|
| Jun / 2003 |
Exploits |
- ATFTPd Exploit Code Release (Long Filename)
- Exploit Code Release for lsmcode Vulnerability
- Exploit Code Released for errpt
- Exploit Code Released for diagrpt Vulnerability
- Apache 2.x APR Exploit Code
- Magic Winmail Server Format String Vulnerability (Exploit)
- IIS WebDAV Exploit New Release
|
| May / 2003 |
Exploits |
- Maelstrom Vulnerable to a Local Buffer Overflow (Another Exploit)
- WsMp3d Remote Exploit for Heap Overflow Vulnerability (CHA)
- Maelstrom Vulnerable to a Local Buffer Overflow (Exploit)
- Cdrecord Format String Vulnerability
- Remote BZFlag Server DoS
- Vulnerabilities in Kerio Personal Firewall (Exploit)
- Polycom 6100-4 NetEngine Denial of Service Attack (TFTP)
- Pi3Web Vulnerable to a DoS (Multiple /)
|
| Apr / 2003 |
Exploits |
- PoPToP PPTP Server Remote Exploit Code Released
- Snort TCP Stream Reassembly Integer Overflow Exploit
- ATM on Linux Exploit Code Release (les, local)
- Half-Life Exploit Code Released (Malformed Packet)
- Remote BSD Samba call_trans2open i386 Buffer Overflow Exploit
- Local Exploit for Sendmail's prescan() Function
- Remote Multiple Buffer Overflow Vulnerabilities in Passlogd Sniffer
|
| Mar / 2003 |
Exploits |
- Chindi DoS Exploit Code
- Remote BitchX/Epic Exploit Code (Serverside)
- OpenSSL Ptrace Exploit Code
- WebDAV Exploit Code Released
- Ptrace Exploit Code Released
- Locator Service Buffer Overflow Exploit Code
- Exploit Released for the Intel PXE Buffer Overflow
- PGP4Pine Exploit Mail Generator
- Exploit Released for SUNWlldap Library Buffer Overflow
- TCPDUMP ISAKMP Denial of Service Exploit Released
- MySQL's Default Configuration Allows Modification of MySQL's Execution Owner (FILE Permissions)
- OpenBSD lprm(1) Exploit
- Win32hlp Exploit for : ":LINK overflow"
- XFree86 XLOCALEDIR Exploit Code
- Buffer Overflow Vulnerability Found in file (Exploit Code)
- DoS Vulnerability in Eudora
|
| Feb / 2003 |
Exploits |
- STMKFont Exploit Code Released
- NetHack 'games' Privileges Escalation Exploit Code (-s)
- RealServer 8 Remote Buffer Overflow Vulnerability (Exploit, SETUP, RTSP)
- Exploit for CVS Double free() for Linux pserver
|
| Jan / 2003 |
Exploits |
- MS-SQL Vulnerability Exploiting Trusted Connections
- Solaris 'at' Exploit Code
- Outlook Remote Code Execution in Preview Pane (S/MIME, PoC)
- MSSQL2000 Remote UDP Exploit
- Local and Remote Exploit For ISC DHCPd Format String (Update Log)
- Stunnel Format String Vulnerability (Exploit)
- Local and Remote Exploit for MySQL (Password Scrambling)
- Psunami Bulletin Board CGI Remote Command Execution
- Security Vulnerability Found in S8Forum
- Tanne Format String Exploit Code
- OpenBSD and NetBSD LKM That Hides Files by Patching getdirentries()
- Ptrace() Injector (Malaria)
- Smart Search CGI Remote Command Execution Exploit
- CUPS Integer Overflow Exploit
|
| Dec / 2002 |
Exploits |
- PUTTY SSH-Client Exploit
- zkfingerd Remote Exploit
- Melange Chat System Remote Exploit Code Released
- Remote Heap malloc/free and Multiple Overflow Vulnerability in WSMP3 (Exploit)
- Exploit for Sendmail Local Root Vulnerability (FreeBSD, -d)
- Pfinger Exploit Code Released
- Pc-cillin pop3trap.exe Buffer Overflow Exploit
- Cobalt RaQ4 Remote Root Exploit (overflow.cgi)
- Zeroo Webserver Remote Directory Traversal Exploit
- BigFun Remote DoS Attack
- VNC Man in the Middle Exploit Code
|
| Nov / 2002 |
Exploits |
- Apache Scoreboard Shared Memory
- Oracle TNS SEH Exploit
- Calisto Internet Talker DoS
- Linux Rsync Remote Exploit Code
- Local Root Exploit for cifslogin on HP-UX
- i386 Linux Kernel DoS (Local)
- vBulletin Calendar Improved Exploit Code
- Exploit Code for IP Smart Spoofing
- QNX Timer Implementation Vulnerable to DoS
- Xsun (Sparc) Local Exploit (RGB_DB)
|
| Oct / 2002 |
Exploits |
- Windows RPC DoS Exploit Code (from SPIKE to C)
- Sendmail Local Exploit Code (GDB support)
- GetAd, NetDDE Exploit Code (WM_COPYDATA)
- Mod_SSL Off-By-One Exploit Code (htaccess)
- Linux Traceroute Exploit Code Released (GDB)
- Proof of Concept Exploit of Windows Help Overflow
- Windows Help Buffer Overflow PoC
- FreeBSD File Descriptors Bug (Iosmash2)
- Telnet/SSH Command Injection via PTrace
|
| Sep / 2002 |
Exploits |
- Local Root Exploit Found in gds_lock_mgr
- OpenSSL Exploit Code (Slapper)
- Buffer Overruns in SQL Server 2000 Resolution Service Could Enable Code Execution (Exploit)
- vBulletin Calendar Command Execution Vulnerability (Exploit)
- AlsaPlayer Buffer Overflow Exploit
- Local Root Exploit for Cisco VPN 5000 Client
- Remote Exploitable Heap Overflow in Null HTTPd
- Cisco VPN Concentrator 3000 ISAKMP DoS details
- Linuxconf Locally Exploitable Buffer Overflow Vulnerability (Exploit)
- PerlCal cal_make.pl Directory Traversal
- EFStool Local Root Exploit for Linux/x86
- KSTAT (and Maybe Others) Bypass (Phantasmagoria)
- Zero Width GIF (Exploit)
- pwck Local Buffer Overflow
|
| Aug / 2002 |
Exploits |
- Caldera Xserver Exploit Code (xkbcomp)
- GDAM123 Exploit Code Released
- Exploit Code Release for Apache Directory Traversal (non-UNIX)
- Windows SMB Nuker
- Denial of Service against MySQLd (Multiple Connections)
- Advanced Windows Shellcode
- Buffer Overflow in MyWebServer (Exploit, GET)
- Cisco IOS Heap Exploit Proof of Concept
- IMAP4rev1 Remote Exploit Code Released (LSUB)
- Remote Exploit Code for Solaris SPARC TelnetD
- Cobalt Linux Local Root Exploit (authenticate)
- Citrix and Terminal Server Multiple Exploits
- Tool allows Hijacking Kernel Symbols and Functions to Hide Binary Files
- Winhlp32.exe Buffer Overflow Exploit Code
- Trillian IRC Event 001 Buffer Overflow Vulnerability (Exploit)
- Exploit Code Released for su Vulnerability (Tru64)
|
| Jul / 2002 |
Exploits |
- IPSwitch IMail Multiple Security Vulnerabilities (GET, HTTP/1.0)
- Arbitrary Code Execution Vulnerability in VanDyke SecureCRT
- How to Reproduce PHP Segfault
- Nanog Traceroute Format String Exploit
- PHP Resource Exhaustion Denial of Service
- TrendMicro's VirusWall Space Gap (Exploit)
- Stealing Hotmail.com Cookie and User Login
- IIS Administration Web Site Redirect Exploits
- 2fax Local Exploit Code Released (-bpcx)
- Exploit Code Released for MFC ISAPI Framework Buffer Overflow (BadBlue PWS)
- Exploit for Previously Reported DoS Issues in Shambala Server
- KCMS Configure Tool Security Vulnerability (Exploit)
- Remote Winamp Exploit (Product Updates)
- OpenBSD SSHd Remote Root Exploit
|
| Jun / 2002 |
Exploits |
- PsyBNC DoS Exploit Code (Long Password)
- Wu-FTPd Remote Heap Overflow Exploit (In Java)
- Telindus Router 10xx and 11xx Remote Exploit
- Multiple Exploit Codes for Apache Chunked Buffer Vulnerability
- Cisco VPNclient Buffer Overflow
- TrACESroute GOLD Local Format String Exploit
- Ciscokill Exploit Code Released
- QNX Multiple Security Vulnerabilities (ptrace, SIGSEGV, phgrafx, phlocale)
- Mnews Exploit Code Released
|
| May / 2002 |
Exploits |
- Remote Exploit for UW-IMAPd Capability (IMAP4)
- YoungZSoft CMailServer Buffer Overflow
- Multiple Vulnerabilities in CISCO VoIP Phones (Additional details)
- cURL Remote Exploit Code Released
- Windows 2000 Server IIS 5.0 .ASP Overflow Exploit
- Bruteforcing support for PPPD (Patch)
- LabVIEW Web Server DoS Vulnerability Exploit Code Released
- 3CDaemon DoS Exploit
|
| Apr / 2002 |
Exploits |
- Suid Application Execution May Give Local Root (Testing App)
- Matu FTP Remote Buffer Overflow Vulnerability
- psyBNC Vulnerable to a DoS Attack (Exploit)
- Suid Application Execution May Give Local Root (Exploit Code)
- Gawk Contains an Exploitable Buffer Overflow
- Posadis Format String and Buffer Overflow Exploit Codes
- An Alternative Method to Check for LKM Backdoor/Rootkit
- /usr/bin/mail OpenBSD Local Root Compromise (Escaping Tilde, Exploit)
- INN Security Problems Allow Gaining of news Privileges
- Exploiting the Race Conditions in LogWatch
- Exploit for Tarantella Enterprise 3 Installations
- ICECast Remote Exploit Code (GET Overflow)
|
| Mar / 2002 |
Exploits |
- Oracle9i TSN Vulnerable to a DoS Attack
- Root Compromise through LogWatch (Exploit code)
- Exploiting the Zlib Bug in OpenSSH
- Solaris Login Remote Exploit (via telnetd)
- phpBB2 Remote Execution Command (db.php)
- SunSolve CD CGI Scripts Allows Remote Command Execution
- XTux Arena Vulnerable To a Denial of Service
- Citadel/UX Server Remote DoS Attack Vulnerability
- MTR Allows Local Users to Gain Root Privileges
- Windows SMTP Service Denial of Service (BDAT)
- Apache & PHP Proof of Concept Exploit
- Details and Exploitation of a Buffer Overflow in mshtml.dll (SRC)
|
| Feb / 2002 |
Exploits |
- Kazaa, Grokster and Morpheus Remote Denial of Service
- Alcatel 4400 PBX Hack
- Bypassing Content Filtering Software (Exploit)
- CodeBlue Vulnerable to an Exploitable Buffer Overflow
- SiteNews Remote Add User
- Avirt Gateway Remote Buffer Overflow Proof of Concept
- Format String Vulnerability in VXPrint Allows Gaining of Arbitrary Privileges
- Hanterm Exploit Code Released
- Sastcpd 'authprog' Local Root Compromise
- User-mode-Linux Security Flaws
- PHP Safe Mode Filesystem Circumvention Problem
- Multiple pwck/grpck Privilege Elevation Vulnerabilities (Exploit code)
- NETGEAR RO318 HTTP Filter Vulnerability
- mIRC irc:// Vulnerability and Nickname Buffer Overflow
|
| Jan / 2002 |
Exploits |
- SHOUTcast Vulnerable to Malformed CGI Request (admin.cgi)
- BadBlue Contains Multiple Security Vulnerabilities (Exploit code)
- UnixWare 7.1.1 Scoadminreg.cgi Local Exploit
- Improved UUCP Exploit Code Released
- Sniffit Exploit Code Released (normmail)
- Chinput Buffer Overflow Vulnerability Exploit Code Released
- /usr/bin/at Exploit Code Released
- UnixWare 7.1.1 rpc.cmsd Remote Exploit
- Eterm SGID 'utmp' Local Buffer Overflow
- UPNP Denial of Service (Joint code, Chargen, Initiator)
- Cross-Site Scripting Vulnerability Found in PostNuke
- BOOZT! Standard CGI Vulnerability (Exploit Released)
- Improper Input Validation in Bugzilla (Exploit)
- XTerm UnixWare Exploit Code Released (-xrm)
- /usr/dt/bin/dtterm Exploit Code Released (-xrm parameter)
- Solaris /bin/login Remote Exploit Code
- UPNP Exploit Code Released
- AIM Buffer Overflow Exploit
|
| Dec / 2001 |
Exploits |
- ATPHTTPd Buffer Overflow Exploit Code
- Windows 2000 IKE DoS Exploit Code
- OpenSSH UseLogin Bug Proof of Concept Exploit
- Lucent ORiNOCO Registry Decryption
- Microsoft IIS/5.0 Content-Length DoS Exploit Code
- Race Condition in FreeBSD AIO Implementation
- OpenBSD Local DoS (Bad Syscalls Releases)
- UUCP Family Exploit (uucp / uuparams / uuname)
- IIS Server Side Include Buffer Overflow (Exploit)
- Compaq Insight Manager Remote SYSTEM Shell (Exploit)
|
| Nov / 2001 |
Exploits |
- Firewall-1 Remote SYSTEM Shell Buffer Overflow
- PowerFTP Directory Traversal and DoS Vulnerabilities
- Digital UNIX CDE dtaction Vulnerability (proof of concept code, -user)
- ActivePerl PerlIS.dll Exploit Code Released
- More Problems with RADIUS (Protocol and Implementations, exploit code)
- RunAs Service Pipe Authentication Failure (exploit code)
|
| Oct / 2001 |
Exploits |
- Remote DoS in 6tunnel
- Weak Authentication in iBill's Password Management CGI
- Response Header Overflow Exploit Code Released
- Oracle9iAS Web Cache Multiple DoS and Buffer Overflow
- TYPSoft FTP Server STOR/RETR Denial of Service Vulnerability
- HylaFax Format String Vulnerabilities (Exploit Code)
- UnixWare 7 lpsystem Exploit Code Released
- Site Protector Password Cracker
- A Security Vulnerability in AIM Causes a DoS (Exploit)
- 3Com OfficeConnect 812/840 Router DoS Exploit Code
- CGIEmail's Command Execution Vulnerability (cgicso)
|
| Sep / 2001 |
Exploits |
- Digital UNIX msgchk Multiple Vulnerabilities (Username Overflow, One Liner)
- Kazaa / Morpheus Denial of Service Attack (Flood)
- AOLserver Exploit Code Released (ParseAuth)
- HP UNIX /usr/sbin/swverify Exploit Code
- JavaScript Can Write Anything to the Windows' Registry
|
| Aug / 2001 |
Exploits |
- Solaris Patchadd Symlink Exploit
- AOLserver Vulnerable To Host Buffer Overflow
- BSDi Reboot Machine Code as Any User
- Exploit Code Released For the Apache Server Address Disclosure Vulnerability
- Solaris Xlock Heap Overflow Vulnerability (Exploit, XUSERFILESEARCHPATH)
- Security Vulnerability found in /usr/bin/locate (Exploit Code)
- ARPNuke, Windows Network Nuker
- Denial of Service Vulnerability in SHOUTcast Server (User Agent, Host)
- Quake 3 Arena Security Vulnerability (CHAR 255, Exploit)
|
| Jul / 2001 |
Exploits |
- Pic LPd Remote Exploit (QUEUE)
- Solaris DTmail Buffer Overflow Vulnerability (MAIL Environment)
- Exploit Code Released for the SMTP Attachment Protection Bypass
- DIP Exploit Code Still Works After 3 Years
- FreeBSD TOP Kill/Renice Format String Vulnerability
- Linux Man Malicious Cache File Creation Vulnerability (Exploit)
- Exploit Code Released for the Small MSS Denial of Service
- ArGoSoft FTP Server Weak Password Encryption
- 3Com TelnetD Password Brute Forcing
- Messenger and Hotmail MITM Exploit (Arptool and Neaky)
- Xman Exploit Code Released
- Quake Spoofed Unconnected Users Denial of Service (Exploit Code)
- Samsung ML-85G Printer Linux Driver Binary Exploit
- FireWall-1 RDP Bypass Vulnerability Exploit Code Released
- Xloadimage Remote Vulnerability (Exploit)
- Multiple Exploit Codes Released for the CFingerD Vulnerability
- Causing CylantSecure to Delay Response
- LMail Local Root Exploit
- Exploits Released for the Solaris Libsldap Buffer Overflow (LDAP_OPTIONS)
- Exploit Code Released for Solaris 'at' Arbitrary Command Execution (Format String)
- Solaris Whodo Buffer Overflow Vulnerability (Exploit, SOR, CFTIME)
- Xvt Buffer Overflow Vulnerability (-T, -name)
- Cisco IOS HTTP Authorization Exploit Code
- Solaris Mailtool Buffer Overflow Exploit Code (OPENWINHOME)
- Exploit Code Released for the MS Windows 9x NETBIOS Password Verification Vulnerability
|
| Jun / 2001 |
Exploits |
- Exploit Code for the Buffer Overflow in XInetD Released (log.c)
- Exploit Code Released for the Index Server ISAPI Extension Vulnerability (IDQ)
- LPRng and Tetex Temp Files Race Vulnerability (UID LP Exploit)
- eXtremail Remote Format String Security Vulnerability
- KTVision Symlinks Vulnerability Leads to Root Compromise
- Suid Scotty (ntping) Buffer Overflow
- Buffer Overflow Found in GazTek HTTP Daemon (GET)
- Additional Details Released on the IIS Remote Buffer Overflow (Indexing Service, IDA)
- Apache Artificially Long Slash Directory Listing Exploit Code
- Rxvt Buffer Overflow Vulnerability
- WebStore Remote Command Execution
- BiblioWeb's Built-in Web Server Vulnerable to DoS (long URL)
- HPUX Old-style Exploit for Cau
- Exploit Code for Su-Wrapper Released
- Sudo Voodoo (Exploit)
- Man and Man-db MANPATH Exploit Code Released
- HP OpenView NNM Buffer Overflow Exploit Code Released (restore_config)
- /usr/bin/mail Buffer Overflow ($HOME)
- TWIG Unquoted SQL Query Vulnerability
- OmniHTTPd Source Viewing Exploit Code
|
| May / 2001 |
Exploits |
- Solaris Tip Buffer Overflow Vulnerability (Exploit Code)
- X-Chat Vulnerable to a Format String Attack (nickname)
- NetBIOS Session Request Flooder Exploit Code Released
- Netscape Enterprise Server Method and URI Overflow
- Microsoft FTP Server Wildcard Processing DoS (Exploit Code)
- IIS CGI Decode Vulnerability Exploit Code Released
- Sendfile Daemon Bugs
- Vixie Cron File Editing Security Vulnerability
- CFingerD Remote Format String Vulnerability (Advance Exploit Code)
- IISHACK2000 - Remote ISAPI Printer Buffer Overflow Exploit Code (Perl)
- Solaris mailx Vulnerability (-F option)
- Cisco's HSRP is vulnerable to a DoS attack
- IIS 5.0 ".printer" Exploit Code Released
|
| Apr / 2001 |
Exploits |
- Netprint Security Vulnerability Leads to Root Compromise (-n option)
- Proof of Concept DoS Code against Novell Border Manager Enterprise Edition
- PHP-Nuke Bad SQL Query Filtering Exploit Code Released
- DTSession Local Root Compromise (LANG environment)
- KCMS_configure Local Root Compromise (-o parameter, exploit)
- WFTPD Pro Vulnerable to a Buffer Overflow Attack (RETR, CWD)
- Globbing Exploit Code Released
- Exploit Code for HylaFAX Vulnerability Released (-q parameter)
- Oracle TNSLSNR DoS (Garbage, TCP 1521)
- Exploit code for Websweeper DoS (GET Request)
- Email List Generator security vulnerability (command execution)
- Exploit code released for CrazyWWWBoard vulnerability (User-Agent)
- Exploit code released for the M3U playlist overflow
- PTrace Improved Exploit Code Released (Race condition)
|
| Mar / 2001 |
Exploits |
- Silent Runner Collector Vulnerable to a Buffer Overflow (Large HELO)
- JavaServer Web Development Kit Directory Traversal Vulnerability
- Inframail DoS vulnerability (Large POST)
- PHP-Nuke vulnerability in XML parser
- Pi3Web Server vulnerable to a buffer overflow and path exposure
- Ikonboard v2.1.7b "show files" vulnerability
- Half-life Server Buffer Overflows and String Formatting Vulnerabilities
- INDEXU Authentication Bypass
- WarFTP Directory Traversal Vulnerability
- SlimServe HTTPd vulnerable to directory traversal
- Vulnerability in Muscat Empower exposes physical path
- WFTPd Pro Buffer Overflow Vulnerability (CWD)
- ROADS search system "show files" vulnerability with "null bite" bug
- SunFTP Vulnerable to chroot Breaking
- SurgeFTP vulnerable to a DoS (Malformed ls request)
- MERCUR Mailserver Buffer Overflow Vulnerability (EXPN)
- Exploit for the SSH CRC-32 Compensation Attack Detector Vulnerability
- Ja-elvis & Ko-helvis local root exploit
|
| Feb / 2001 |
Exploits |
- WebReflex HTTPd buffer overflow
- APC management card vulnerable to a DoS attack (1 at a time, Lockout timeout)
- Licq vulnerable to a DoS
- ELM exploit code released (-f parameter)
- WebSPIRS CGI script "show files" vulnerability
- Fore/Marconi ASX Switches DoS exploit code released
- Chili!Soft ASP contains multiple vulnerabilities
- BIND TSIG exploit code released
- NetSuite web server vulnerable to a buffer overflow attack
- Sedum HTTP Server vulnerable to directory traversal
- Vulnerability in Action Quake2 makes it vulnerable to a DoS
- Free Java Web Server vulnerable to directory traversal
- Resin Webserver vulnerable to directory traversal
- Thinking Arts Store.cgi Directory Traversal
- Winlogon Vulnerability Enables Local Users to Crash Windows NT/2000 (Exploit Code)
- Bajie HTTP JServer vulnerable to Shell Command Execution and Directory Traversal
- HIS Auktion "show files" and remote command execute vulnerabilities
- Workaround for the Unintended JSP Execution when using Oracle, Apache and JServ
- Potential Vulnerability in the execution of JSPs outside doc_root (Patch Available)
- Oracle Java Virtual Machine Vulnerability when granting file permission
- DC20Ctrl exploit code released
- Environment and Setup Variables can be access through WebPage.cgi
- Winsock Mutex vulnerability exploit code released
- SQLExec allows easy exploitation of default SQL passwords
- Buffer overflow and Directory Traversal Vulnerabilities in BiblioWeb Server
- Traversal Vulnerability found in Picserver
- Nobreak Technologies CrazyWWWBoard vulnerable to a buffer overflow
- XMail CTRLServer remote buffer overflow vulnerability
- Multiple vulnerabilities in Prospero CGI
- QNX RTP FTPd stack overflow
- IBM WebSphere vulnerable to CSS vulnerability
- Solaris ximp40 shared library buffer overflow
|
| Jan / 2001 |
Exploits |
- AudioGalaxy stores passwords insecurely
- BBS Forum vulnerable to showcode vulnerability
- Solaris mailx(1) lockfile bug
- Mac OS 9 Multiple Users Control Panel password vulnerability
- BS Scripts Multiple CGI Vulnerabilities
- Oracle Database Server vulnerable to a Denial of Service attack
- Netscape Enterprise Server REVLOG request problem
- Netopia R9100 Router vulnerable to a DoS (self-telnet)
- Format bugs in icecast allow remote code execution
- Borderware Firewall ping DoS vulnerability (Smurf exploit)
- SCO OpenServer /usr/bin/mscreen local exploit
- Tru64 (OSF/1) /usr/bin/su local exploit
- Buffer overflow in iPlanet Web Server 4 server side SHTML parsing module (Exploit)
- Matt's ICQ Clone Security Holes
- Solaris /usr/bin/write exploit code released
- jaZip exploitable buffer overflow (DISPLAY)
- Tcpdump remote root vulnerability (AFS parsing overflow)
- Exploit code released for the Memory leakage in ProFTPD (SIZE FTP)
- getgrnam() function exploit code released (Exploit)
- IRIX's fcagent daemon is vulnerable to a Denial of Service attack.
- CU parameter overflow vulnerability (Exploit code, -l command line argument)
- Fancylogin exploit code released (-h parameter)
- Another remote heap buffer overflow in oops (domain_name, Exploit)
- STonX exploit code released (HOME and STONEX environment variables)
|
| Dec / 2000 |
Exploits |
- Exploit code for xconq has been released (XCONQCONFIG)
- HP OpenView OmniBack II generic remote exploit
- C-Kermit exploit code released
- ITetris root exploit code released
- netToe vulnerable to a DoS
- Insecure input validation in everythingform.cgi, ad.cgi and simplestmail.cgi (command execution)
- PHP remote format string overflow vulnerability (Exploit code)
- IBM Net.Data Local Path Disclosure
- /usr/bin/pppd vulnerable to a buffer overflow (exploit code)
- File Upload via Form exploit code released
- BroadVision One-To-One Enterprise Path disclosure vulnerability
- BSDI /usr/contrib/mh/bin/inc local root exploit
- /usr/X11R6/bin/mogrify exploit code released (HOME env)
- BSDI /usr/bin/suidperl local root exploit
- Wingate MSG_OOB flag DoS (exploit code)
- Exploit code for Exchange content="" vulnerability
- PhoneBook exploit code released
|
| Nov / 2000 |
Exploits |
- glibc LANGUAGE exploit has been released
- Vulnerabilities found in PTlink (IRCd) and PTlink (Services)
- CGIForum allows reading of local files (thesection parameter)
- RCP shell escape bug allows execution of arbitrary commands
- rcvtty local exploit (for BSDI)
- Koules root exploit released
- Buffer overflow vulnerability in Oracle cmctl (exploit code)
- SmartServer password encryption cracked
- BrowseGate Password encryption cracked
- Bad password encryption in Cart32
- Vixie cron fopen() and preserved umask vulnerability
- WatchGuard Firebox Firewall DoS (resource depletion)
- BSDI Elm exploit code has been released (EXEC and TERM)
- Sockv5 exploit code has been released
- Cons.saver local DoS attack (NULL overwrite)
- BSDI Filter exploit code has been released
- Gnomehack exploit code has been released
- PHF Buffer overflow exploit code has been released
- GBook.cgi allows remote command execution
- RideWay PN Telnet DoS (garbled hostname)
- Security vulnerabilities in Small HTTP Server (DoS)
- Modutils and Netkit allow gaining of root access
- GSX vulnerable to a DoS (multiple connections)
- BIND 8.2.2-P5 DoS vulnerability (exploit, BIND_ZXFR)
- HP-UX resource monitor service (exploit)
- Authentix Input Validation security hole
- Quake World server buffer overflow (rcon)
- Exploit code released for the nasty XFree DoS
- Poll It CGI vulnerable to arbitrary command execution
- Remote command execution via KW Whois
- Exploit released for dump/restore vulnerability
- Bypassing Serv-U FTP Server's Anti-Hammering Protection
- Unify eWave ServletExec DoS
- Listmail exploit code released
- FormNow exploit code released
- Ultraseek Remote DoS Vulnerability (malformed request)
|
| Oct / 2000 |
Exploits |
- Mailing List & News remote security vulnerability exposed
- 'Host' command vulnerable to buffer overflow
- NTop -w vulnerability as an example for finding ESPs
- News Update's password protection can be bypassed
- Additional details about the IIS remote execution vulnerability
- JRun's vulnerabilities explained (command execution, file retrieval, WEB-INF)
- Multiple vulnerabilities in Half-life Dedicated Server for Linux
- HP-UX crontab temporary file symbolic link vulnerability
- NTop -w remote buffer overflow (exploit code)
- Avirt Mail vulnerable to a DoS (SMTP session)
- Xlock -d format string exploit code has been released
- Linux Napster remote DoS exploit code has been released
- Tin exploit code has been released (TERM variable)
- Route (/sbin/route) exploit has been released (add parameter)
- Linux Oracle security vulnerability (ORACLE_HOME)
- Linux /usr/X11R6/bin/bitmap exploit code has been released (-stipple)
- Linux /usr/games/zarch and /usr/games/splumber exploit code has been released
- Dopewars vulnerability allows gaining of privileged access (popen, HOME)
- Slrnpull exploit code has been released (SLRNPULL_ROOT)
- Makewhatis exploit code released
- DoS in Intel Corporation InBusiness eMail Station
- Vulnerability in Oracle Internet Directory
- DoS attack against computers running Microsoft NetMeeting (Additional details)
- Comprehensive exploit for PHP Format String vulnerability released
- Shred does not really wipe the file
- Bytes Interactive's Web Shopper (shopper.cgi) Directory Traversal Vulnerability
- Mail File POST vulnerability
- eXtropia WebStore Directory Traversal vulnerability (file viewing)
- PINE exploit has been released (periodical check)
- Ncurses buffer overflows (exploit code)
- Multiple OpenBSD products vulnerable to string format attacks (fstat, photurisd, talkd, eeprom)
- Klogd exploit using Envcheck
- Godmessage 4 exploit code has been released
- Glibc and userhelper can be used to gain local root
- OpenBSD xlock exploit code has been released
- OpenBSD vulnerable to an ARP-request DoS
- Local file exposure in Moreover.com's Cached_Feed.cgi
- BSD chpass exploit code released
- /bin/su local libc exploit yielding a root shell
- Webteacher's Webdata local files browsing vulnerability
|
| Sep / 2000 |
Exploits |
- Exploit code released for the WebTV DoS
- Extent RBS directory Transversal
- Harassing ICUII clients
- Immunix OS exploit code for the glibc 'format' string bug
- Exploiting Eudora and the double click Office vulnerability (DLL)
- IBM WebSphere 'Host:' vulnerability
- Another Horde library $from bug
- SCO UnixWare 7 / Double Vision local root exploit
- DoS in FUR HTTP Server
- Mobius DocumentDirect exploit code has been released
- MultiHTML vulnerability allows local files retrieval
- Sambar Server search CGI vulnerability
- Robotex Viking Server exploit code has been released
- TYPSoft FTP Server remote DoS
- YaBB security vulnerability ($num)
- AnyPortal (php) allows access to local files
- Unsafe passing of variables to mailform.pl in MailForm
- WinSMTPD remote exploit and DoS (HELO)
- NetMailshar Denial of Service Vulnerability
- Tetrinet for Linux Denial of Service attack
- PhpPhotoAlbum file access vulnerability (explorer, getalbum)
- Exploit code for screen root compromise has been released (string bug)
- Windows 9x share service file handle vulnerability
- EFTP vulnerable to two DoS attacks
- CPMdaemon password brute force attack
- WFTPD contains two security vulnerabilities (%C and upper characters)
|
| Aug / 2000 |
Exploits |
- More problems with Auction Weaver & CGI Script Center (fromfile)
- SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open)
- News Publisher CGI vulnerability (new authors)
- GoodTech's FTP Server vulnerable to a DoS (RNTO)
- DoS vulnerability in vqServer (long URL)
- SuidPerl exploit code and patch released
- Totalbill vulnerable to an exploitable buffer overflow
- Denial of Service problem with Pragma TelnetServer 2000 (DoS)
- Account Manager CGI vulnerability (Admin password)
- Subscribe Me users can modify the administrative password without knowing it
- Gopher+ contains an exploitable buffer overflow (halidate)
- Wais.pl parameter passing security problem (attack walkthrough)
- Exploitable buffer overflow in Darxite password authentication (DoS, Buffer overflow)
- Diablo 2 TCP/IP Sever DoS
- HtGrep CGI vulnerable to arbitrary file viewing
- Omron Worldview root compromise (Environment)
- Netauth vulnerable to dotdotdot traversal (password file retrieval)
- Imail Web Service remote DoS attack (HOST)
- An exploitable stack overflow in procps's top (HOME)
- Statistics Server exploitable buffer overflow (Large GET)
- LSD releases numerous exploits for IRIX
- A new advanced exploit code for the string formating vulnerability in StatD
- Firewall-1 Session Agent security hole still exist (DoS and password recovery)
- Serv-U FTP Server vulnerable to NULL byte attack (DoS)
- Kon2 vulnerable to a locally exploitable root compromise (CHARSET_REGISTRY)
- PHP Path Revealing Vulnerability
|
| Jul / 2000 |
Exploits |
- TelServ reveals usernames and passwords
- Kaufman Mail Warrior's weak encryption has been cracked
- AnalogX Proxy DoS (USER, HELO, SOCK4)
- Winamp M3U playlist parser buffer overflow vulnerability
- Multiple vulnerabilities in WFTPD (STAT, REST, MLST)
- StatD string format parsing root exploit code
- GAMSoft's TelSrv vulnerable to a DoS
- Gatekeeper remote exploit code has been released
- Input Validation FTPD vulnerabilities explained and summarized
- Guild FTPd allows remote checking for files existence
- WFTPD vulnerable to a remotely exploitable DoS (RNTO)
- Remote DoS attack on WircSrv Irc Server
- Poll It CGI exposes local files
- Remote DoS problem found in LocalWEB HTTP Server
|
| Jun / 2000 |
Exploits |
- LeafChat IRC client Denial of Service
- IP options exploit code has been released
- Polish SMS Gateway vulnerable to remotely exploitable buffer overflow
- XFree86 libICE DoS
- Trivial DoS attack of LDAP services ('*' attack)
- WuFTPD remote root exploit code has been released (MKD, CWD, SITE EXEC)
- NetWin's Dmailweb Denial of Service attack (pophost, username)
- GPM Denial of Service attack
- iMesh vulnerable to remote code execution
- MDaemon vulnerable to a remote DoS (UIDL)
- AnalogX SimpleServer vulnerable to remote DoS
- Dragon Server vulnerable to several DoS attacks
- Buffer overflow problem in the Small HTTP Server
- Dump exploit code has been released (-R)
- Splitvt exploit code has been released
- SoftHead A-FTP vulnerable to DoS attack
- Exploit code has been released for the Remote Registry Access Authentication vulnerability
- INNd remote news user/group exploit code released
- Snoop vulnerable to a remotely exploitable buffer overflow
- WebBanner CGI allows executing of arbitrary commands
- Mercur Mail server large buffer exploit code has been released
- MailStudio remote code execution exploit code
- Path revealing vulnerabilities in Ceilidh bulletin board
- Sendmail local root exploit using the Linux Capabilities bug
- MS Access 97's poor password encryption
- EServ's logging mechanism contains a heap overflow problem
- DoS vulnerability in IMate WebMail Server
- Savant Webserver exposes CGI script source
- DoS vulnerability in IMate WebMail Server
- Buffer Overrun problem in ITHouse Mail Server
- Majordomo exploit code released
- Media Streaming Broadcast Distribution DoS exploit code released
- /usr/bin/Mail exploit code for Slackware released
- Netwin DSMTP server exploit code released
- Deerfield Communications MDaemon Mail Server DoS (long username)
- gdm exploit code has been released (xdmcp)
- IPX 'storm' Denial of Service
- Xterm Denial of Service attack
- A new DoS attack against Real Server (template)
|
| May / 2000 |
Exploits |
- cdrecord exploitable buffer overflow
- Additional majordomo security vulnerabilities
- Kdesud root compromise
- Jolt2 - a new Windows DoS attack
- Ezboard vulnerable to remotely exploitable DoS attack
- gdm remote hole can lead to root compromise
- Infosrch.cgi exploit code creates an "interactive" shell
- MDBMS remote exploit code has been released
- Gauntlet Firewall exploit code has been released
- Fdmount local exploit code has been released
- Lotus Domino Server allows documents to be modified remotely
- Xsolider exploitable buffer overflow
- New exploit code for AntiSniff "patched" version
- ksu and krshd exploit code released
- Lotus ESMTP Service vulnerable to DoS
- Intel Express router vulnerable to remote DoS
- Remote Denial of Service against Axent NetProwler
- klogin remote exploit code has been released
- KSCD exploit code released
- Matt Kruse Calendar script allows remote code execution
- CProxy DoS code released
- Argosoft FTP Server contains several security vulnerabilities
- Proxy Plus insecure defaults
- NiteServer FTPd DoS
- AntiSniff can be attacked to execute arbitrary code
- Banner Rotation 01's password exposure
- Mining BlackICE with RFPickAxe
- BreezeCOM adapters use factory set passwords
- Emurl's User ID generation mechanism cracked
- Eudora Pro and Outlook vulnerable to long filename vulnerability
- PCAnywhere configuration files use weak passwords encryption
- Root compromise bug in Bugzilla (unchecked system() call)
- NetBSD unaligned IP options DoS
- FormMail discloses environment variables information
- Solaris root exploit for /usr/lib/lp/bin/netpr
- Internet Explorer Opens the Cookie Jar
- Netopia DSL Router Vulnerability
- AOL Instant Messenger path disclosure
- Microsoft Office 2000 UA Control Scripting exploit code
- Cisco's "show" command shows too much
- NetStructure 7180 backdoor vulnerability
- WebWho CGI can compromise system security
- Remote DoS attack using the "Malformed Extension Data in URL" vulnerability
- DNewsweb exploit code released
- Cayman 3220-H DSL Router vulnerable to a DoS (long username/password)
- Timbuktu Pro exploit code released
- Remotely exploitable buffer overflow in Sniffit
- IIS Denial-of-Service vulnerability (MaxClientRequestBuffer)
- Tcpdump found to be vulnerable to a DoS
- Source code to mstream, a DDoS tool, has been released
- Listserv web archives exploitable buffer overflow
- Dmailweb buffer overflow vulnerability allows remote code execution
- CASSANDRA NNTPServer vulnerable to remote DoS
- New Windows 95/98 Denial of Service discovered (NULL source name)
- Gnomelib exploit code has been released
|
| Apr / 2000 |
Exploits |
- Solaris lpset dlopen vulnerability
- Novell's remote administration service vulnerable to a buffer overflow (8008, DoS)
- IC Radius suffers from a buffer overflow vulnerability
- Cisco router vulnerable to an HTTP based DoS
- SuSE vulnerability allows impermissible file deletion by local users (MAX_DAYS_IN_TMP)
- Piranha default password exploit code
- HP printers vulnerable to remote DoS (spooler port)
- CVS vulnerable to DoS
- Sendmail's mail.local vulnerability (unsafe fgets)
- Solaris x86 Xsun overflow
- Solaris 7 x86 lp exploit
- Solaris 7 x86 lpset exploit
- Hylafax version 4.0.2 vulnerable to a local root exploit
- Remote vulnerability in LCDproc 0.4 (shell access)
- Panda Security found to contain multiple security vulnerabilities
- DoS attack against HP JetDirect Printers
- Windows 9x's explorer.exe contains a buffer overflow (long filenames)
- ZoneAlarm Firewall can be easily scanned for open ports
- AdTran's MX2800 M13 found to be vulnerable to a DoS (Ping Flood)
- QNX's crypt, encryption algorithm has been cracked
- AVM's Ken! Proxy vulnerable to two security holes (DoS, dotdotdot traversing)
- IMAPd vulnerable to a remotely exploitable buffer overflow
- Remote DoS attack in Real Networks' RealServer (412 magic)
- More vulnerabilities in FP (CERN Image Map Dispatcher)
- Netscape JavaScript-in-cookies security hole
- StarOffice can be caused to crash by a simply embedding a URL
- htDig reveals web server configuration paths
- DVWSSR.DLL found to contain a remotely exploitable buffer overflow
- TrendMicro's Interscan vulnerable to remotely exploitable DoS (HELO, 4075)
- TalentSoft Web+ input validation bug vulnerability
- IE is still vulnerable to Cross-frame security when Javascript is enabled
- XFServer vulnerable to DoS attack (Xwrapper)
- Dvwssr.dll allows downloading of ASP source code ('Netscape engineers are weenies')
- CRYPTOCard PalmToken PIN Extraction code released
- SalesLogix Eviewer Web App vulnerable to remote DoS
- BeOS network process DoS
- Infonautics getdoc.cgi allows unauthorized access to local documents
- BizDB Search Script exposes server to remote command execution
- Eicon's ISDN Modem is vulnerable to a Denial-of-Service attack
- WebObjects application server DoS attack
- FCheck system() vulnerability
- New CGI vulnerabilities uncovered.
|
| Mar / 2000 |
Exploits |
- Windows TCP/IP Print Request Server vulnerable to DoS
- MS Index Server vulnerability allows viewing of ASP source code
- Exploit code released for the objectserver security vulnerability
- Linux gpm setgid vulnerability
- vqSoft's vqServer stores passwords in plaintext
- Local Denial of Service attack against Linux (/dev/log & socket)
- GNQS vulnerable to local root compromise
- PIX DMZ Denial of Service (TCP Resets)
- OfficeScan exposes local networks to centralized DoS
- Netscape Enterprise Server and '?wp' tags
- Several exploits for the wmcdplay vulnerability
- Netscape Messenger sends out sensitive information (LiveConnect)
- Cross Site Scripting exploit code released (Internet Explorer)
- Several security bugs in Netscape Navigator
- Exploit code released for the userhelper security vulnerability
- Abuse.man CGI security vulnerability allows remote command execution
- IMWheel allows gaining of local root privileges
- Kreatecd vulnerable to local root compromise
- Sojourn search engine vulnerable to directory traversal
- Mercur POP3 / IMAP server vulnerable to DoS
- Navigator interprets HTML in ftp directory listings
- Mercur's WebView WebMail Client vulnerable to DoS attack
- Extending the FTP "ALG" vulnerability to any FTP client
- IrcII-4.4 DCC Chat buffer overflow
- ICQ's web based Guestbook CGI can crash the ICQ client
- Atsadc vulnerable to local root compromise
- Wmcdplay vulnerable to a local root compromise
- Pocsag allows remote access via a default password
- Simple HTML code can crash Internet Explorer (steelblue)
- StarScheduler (StarOffice) remote security vulnerabilities
- ClipArt Gallery exploit code released
- InfoSrch.cgi vulnerable to remote command execution
- Corel Linux 1.0 configuration error leads to root compromise
- AOL Instant Messenger DoS vulnerability
- TrendMicro OfficeScan contains numerous security holes (remote files modification)
- TrendMicro's InterScan can be remotely uninstalled
- ht://Dig information exposure
- Axis StorPoint CD authentication mechanism can be bypassed
|
| Feb / 2000 |
Exploits |
- DoS in Trendmicro OfficeScan
- man bug allows privileges elevation
- EZ Shopper 3.0 vulnerable to remote command execution
- NetGear ISDN RT34x router vulnerable to several DoS attacks
- Corel xconf allows gaining of local root
- Wordpad vulnerability allows executing of arbitrary commands
- Exploit code released for Firewall-1 FTP PASV security vulnerability
- Remotely exploitable buffer overflow in InterAccess's TelnetD
- GrabRtrConf - an automated script that downloads router configuration files
- Crashing IIS by creating a long filename in the \mailroot\pickup directory
- UltimateBB security hole discovered
- FireWall-1 stateful inspection vulnerability allows attacking of internal hosts
- Novell BorderManager 3.5 vulnerable to remote DoS attack
- MySQL password handling problem exploit code released
- CGI.pm and the untrusted-URL problem
- Many name servers are vulnerable to traffic amplification and NS route discovery
- Zeus Web server allows remote attacker to view source code of CGIs
- Remote access vulnerability in MySQL server
- Bypassing AXIS 700 Network Scanner's authentication scheme
- GroupWise Web Access servlet Denial of Service attack
- Hacking wwwthreads via SQL (Exploit code included)
- SHGetPathFromIDList() causes Windows programs to crash (DoS)
- Webspeed security vulnerability (WSISA vulnerability)
- "The Finger Server" security flaw allows remote code execution
- Majordomo vulnerable to local exploit (resend vulnerability)
- BIND NXT remote overflow exploit code has been released
- Security concerns when developing a dynamically generated web site
- Sybergen SyGate security hole (TCP 7323)
- Tiny FTPd allows execution of arbitrary code
- Outlook Express 5 allows remote e-mailers to retrieve local email messages
|
| Jan / 2000 |
Exploits |
- Checkpoint FireWall-1 Script Strip algorithm can be bypassed
- Breaking Cobalt's RaQ2 password CGI
- QPopper POP3 server remotely exploitable security vulnerability (LIST)
- BSD systems procfs vulnerability
- BNC IRC Proxy Server buffer overflow
- Vpopmail (qmail add-on) is vulnerable to remote root exploit (vpopmail, vchkpw)
- Exploit code for the ppptalk security vulnerability has been released
- Nortel Contivity package CGI vulnerability
- ZBServer Pro vulnerable to a remotely exploitable buffer overflow (GET)
- Cobalt RaQ web server vulnerability (patch available)
- Visual CASEL allows execution of unauthorized applications
- PowerScripts PlusMail password vulnerability (password change)
- Super Mail Transfer Package vulnerable to remote DoS
- Yet another Hotmail security hole - injecting JavaScript in IE using "@import url(javascript:...)"
- CuteFTP's password storage insecurity
- CuteFTP's password storage insecurity
- SolutionScripts.com Home Free CGI package vulnerability (search CGI)
- IMail IMonitor vulnerable to a remote DoS attack (CGI)
- UnixWare's pis utility can be used to gain root
- Solaris sadmind remote buffer overflow vulnerability
- QPopper vulnerable to a remotely exploitable buffer overflow (AUTH)
- Multiple DoS attack vulnerabilities in MDaemon Server
- Netscape FastTrack server remote exploit (long GET)
- IRIX sound player security vulnerability
- UnixWare rtpm exploit
|
| Dec / 1999 |
Exploits |
- CSM Mail Server vulnerable to a DoS attack (long HELO)
- RedHat's initscripts allows local users to execute arbitrary code as other users
- IBM NetStation/UnixWare local root exploit (HTTP interface)
- Savant Web Server is vulnerable to remote DoS attack (GET NULL)
- Sendmail vulnerable to ETRN DoS attack
- IMail's password encryption scheme
- Internet Explorer's cross-frame vulnerability (NavigateAndFind)
- Rover POP3 Server is vulnerable to a DoS attack (long USER)
- Remote buffer overflow in miniSQL (w3-msql)
- Netscape Navigator/Communicator 4.5 buffer overflow
- Multiple vulnerabilities in glFtpD
- Quake servers can be used to 'Smurf up' attacks
- RealMedia server vulnerable to remote DoS attack (ramgen)
- Wmmon under FreeBSD can be used to compromise kmem privileges
- Solaris 2.7 dmispd local/remote vulnerabilities
- UnixWare i2odialogd remote root exploit
- Linuxconf contains remotely exploitable buffer overflow
- Lotus Domino HTTP contains three security vulnerabilities (CGI and Denial-of-Service)
- Remote DoS in DNS PRO for WinNT
- FTP conversions on misconfigured systems (specifically wu-ftpd) posses a security threat
- GroupWise Web Interface 'HELP' hole
- Norton Email Protection Remote Buffer Overflow
- War FTP Daemon security vulnerability (60 connections & USER)
- SSH 1.2.27 Exploit code has been released
- FreeBSD 3.3 xsoldier root exploit
- Infoseek's Ultraseek for Windows NT is vulnerable to a remote buffer overflow
- VDO Live Player 3.02 contains an exploitable buffer overflow (vdo://)
- Several FTP Servers are vulnerable to multiple PORT commands DoS
- GoodTech Telnet Server NT vulnerable to a remote DoS
- UnixWare pkg* command exploits
- NT WinLogon VM contains plaintext password visible in admin mode
- UnixWare allows gaining of root with non-su/gid binaries
- UnixWare pkg vulnerability
- HP Secure Web Console is not so secure after all
- Phorum 3.0.x multiple vulnerabilities
- UnixWare core dumps follow symlinks
- CommuniGate Pro vulnerable to a remote DoS attack
- UnixWare 7 uidadmin vulnerable to an exploitable buffer overflow
- FreeBSD gated local exploit
- Solaris 'chkperm' & 'arp' security vulnerabilities
- Several FreeBSD-3.3 vulnerabilities have been found (seyon, xmindpath)
- UnixWare 7 gethostbyname() overflow
- FTP Serv-U vulnerable to a remotely exploitable buffer overflow (SITE)
|
| Nov / 1999 |
Exploits |
- MS SQL Server vulnerable to "Magic" packet attack
- Local users can cause Linux kernel to panic (syslogd)
- Oracle Database Server root exploit code has been released
- IrFan image viewer 3.07 vulnerable to a buffer overflow
- RealNetworks RealServer G2 username/password buffer overflow
- BisonWare FTP Server 3.5 contains several vulnerabilities
- Solaris7 dtmail/dtmailpr/mailtool exploitable buffer overflow
- MDaemon Server is vulnerable to multi-connection security vulnerability
- Solaris7 'kcms_configure' vulnerable to an exploitable buffer overflow (NETPATH)
- Mail-Gear 1.0 web interface is vulnerable to Directory Traversal
- UnixWare 7's xlock vulnerable to an exploitable buffer overflow
- UnixWare 7's su vulnerable to an exploitable buffer overflow
- UnixWare 7's Xsco vulnerable to an exploitable buffer overflow
- Denial of Service Vulnerability in Cabletron's SmartSwitch Router (SSR)
- An improved Wu-FTPD exploit code has been released (WUFTPD)
- Remote DoS attack in Vermillion FTP Daemon (VFTPD)
- Tektronix PhaserLink Webserver gives out the administrator password
- HP JetDirect web server vulnerable to long URL attack
- ZetaMail POP3/SMTP server vulnerable to a remote DoS attack
- W4 Server CGI remote buffer overflow
- E-MailClub 'FROM' remote buffer overflow
- WebBBS login & password Buffer Overflow Vulnerability
- Remote DoS Attack against G6 FTP Server v2.0 (beta 4/5)
- DeleGate vulnerable to a remotely exploitable buffer overflow
- Network Solutions encrypted 'NIC update' password can be easily recovered
- TransSoft's Broker Ftp Server vulnerable to a remote DoS attack
- FreeBSD 3.3 'seyon' utility vulnerability
- FormHandler CGI template vulnerability
- WU-FTP 2.4.x leaks user information
- NFS Server MAX_PATH exploit code has been released
- Remote DoS attack on QVT/Term
- Artisoft XtraMail vulnerable to DoS attacks
- FTGate Version 2.1 and Eserv 2.5 vulnerable to Directory Traversal
- BIG/ip 'view_textfile' and 'default user' security vulnerabilities
- StackGuard security vulnerability fixed
- Interscan VirusWall NT 3.23/3.3 buffer overflow
- KVIrc client vulnerable to local file browsing
- IPSwitch IMAIL POP3 vulnerable to a remotely exploitable buffer overflow (USER)
- Guestbook.pl and SSI don't mix
- BFTelnet Server ver 1.1 vulnerable to remote DoS
- Alibaba Web Server vulnerable once again to a remote buffer overflow
- Bash 1.x command substitution vulnerability
- WFTPd 'MKD' exploit code released
- Cisco Routers' NAT support exposes the router for DoS attacks
- Xitami web server vulnerable to remote DoS via the administrative port
- MacOS Programmer's Window Vulnerability
- Alibaba Web Server vulnerable to remote command execution
- Sendmail 8.9.x vulnerable to SIGKILL alias file killing
- Windows NT remote denial of service (RFPoison)
- Amanda backup local root compromises
- Multiple vulnerabilities in UNIX & Windows 9x/NT applications
- Avirt Mail Server 3.x is vulnerable to a remote buffer overflow attack
- Palm HotSync Manager is vulnerable to Denial of Service attack
- Express FS 2.x FTP Server is vulnerable to a remote buffer overflow
|
| Oct / 1999 |
Exploits |
- Axent Raptor Firewall 'IP Options' DoS code released
- Netscape Messaging Server vulnerable to "RCPT TO" DoS
- IRCd vulnerable to oversize PTR record DoS
- FreeBSD vfs_cache vulnerable to a Denial-of-Service attack
- Netscape 4.7 and earlier vulnerable to "Huge Key" DoS
- OmniHTTPD Buffer Overflow Vulnerability
- Squid Web Proxy Authentication Failure Vulnerability
- Linux cwdtools Vulnerabilities
- WebSphere's Key Database password protection have been cracked
- OpenLink 3.2 vulnerable to a remote buffer overflow
- Netscape 4.5 and above are vulnerable to 'Dynamic Font' DoS
- 'xmonisdn' allows reading of any local files under RedHat 6.x
- Remote Denial-of-Service in Axent's Raptor Firewall 6.0
- FTP Serv-U Ver2.5 exploit code have been released
- NashuaTec D445 suffers from a number of security holes
- Detailed exploit code has been released for the "IFRAME ExecCommand" vulnerability
- Netscape browser is vulnerable to < and > character replacement
- Xerox DocuColor 4 LP is vulnerable to a DoS
- SCO OpenServer 5.0.5 'cancel' buffer overflow
- A bug in IRCd 2.10.x (qident) can be used for a Denial of Service attack
- EFNet IRCd allows shell access to the IRC server
- SCO Openserver XBase exploit code
- SCO OpenServer 5.0.5 'userOsa' scripts allow overwriting of the shadow file
- Novell Client 3.0 vulnerable to Denial of Service attack
- Remote buffer overflow in ftpd on AIX 4.3.x
- Hybrid Network's Cable Modems Security vulnerability
- Solaris 2.7 /usr/bin/mail exploit code released
- Patch Available for the Undocumented CFML Tags vulnerability
- RedHat 6.0 RPMMail security vulnerability
- iHTML Merchant security vulnerabilities
- Yahoo! Messenger remote Denial of Service
- SCO UnixWare 7.1 /usr/lib/merge/dos7utils local root exploit
- Linux cdda2cdr local exploit
- Sambar Web Server 4.2.1 vulnerable to a Denial of Service attack
- TeamTrack web server vulnerability
- Buffer Overflow problems in ActiveX controls
|
| Sep / 1999 |
Exploits |
- Arkiea Backup HOME Environment Variable Vulnerability
- SuSE sscw Environment Variable Buffer Overflow Vulnerability
- CFingerD GECOS Buffer overflow vulnerability
- SCO 5.0.x Xt lib exploit code is available
- Exploit code and Patch released for 'dtaction' vulnerability on Digital UNIX
- SuSE 6.2 '/usr/bin/sccw' allows reading of any local file
- WWWBoard passwords vulnerability
- SSH 1.2.27 vulnerable to a Denial of Service attack
- Patch released for the new ProFTPd 1.2.0pre6 vulnerability
- Exploit code for the 'xterm' vulnerability has been released
- Exploit code for the 'XSco' vulnerability has been released
- Exploit code for the 'xlock' vulnerability has been released
- Exploit code for the patched 'SCOterm' has been released
- Exploit code for the SCOterm vulnerability has been released
- Exploit code released for the 'SCOlock' SCO Server vulnerability
- Exploit code released for the 'deliver' SCO Server vulnerability
- Exploit code for the AMD vulnerability has been released
- Another shared memory exploit script has been released (ShareDream)
- Sega's Dreamcast Web Browser Email Security Issue
- Vulnerability in Internet Explore 4/5 causes browser to crash
- New ProFTPd exploit code released (for version 1.2.0pre1,2,3)
- SCO 5.0.5 lpr local root exploit code released
- SunOS 4.1.1, 4.1.3 and 4.1.4 tmpfs Denial-of-Service
- Two new vulnerabilities in TenFour TFS SMTP 3.2
- IDs can be easily spoofed in Bluestone Sapphire/Web
- Netscape releases Netscape Enterprise Server 3.6sp2 patch
- An exploitable Heap Overflow in Windows 95/98 Telnet.exe
- Sun releases patches for LC_MESSAGES vulnerability
- SCO 5.0.5 doctor program allows local users to read /etc/shadow
- Windows 2000 COM handler allows attackers to start the Telnet service remotely
- Mars Netware Emulator contains buffer overflows
- Netscape Communicator EMBED tag vulnerability
- Two new exploit scripts released for Vixie CronD vulnerability
- TFS Gateway 4.0 vulnerable to a Denial of Service attack
|
| Aug / 1999 |
Exploits |
- Lotus Notes Domino Server 4.6 vulnerable to Denial of Service Attack
- Lotus Notes vulnerable to a Denial of Service attack
- Patch released for Sun's 'rpc.cmsd' buffer overflow vulnerability
- IE 5.0 HTML Applications exploit code released
- WindowMaker buffer overflow vulnerabilities
- CiscoSecure Access Control Server allows unauthorized access
- QMS-2060 network printer contains a security hole
- XServer logon encryption can be easily decrypted
- Vulnerability in W3-msql cgi script
- New version of isdnutils fixes exploitable xmonisdn
- Dragon-Fire IDS Vulnerability
- WebTrends ERServer is vulnerable to a Denial of Service attack
- Exploit code for a bug in ircd2.10.x's qident has been released
- ALMail32 Buffer overflow vulnerability
- CheckPoint Firewall-1 is vulnerable to 'Port 0' Denial of Service attack
- 3Com's HiPer ARC vulnerable to a Denial of Service attack
- Cfingerd 1.3.2 and earlier is vulnerable to a root exploit
- Exploit code for the scosession vulnerability is available
- miniSQL w3-auth() buffer overflow
- Vulnerabilities in BO2K encryption Plugins
- Netscape Communicator 4.6 vulnerable to 'mailto:' Denial of Service
- Netware 5 client can be hijacked
- Insecurity in Apache installation as shipped on Debian 2.1 and Boa
|
| Jul / 1999 |
Exploits |
- Java Hotspot Performance Engine vulnerable to attack
- mSQL multiple buffer overflows
- InterMute privacy enhancer exposes information to other users
- WS FTP Pro's weak password encryption algorithm
- Very long filenames can crash NT (updated)
- AMaViS virus scanner for Linux can be used to gain root
- IRC Networks can be easily crashed
- Patrol's SNMP Agent 3.2 can lead to root compromise
- AIX 4.2.X & 4.3.X can easily halted
- Pine remote exploit source code released
- HPUnix CDE installation leaves current directory in root PATH
- SDR vulnerable to attack
- VMware v1.0.1 exploit code released
- Netscape Communicator JavaScript crash
- Another Cold Fusion Server vulnerability
- 'Super' is susceptible to buffer overflow attack
- DosEMU buffer overflow assists in gaining root
- How to break IoMega's Zip Drive read/write password protection
- Patch Available for the "Unprotected IOCTLs" Vulnerability
- Moyari - a new Windows 95/98 Denial of Service attack
- Cognos PowerPlay Web Edition allows users to gain access to sensitive information
- klock Screen Saver can be bypassed
- CFingerD 1.3.2 is vulnerable to a remote buffer overflow
- Exploit code for Xi Graphics Accelerated X Server
|
| Jun / 1999 |
Exploits |
- Cabletron Spectrum root-shell vulnerability
- Xi Graphics Accelerated X Server 4.x, 5.x vulnerable to buffer overflows
- IIS Remote Exploit injection code released
- Cisco IOS Software keyword parsing vulnerability
- KDE K-Mail File Creation Vulnerability
- TCPDump is vulnerable to Denial of Service attack
- Netware web server Denial of Service
- Vulnerability in 'statd' exposes vulnerability in automountd
- How to hack, flood, spoof, nuke and sniff ICQ
- Denial of Service attack against Windows NT PDC
- Weaknesses in DNS label decoding can cause a Denial of Service
- A new buffer overflows in smbvalid library
- RedHat 6.0 /dev/pts permissions bug can disrupt xterm sessions
- whois_raw cgi security vulnerability
- A remote exploit code for the POP2 daemon vulnerability
- CGI can cause MacOS X system panic
- Solaris sdtcm_convert program allows root access
- Broker FTP Server 3.0 is vulnerable to 'directory traveling'
- Netscape Communicator 4.6 JavaScript <TITLE> vulnerability
- IRIX MIDIKeys allows guest users root access
- Remote vulnerability in POP2 Daemon
|
| May / 1999 |
Exploits |
- Buffer overflow in SmartDesk WebSuite v2.1
- Multiple Web Interface security holes
- Compaq Insight Manager exposes sensitive information
- Solaris LIBC exploit code
- Netfinity Remote Control software's security vulnerability
- Netscape Communicator's <TITLE> vulnerability
- WinAMP 2.x vulnerable to a buffer overflow
- HP's Trusted Gateway Agent is vulnerable to a Denial of Service attack
- INN server is vulnerable to a buffer overflow attack
- Netscape Navigator and Internet Explorer are vulnerable to Bookmark vulnerability
- Novell NetWare TTS is vulnerable to a Denial of Service attack
- Solaris 'lpset' buffer overflow can compromise the system
- Security problem with sockets in FreeBSD
- Solaris 'dtprintinfo' program contains a root exploit
- FTP Serv-U daemon is vulnerable to a buffer overflow
- Alibaba Web Server is vulnerable to path climbing
- Multiple file system vulnerabilities in Oracle 8
- An improved wu-ftpd exploit code released
- Patch Available for the "DHTML Edit" Vulnerability
- Exceed X Server versions 5.0 and 6.0 are vulnerable to a Denial of Service attack
- CSM Mail is vulnerable to Remote Buffer Overflow
- 'Discus' discussion group server permission hole
|
| Apr / 1999 |
Exploits |
- Cold Fusion Server vulnerability scanner
- Bash 1.14.x vulnerable to 'exit code' parsing
- FFingerD vulnerable to privacy hole
- IPFilter file lock hazard
- Cisco routers vulnerable to information leakage
- Internet Explorer 5.0 '%01 security bug' found (new)
- NetBSD Kernel hangs in name lookup
- Another ICQ99 Web Sever security flaw
- Patrol 3.25 security weakness found
- Webcom's Guestbook CGI vulnerability
- Network Appliance NetCache 3.3.1 vulnerable to SNMP 'public' community
- Multiple WinGate Vulnerabilities
- SiteServer 3.0 DirectMail saves username and password in clear text
- Xylan OmniSwitch login can be easily bypassed
- Several X windows vulnerabilities allow users to change permission of system files
- ICQ99 Web Server vulnerable to Denial of Service
- WebRamp Denial of Service Attacks
|
| Mar / 1999 |
Exploits |
- Wide spread infections of the 'Melissa' Macro Virus
- SuSE X11 directory permission overrun
- FTP Servers exploit
- NetBSD security vulnerability in umapfs
- NetBSD 'noexec' mount flag is not properly handled by non-root mount
- Netscape Communicator's talkback enhancement vulnerability
- Microsoft Exchange buffer overflow attack (patch available)
- AOL Server 2.2 password vulnerability
- Linux Blind TCP Spoofing demonstration code released
- WinFreeze, a Denial of Service attack against Windows
- Windows NT Screen Saver vulnerability (a patch is available)
- Windows NT Screen Saver vulnerability (a patch is available)
- Netscape communicator found() vulnerability
- XCMail remote vulnerability
- War FTP Deamon 1.70 beta1 saves passwords in 'clear' text.
- Gnuplot 3.5 can be compromised to gain root
- Oracle installation stores admin password in log file
- Vulnerabilities found in IMail
|
| Feb / 1999 |
Exploits |
- AltaVista Firewall '97 is vulnerable to a DNS attack
- InterScan VirusWall can be bypassed (patch is available)
- A new Cuartango exploit
- Netscape Communicator Window Spoofing
- Macintosh version of Word '98 includes sensitive material in document files.
- Another ICQ 98a bug
- BackOffice installation exposes passwords
- PadLock-IT 1.01 bad password saving scheme
- IIS Remote FTP Denial of Service attack
- IIS 4.0 vulnerable to ExAir sample site Denial of Service
- Multiple vulnerabilities in ControlIT
- MiRC DCC Security hole
- IIS and Perl may be used to reveal true directory location
- Vulnerabilities found in Swish search engine
- WS_FTP Server Remote Denial of Service attack
- OShare, a new Windows Denial of Service attack
- RPCBind security vulnerability
|
| Jan / 1999 |
Exploits |
- Quake II Server buffer overflow
- Linux 2.0.35/36 vulnerable to local port Denial of Service attack
- FoolProof found to be full of security glitches.
- Forms 2.0 (Fm20*.dll) ActiveX Control Security Fix
- Windows 95/98 FrontPage extension security vulnerability
- Solaris 2.5.1 and 2.6 vulnerable to ff.core exploit
- HTTP REQUEST_METHOD security flaw
- IIS 4.0 is vulnerable when upgraded from earlier versions
- Sendmail 8.9/8.8 vulnerable to two new attacks
- CGIc Library is vulnerable to a buffer overflow attack
- DPEC's Online Courseware vulnerable to attack
- Solaris AutoMountD vulnerable to a remote exploit
- Linux's urandom Denial of Service
- Solaris 2.7 allows finger bouncing
- Iomega's poor Jazz drive backup encryption
- Yahoo Pager vulnerable to Denial of Service attack
- ICQ 98a security flaw
- WFTPd vulnerable to a remotely exploitable buffer overflow
- SCO's CalServer vulnerable to a buffer overflow
- L0phtCrack 2.5 misplaces temporary password files
- suGuard 1.0 assists in gaining root access
- Tripwire buffer overflow
|
| Dec / 1998 |
Exploits |
- KCMS Configure tool vulnerable to buffer overflow
- The LP daemon is susceptible to Denial of Service attacks.
- Linux Pluggable Authentication Modules (PAM) insecurity.
- IRIX tape device insecurity.
- Cookie Monster vulnerability
- Microsoft Explorer bug fixed.
- MSProxy 2.0 can be used to attack hosts on internal network
- Solaris DTmail vulnerable to buffer overflow attack.
- MacOS 8.5.1's Web Sharing Denial of Service attack.
- RealSystem G2 Server saves password in clear text.
- Microsoft's Network Monitor susceptible to Denial of Service attack.
- Bootp Daemon remote vulnerability.
- AutoFSD was found to be vulnerable to a remote exploit.
- EWS (Excite for Web Servers) 1.1 security compromises.
- Netscape browser bug allows reading of local files.
- Exceed 6.0.1.0 saves usernames and passwords in the clear.
- MkCookie program fault allow root compromise.
- Platinum PCM 7.0 Denial of Service.
|
| Nov / 1998 |
Exploits |
- IPFW's logs can be made ineffective.
- IRIX's gr_osview race condition.
- SunOS's rdist program may assist in gaining root.
- Windows NT's SNMP service vulnerability.
- AIX's infod may assist in gaining root remotely.
- NetBSD's character device drivers enable direct access to memory and disks.
- Samba 1.9.18 security vulnerabilities.
- Multiple KDE security vulnerabilities.
- WinGate Denial of Service
- NFTP's string handling vulnerability.
- CA's Archserve Exchange DB Agent saves passwords in the clear.
- RPC's portmapper pmap_(un)set insecurities.
- BootP 2.4.3 daemon was found to be vulnerable to a race condition.
- XFree86 3.3.2' setup tool race condition.
- CatDOC 0.90 buffer overflows.
- Internet Explorer 4.x's Custom settings don't work.
- ICQ 98 beta sends out sensitive information.
- mSQL Denial of Service.
- Cisco 7xxx routers IP Datagrams mishaps.
- KLogd may assist malicious users in gaining root.
- Internet Explorer 4.x "width= height=" bug.
- Internet Explorer's DirectDraw support can cause a complete crash.
- Solstice Enterprise Agent SNMP vulnerability.
- CDE's dtappgather assists in gaining root.
- Netscape browser saves forms and emails in the clear.
- Netscape Communicator preference file found to be wide open.
- APC SmartUPS 2200 vulnerable to DoS.
- A GNU Text Utility (head) could cause Slackware to panic.
- RedHat 5.2's XWindows vulnerable to Cookie Hijacking.
- A possible buffer overflow in xlock.
|
| Oct / 1998 |
Exploits |
- Lynx 2.8.x (including the latest development version) overflow.
- USR Netserver 8/16 vulnerable to nestea attacks.
- Solaris License Manager's lock files exploits.
- FreeBSD 3.0-Release vulnerable to nestea v2.
- Sendmail (till the latest version) Denial of Service.
- HP Unix doesn't log failed 'su' commands.
- Netscape Communicator 4.07 Javascript mishaps.
- Netscape Communicator 4.5P2 (UNIX) doesn't disable JavaScript.
- Mutt Mail user agent vulnerability.
- Netscape MIME Type buffer overflow.
- OSPF monitor may assist in gaining root.
- Internet Explorer 4.0 Security Zone compromise.
- RouteD "file create" exploit.
- Solaris /dev/rmt/* permission problem.
- Novell Netware 4.11 and 5.0 vulnerable to echo/chargen attack.
- Another Cuartango Security Hole (an Internet Explorer hole).
- Midnight Commander 4.5.xx file overrun.
- FreeBSD 2.2.x (before 2.2.8R) can be attacked by a RST Denial of Service.
- Netscape 4.x vulnerable to "internal/parser".
- Cuartango Security Hole (an Internet Explorer hole).
- AOL 4.0 Email crash.
- A Digital Unix 4.0D bug in cdfs found (xcd related).
|