref></refs><vuln_soft><prod name="Imail" vendor="Ipswitch"><vers num="6.06" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0495" published="2001-06-27" seq="2001-0495" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://archives.neohapsis.com/archives/bugtraq/2001-04/0490.html">BUGTRAQ:20010426 Vulnerability in WebXQ Server</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2660">BID:2660</ref><ref source="XF" url="http://xforce.iss.net/static/6466.php">webxq-dot-directory-traversal(6466)</ref><ref source="OSVDB" url="http://www.osvdb.org/1799">1799</ref></refs><vuln_soft><prod name="WebXQ" vendor="Datawizard"><vers num="2.1.204"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0496" published="2001-06-27" seq="2001-0496" severity="Medium" type="CVE"><desc><descript source="cve">kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Red Hat" url="http://www.redhat.com/support/errata/RHSA-2001-059.html">REDHAT:RHSA-2001:059</ref><ref adv="1" patch="1" source="Mandrake" url="http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-046.php3">MANDRAKE:MDKSA-2001:046</ref><ref source="XF" url="http://xforce.iss.net/static/6856.php">kdelibs-kdesu-insecure-tmpfile(6856)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="7.1"/></prod><prod name="Mandrake Linux" vendor="MandrakeSoft"><vers num="2007.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0497" published="2001-07-21" seq="2001-0497" severity="Medium" type="CVE"><desc><descript source="cve">dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise78.php">BIND Inadvertent Local Exposure of HMAC-MD5 (TSIG) Keys</ref><ref source="XF" url="http://xforce.iss.net/static/6694.php">bind-local-key-exposure(6694)</ref><ref source="OSVDB" url="http://www.osvdb.org/5609">5609</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="8.2.4" prev="1"/><vers num="9.1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0498" published="2001-07-21" seq="2001-0498" severity="Medium" type="CVE"><desc><descript source="cve">Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="PGP Security" url="http://www.pgp.com/research/covert/advisories/049.asp">NAI:20010627 Oracle 8i SQLNet Header Vulnerability</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/049.asp">20010627 Oracle 8i SQLNet Header Vulnerability</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0499" published="2001-07-21" seq="2001-0499" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="PGP Security" url="http://www.pgp.com/research/covert/advisories/050.asp">NAI:20010627 Vulnerability in Oracle 8i TNS Listener</ref><ref source="NAI" url="http://www.nai.com/research/covert/advisories/050.asp">20010627 Vulnerability in Oracle 8i TNS Listener</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-2001-16.html">CA-2001-16</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/620495">VU#620495</ref><ref source="BID" url="http://www.securityfocus.com/bid/2941">2941</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6758">oracle-tns-listener-bo(6758)</ref></refs><vuln_soft><prod name="Oracle8i" vendor="Oracle"><vers num="8.1.7" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0500" published="2001-07-21" seq="2001-0500" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-033.asp">MS01-033</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-2001-13.html">CA-2001-13</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/191873">20010618 All versions of Microsoft Internet Information Services, Remote buffer overflow (SYSTEM Level Access)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2880">2880</ref><ref source="XF" url="http://www.iss.net/security_center/static/6705.php">iis-isapi-idq-bo(6705)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-098.shtml">L-098</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:197">oval:org.mitre.oval:def:197</ref></refs><vuln_soft><prod name="Index Server" vendor="Microsoft"><vers num="2.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="6.0 beta" prev="1"/></prod><prod name="Indexing Service" vendor="Microsoft"><vers num="Windows 2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0501" published="2001-07-21" seq="2001-0501" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99325144322224&amp;w=2">BUGTRAQ:20010622 Fwd: Microsoft Word macro vulnerability advisory MS01-034</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-034.asp">MS01-034</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/2876">bid2876</ref><ref source="XF" url="http://xforce.iss.net/static/6732.php">msword-macro-bypass-security(6732)</ref></refs><vuln_soft><prod name="Word" vendor="Microsoft"><vers num="2002" prev="1"/><vers edition="Mac" num="98"/><vers num="98"/><vers num="97 SR2"/><vers num="97 SR1"/><vers num="97"/><vers edition="Mac" num="2001"/><vers num="2000 SR2"/><vers num="2000 SR1a"/><vers num="2000 SR1"/><vers num="2000"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0502" published="2001-07-21" seq="2001-0502" severity="Medium" type="CVE"><desc><descript source="cve">Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/MS01-036.asp">MS01-036</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-101.shtml">L-101</ref><ref source="XF" url="http://xforce.iss.net/static/6745.php">win2k-ldap-change-passwords(6745)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2929">2929</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0503" published="2001-07-21" seq="2001-0503" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft NetMeeting 3.01 with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service via a malformed string to the NetMeeting service port, aka a variant of the &quot;NetMeeting Desktop Sharing&quot; vulnerability.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms00-077.asp">MS00-077</ref><ref source="XF" url="http://www.iss.net/security_center/static/5368.php">netmeeting-desktop-sharing-dos(5368)</ref><ref source="OSVDB" url="http://www.osvdb.org/5608">5608</ref></refs><vuln_soft><prod name="NetMeeting" vendor="Microsoft"><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0504" published="2001-08-14" seq="2001-0504" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in authentication process for SMTP service in Microsoft Windows 2000 allows remote attackers to use incorrect credentials to gain privileges and conduct activites such as mail relaying.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms01-037.asp">MS01-037</ref><ref source="XF" url="http://xforce.iss.net/static/6803.php">win2k-smtp-mail-relay(6803)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2988">2988</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-107.shtml">L-107</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/435963">VU#435963</ref></refs><vuln_soft><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-2001-0505" published="2001-10-30" seq="2001-0505" severity="Medium" type="CVE"><desc><descript source="cve">Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms01-039.asp">MS01-039</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/581603">VU#581603</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/994851">VU#994851</ref><ref source="BID" url="http://www.securityfocus.com/bid/3089">3089</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6882">sfu-nfs-dos(6882)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/6883">sfu-telnet-dos(6883)</ref></refs><vuln_soft><prod name="Microsoft Services" vendor="Microsoft"><vers edition="Unix" num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0506" published="2001-09-20" seq="2001-0506" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the &quot;SSI privilege elevation&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms01-044.asp">MS01-044</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/3190">bid3190</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=99802093532233&amp;w=2">20010817 NSFOCUS SA2001-06 : Microsoft IIS ssinc.dll Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/242541">20011127 IIS Server Side Include Buffer overflow exploit code</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-132.shtml">L-132</ref><ref source="XF" url="http://xforce.iss.net/static/6984.php">iis-ssi-directive-bo(6984)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-2001-0507" published="2001-09-20" seq="2001-0507" severity="High" type="CVE"><desc><descript source="cve">IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the &quot;System file listing privilege elevation&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms01-044.asp">MS01-044</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/205069">20010816 ENTERCEPT SECURITY ALERT: Privilege Escalation Vulnerability in Microsoft IIS</ref><ref source="XF" url="http://xforce.iss.net/static/6985.php">iis-relative-path-privilege-elevation(6985)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/l-132.shtml">L-132</ref><ref source="OSVDB" url="http://www.osvdb.org/5607">5607</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:909">oval:org.mitre.oval:def:909</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:912">oval:org.mitre.oval:def:912</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-2001-0508" published="2001-09-20" seq="2001-0508" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in IIS 5.0 allows remote attackers to cause a denial of service (restart) via a long, invalid WebDAV request.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/ms01-044.asp">MS01-044</ref><ref source="BUGTRAQ" url="http://online.securityfocus.com/archive/1/182579">20010506 IIS 5.0 PROPFIND DOS #2</ref><ref source="XF" url="http://www.iss.net/security_center/static/6982.php">iis-webdav-long-request-dos(6982)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2690">2690</ref><ref source="OSVDB" url="http://www.osvdb.org/5606">5606</ref><ref source="OSVDB" url="http://www.osvdb.org/5633">5633</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-2001-0509" published="2001-09-20" seq="2001-0509" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft TechNet" url="http://www.microsoft.com/technet/security/bulletin/MS01-041.asp">MS01-041</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/6914.php">ms-malformed-rp
