Security News
-
Security Reviews
-
Exploits
-
Tools
-
UNIX Focus
-
Windows Focus
Ask the Team
Mailing Lists
Advertising Info
Advisories
About SecuriTeam
Blogs
Brought to you by:
Suppliers of:
Website Testing Tools
Network Testing Tools
Software Testing Tools
SecuriTeam in Your Inbox
New vulnerability?
New tool?
Tell us
(Our
PGP key
).
Exploits Archive 1999
Select Year:
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
December
1999
IRIX sound player security vulnerability
Netscape FastTrack server remote exploit (long GET)
UnixWare rtpm exploit
Savant Web Server is vulnerable to remote DoS attack (GET NULL)
UnixWare's pis utility can be used to gain root
IBM NetStation/UnixWare local root exploit (HTTP interface)
RedHat's initscripts allows local users to execute arbitrary code as other users
CSM Mail Server vulnerable to a DoS attack (long HELO)
Remote buffer overflow in miniSQL (w3-msql)
Rover POP3 Server is vulnerable to a DoS attack (long USER)
Sendmail vulnerable to ETRN DoS attack
Multiple vulnerabilities in glFtpD
Netscape Navigator/Communicator 4.5 buffer overflow
Quake servers can be used to 'Smurf up' attacks
Lotus Domino HTTP contains three security vulnerabilities (CGI and Denial-of-Service)
IMail's password encryption scheme
Linuxconf contains remotely exploitable buffer overflow
UnixWare i2odialogd remote root exploit
Solaris 2.7 dmispd local/remote vulnerabilities
Wmmon under FreeBSD can be used to compromise kmem privileges
RealMedia server vulnerable to remote DoS attack (ramgen)
Internet Explorer's cross-frame vulnerability (NavigateAndFind)
FTP conversions on misconfigured systems (specifically wu-ftpd) posses a security threat
Remote DoS in DNS PRO for WinNT
Norton Email Protection Remote Buffer Overflow
GroupWise Web Interface 'HELP' hole
Infoseek's Ultraseek for Windows NT is vulnerable to a remote buffer overflow
FreeBSD 3.3 xsoldier root exploit
SSH 1.2.27 Exploit code has been released
VDO Live Player 3.02 contains an exploitable buffer overflow (vdo://)
War FTP Daemon security vulnerability (60 connections & USER)
Solaris sadmind remote buffer overflow vulnerability
Several FTP Servers are vulnerable to multiple PORT commands DoS
NT WinLogon VM contains plaintext password visible in admin mode
UnixWare pkg* command exploits
GoodTech Telnet Server NT vulnerable to a remote DoS
UnixWare pkg vulnerability
CommuniGate Pro vulnerable to a remote DoS attack
UnixWare core dumps follow symlinks
HP Secure Web Console is not so secure after all
Solaris 'chkperm' & 'arp' security vulnerabilities
FreeBSD gated local exploit
UnixWare 7 uidadmin vulnerable to an exploitable buffer overflow
FTP Serv-U vulnerable to a remotely exploitable buffer overflow (SITE)
UnixWare 7 gethostbyname() overflow
Several FreeBSD-3.3 vulnerabilities have been found (seyon, xmindpath)
November
1999
Mail-Gear 1.0 web interface is vulnerable to Directory Traversal
Solaris7 'kcms_configure' vulnerable to an exploitable buffer overflow (NETPATH)
MDaemon Server is vulnerable to multi-connection security vulnerability
Solaris7 dtmail/dtmailpr/mailtool exploitable buffer overflow
QPopper vulnerable to a remotely exploitable buffer overflow (AUTH)
MS SQL Server vulnerable to "Magic" packet attack
UnixWare 7's Xsco vulnerable to an exploitable buffer overflow
UnixWare 7's su vulnerable to an exploitable buffer overflow
UnixWare 7's xlock vulnerable to an exploitable buffer overflow
Denial of Service Vulnerability in Cabletron's SmartSwitch Router (SSR)
Multiple DoS attack vulnerabilities in MDaemon Server
Remote DoS attack in Vermillion FTP Daemon (VFTPD)
An improved Wu-FTPD exploit code has been released (WUFTPD)
HP JetDirect web server vulnerable to long URL attack
Local users can cause Linux kernel to panic (syslogd)
Tektronix PhaserLink Webserver gives out the administrator password
ZetaMail POP3/SMTP server vulnerable to a remote DoS attack
Remote DoS Attack against G6 FTP Server v2.0 (beta 4/5)
WebBBS login & password Buffer Overflow Vulnerability
E-MailClub 'FROM' remote buffer overflow
W4 Server CGI remote buffer overflow
DeleGate vulnerable to a remotely exploitable buffer overflow
Oracle Database Server root exploit code has been released
NFS Server MAX_PATH exploit code has been released
WU-FTP 2.4.x leaks user information
FormHandler CGI template vulnerability
FreeBSD 3.3 'seyon' utility vulnerability
TransSoft's Broker Ftp Server vulnerable to a remote DoS attack
Network Solutions encrypted 'NIC update' password can be easily recovered
IrFan image viewer 3.07 vulnerable to a buffer overflow
Artisoft XtraMail vulnerable to DoS attacks
Remote DoS attack on QVT/Term
StackGuard security vulnerability fixed
BIG/ip 'view_textfile' and 'default user' security vulnerabilities
Interscan VirusWall NT 3.23/3.3 buffer overflow
IPSwitch IMAIL POP3 vulnerable to a remotely exploitable buffer overflow (USER)
Guestbook.pl and SSI don't mix
Alibaba Web Server vulnerable once again to a remote buffer overflow
FTGate Version 2.1 and Eserv 2.5 vulnerable to Directory Traversal
Cisco Routers' NAT support exposes the router for DoS attacks
WFTPd 'MKD' exploit code released
Bash 1.x command substitution vulnerability
Xitami web server vulnerable to remote DoS via the administrative port
RealNetworks RealServer G2 username/password buffer overflow
Sendmail 8.9.x vulnerable to SIGKILL alias file killing
MacOS Programmer's Window Vulnerability
BFTelnet Server ver 1.1 vulnerable to remote DoS
Alibaba Web Server vulnerable to remote command execution
Avirt Mail Server 3.x is vulnerable to a remote buffer overflow attack
Multiple vulnerabilities in UNIX & Windows 9x/NT applications
Amanda backup local root compromises
Windows NT remote denial of service (RFPoison)
October
1999
IRCd vulnerable to oversize PTR record DoS
Netscape Messaging Server vulnerable to "RCPT TO" DoS
WFTPd vulnerable to a remotely exploitable buffer overflow
Axent Raptor Firewall 'IP Options' DoS code released
Express FS 2.x FTP Server is vulnerable to a remote buffer overflow
Palm HotSync Manager is vulnerable to Denial of Service attack
Netscape 4.7 and earlier vulnerable to "Huge Key" DoS
Linux cwdtools Vulnerabilities
Squid Web Proxy Authentication Failure Vulnerability
OmniHTTPD Buffer Overflow Vulnerability
WebSphere's Key Database password protection have been cracked
Remote Denial-of-Service in Axent's Raptor Firewall 6.0
'xmonisdn' allows reading of any local files under RedHat 6.x
Netscape 4.5 and above are vulnerable to 'Dynamic Font' DoS
OpenLink 3.2 vulnerable to a remote buffer overflow
Detailed exploit code has been released for the "IFRAME ExecCommand" vulnerability
NashuaTec D445 suffers from a number of security holes
Xerox DocuColor 4 LP is vulnerable to a DoS
Netscape browser is vulnerable to < and > character replacement
SCO OpenServer 5.0.5 'cancel' buffer overflow
SCO OpenServer 5.0.5 'userOsa' scripts allow overwriting of the shadow file
Novell Client 3.0 vulnerable to Denial of Service attack
SCO UnixWare 7.1 /usr/lib/merge/dos7utils local root exploit
Yahoo! Messenger remote Denial of Service
iHTML Merchant security vulnerabilities
RedHat 6.0 RPMMail security vulnerability
Patch Available for the Undocumented CFML Tags vulnerability
Solaris 2.7 /usr/bin/mail exploit code released
Hybrid Network's Cable Modems Security vulnerability
Remote buffer overflow in ftpd on AIX 4.3.x
KVIrc client vulnerable to local file browsing
TeamTrack web server vulnerability
Sambar Web Server 4.2.1 vulnerable to a Denial of Service attack
Buffer Overflow problems in ActiveX controls
September
1999
Arkiea Backup HOME Environment Variable Vulnerability
SuSE sscw Environment Variable Buffer Overflow Vulnerability
SCO 5.0.x Xt lib exploit code is available
CFingerD GECOS Buffer overflow vulnerability
FreeBSD vfs_cache vulnerable to a Denial-of-Service attack
Exploit code and Patch released for 'dtaction' vulnerability on Digital UNIX
Patch released for the new ProFTPd 1.2.0pre6 vulnerability
SSH 1.2.27 vulnerable to a Denial of Service attack
WWWBoard passwords vulnerability
SuSE 6.2 '/usr/bin/sccw' allows reading of any local file
Exploit code for the AMD vulnerability has been released
Exploit code released for the 'deliver' SCO Server vulnerability
Exploit code released for the 'SCOlock' SCO Server vulnerability
Exploit code for the SCOterm vulnerability has been released
Exploit code for the patched 'SCOterm' has been released
Exploit code for the 'xlock' vulnerability has been released
Exploit code for the 'XSco' vulnerability has been released
Exploit code for the 'xterm' vulnerability has been released
SCO 5.0.5 lpr local root exploit code released
New ProFTPd exploit code released (for version 1.2.0pre1,2,3)
Vulnerability in Internet Explore 4/5 causes browser to crash
Sega's Dreamcast Web Browser Email Security Issue
Another shared memory exploit script has been released (ShareDream)
Two new vulnerabilities in TenFour TFS SMTP 3.2
SunOS 4.1.1, 4.1.3 and 4.1.4 tmpfs Denial-of-Service
Sun releases patches for LC_MESSAGES vulnerability
Netscape releases Netscape Enterprise Server 3.6sp2 patch
IDs can be easily spoofed in Bluestone Sapphire/Web
FTP Serv-U Ver2.5 exploit code have been released
Windows 2000 COM handler allows attackers to start the Telnet service remotely
SCO 5.0.5 doctor program allows local users to read /etc/shadow
Mars Netware Emulator contains buffer overflows
Netscape Communicator EMBED tag vulnerability
Two new exploit scripts released for Vixie CronD vulnerability
TFS Gateway 4.0 vulnerable to a Denial of Service attack
August
1999
Lotus Notes vulnerable to a Denial of Service attack
Patch released for Sun's 'rpc.cmsd' buffer overflow vulnerability
Phorum 3.0.x multiple vulnerabilities
IE 5.0 HTML Applications exploit code released
Lotus Notes Domino Server 4.6 vulnerable to Denial of Service Attack
CiscoSecure Access Control Server allows unauthorized access
WindowMaker buffer overflow vulnerabilities
QMS-2060 network printer contains a security hole
XServer logon encryption can be easily decrypted
New version of isdnutils fixes exploitable xmonisdn
An exploitable Heap Overflow in Windows 95/98 Telnet.exe
Dragon-Fire IDS Vulnerability
Vulnerability in W3-msql cgi script
ALMail32 Buffer overflow vulnerability
Exploit code for a bug in ircd2.10.x's qident has been released
WebTrends ERServer is vulnerable to a Denial of Service attack
3Com's HiPer ARC vulnerable to a Denial of Service attack
CheckPoint Firewall-1 is vulnerable to 'Port 0' Denial of Service attack
EFNet IRCd allows shell access to the IRC server
A bug in IRCd 2.10.x (qident) can be used for a Denial of Service attack
Cfingerd 1.3.2 and earlier is vulnerable to a root exploit
Vulnerabilities in BO2K encryption Plugins
Netware 5 client can be hijacked
July
1999
InterMute privacy enhancer exposes information to other users
WS FTP Pro's weak password encryption algorithm
Java Hotspot Performance Engine vulnerable to attack
AMaViS virus scanner for Linux can be used to gain root
AIX 4.2.X & 4.3.X can easily halted
Patrol's SNMP Agent 3.2 can lead to root compromise
IRC Networks can be easily crashed
SDR vulnerable to attack
HPUnix CDE installation leaves current directory in root PATH
Pine remote exploit source code released
miniSQL w3-auth() buffer overflow
Exploit code for the scosession vulnerability is available
VMware v1.0.1 exploit code released
Cognos PowerPlay Web Edition allows users to gain access to sensitive information
Netscape Communicator 4.6 vulnerable to 'mailto:' Denial of Service
Moyari - a new Windows 95/98 Denial of Service attack
Patch Available for the "Unprotected IOCTLs" Vulnerability
klock Screen Saver can be bypassed
CFingerD 1.3.2 is vulnerable to a remote buffer overflow
Exploit code for Xi Graphics Accelerated X Server
June
1999
Xi Graphics Accelerated X Server 4.x, 5.x vulnerable to buffer overflows
Cabletron Spectrum root-shell vulnerability
SCO Openserver XBase exploit code
Netscape Communicator JavaScript crash
KDE K-Mail File Creation Vulnerability
Cisco IOS Software keyword parsing vulnerability
IIS Remote Exploit injection code released
TCPDump is vulnerable to Denial of Service attack
Netware web server Denial of Service
How to hack, flood, spoof, nuke and sniff ICQ
Vulnerability in 'statd' exposes vulnerability in automountd
Denial of Service attack against Windows NT PDC
Weaknesses in DNS label decoding can cause a Denial of Service
RedHat 6.0 /dev/pts permissions bug can disrupt xterm sessions
A new buffer overflows in smbvalid library
CGI can cause MacOS X system panic
whois_raw cgi security vulnerability
A remote exploit code for the POP2 daemon vulnerability
Broker FTP Server 3.0 is vulnerable to 'directory traveling'
Solaris sdtcm_convert program allows root access
May
1999
Remote vulnerability in POP2 Daemon
IRIX MIDIKeys allows guest users root access
Netscape Communicator 4.6 JavaScript <TITLE> vulnerability
Compaq Insight Manager exposes sensitive information
Multiple Web Interface security holes
Buffer overflow in SmartDesk WebSuite v2.1
Solaris LIBC exploit code
Netfinity Remote Control software's security vulnerability
Netscape Communicator's <TITLE> vulnerability
BisonWare FTP Server 3.5 contains several vulnerabilities
WinAMP 2.x vulnerable to a buffer overflow
Netscape Navigator and Internet Explorer are vulnerable to Bookmark vulnerability
INN server is vulnerable to a buffer overflow attack
HP's Trusted Gateway Agent is vulnerable to a Denial of Service attack
Novell NetWare TTS is vulnerable to a Denial of Service attack
Solaris 'lpset' buffer overflow can compromise the system
UnixWare allows gaining of root with non-su/gid binaries
Solaris 'dtprintinfo' program contains a root exploit
Linux cdda2cdr local exploit
Multiple file system vulnerabilities in Oracle 8
Security problem with sockets in FreeBSD
Alibaba Web Server is vulnerable to path climbing
FTP Serv-U daemon is vulnerable to a buffer overflow
Patch Available for the "DHTML Edit" Vulnerability
An improved wu-ftpd exploit code released
'Discus' discussion group server permission hole
Exceed X Server versions 5.0 and 6.0 are vulnerable to a Denial of Service attack
CSM Mail is vulnerable to Remote Buffer Overflow
Very long filenames can crash NT (updated)
April
1999
Cold Fusion Server vulnerability scanner
Another Cold Fusion Server vulnerability
FFingerD vulnerable to privacy hole
Bash 1.14.x vulnerable to 'exit code' parsing
Cisco routers vulnerable to information leakage
IPFilter file lock hazard
Internet Explorer 5.0 '%01 security bug' found (new)
NetBSD Kernel hangs in name lookup
Webcom's Guestbook CGI vulnerability
Another ICQ99 Web Sever security flaw
Patrol 3.25 security weakness found
Insecurity in Apache installation as shipped on Debian 2.1 and Boa
Network Appliance NetCache 3.3.1 vulnerable to SNMP 'public' community
Multiple WinGate Vulnerabilities
Several X windows vulnerabilities allow users to change permission of system files
Xylan OmniSwitch login can be easily bypassed
SiteServer 3.0 DirectMail saves username and password in clear text
WebRamp Denial of Service Attacks
ICQ99 Web Server vulnerable to Denial of Service
March
1999
SuSE X11 directory permission overrun
Wide spread infections of the 'Melissa' Macro Virus
FTP Servers exploit
Netscape Communicator's talkback enhancement vulnerability
NetBSD 'noexec' mount flag is not properly handled by non-root mount
NetBSD security vulnerability in umapfs
AOL Server 2.2 password vulnerability
Microsoft Exchange buffer overflow attack (patch available)
Linux Blind TCP Spoofing demonstration code released
WinFreeze, a Denial of Service attack against Windows
Windows NT Screen Saver vulnerability (a patch is available)
Windows NT Screen Saver vulnerability (a patch is available)
War FTP Deamon 1.70 beta1 saves passwords in 'clear' text.
Netscape communicator found() vulnerability
XCMail remote vulnerability
Gnuplot 3.5 can be compromised to gain root
Oracle installation stores admin password in log file
Vulnerabilities found in IMail
February
1999
AltaVista Firewall '97 is vulnerable to a DNS attack
InterScan VirusWall can be bypassed (patch is available)
A new Cuartango exploit
'Super' is susceptible to buffer overflow attack
Netscape Communicator Window Spoofing
Macintosh version of Word '98 includes sensitive material in document files.
Another ICQ 98a bug
BackOffice installation exposes passwords
PadLock-IT 1.01 bad password saving scheme
Vulnerabilities found in Swish search engine
Multiple vulnerabilities in ControlIT
IIS 4.0 vulnerable to ExAir sample site Denial of Service
OShare, a new Windows Denial of Service attack
WS_FTP Server Remote Denial of Service attack
IIS and Perl may be used to reveal true directory location
MiRC DCC Security hole
January
1999
RPCBind security vulnerability
Quake II Server buffer overflow
Linux 2.0.35/36 vulnerable to local port Denial of Service attack
IIS Remote FTP Denial of Service attack
Forms 2.0 (Fm20*.dll) ActiveX Control Security Fix
IIS 4.0 is vulnerable when upgraded from earlier versions
HTTP REQUEST_METHOD security flaw
Solaris 2.5.1 and 2.6 vulnerable to ff.core exploit
Windows 95/98 FrontPage extension security vulnerability
Sendmail 8.9/8.8 vulnerable to two new attacks
CGIc Library is vulnerable to a buffer overflow attack
DPEC's Online Courseware vulnerable to attack
Solaris 2.7 allows finger bouncing
Linux's urandom Denial of Service
Solaris AutoMountD vulnerable to a remote exploit
Iomega's poor Jazz drive backup encryption
Yahoo Pager vulnerable to Denial of Service attack
mSQL multiple buffer overflows
DosEMU buffer overflow assists in gaining root
L0phtCrack 2.5 misplaces temporary password files
SCO's CalServer vulnerable to a buffer overflow
ICQ 98a security flaw
Tripwire buffer overflow
suGuard 1.0 assists in gaining root access
Select Year:
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
Security News
-
Security Reviews
-
Exploits
-
Tools
-
UNIX Focus
-
Windows Focus
All Sections
Security News
Unix focus
Exploits
Tools
Windows focus
Security Reviews
Publique! CMS and SQL Injection Vulnerabilities
LedgerSMB Multiple Vulnerabilities
Files2Links F2L-3000 SQL Injection Vulnerability
Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability
HP-UX Running Apache Data Injection and DoS Vulnerability
MIT krb5 KDC denial of service in cross-realm referral processing
Trango Broadband Wireless Rogue SU Authentication Bug
Exposing HMS HICP Protocol and Intellicom NetBiterConfig.exe Remote Buffer Overflow
AproxEngine Multiple Vulnerabilities
APC Switched Rack PDU XSS Vulnerability
More ›››
Featured Articles
Microsoft Embedded OpenType Font Engine Heap Buffer Overflow (MS09-029)
Virtualmin Multiple Vulnerabilities
Microsoft WordPad Word97 Converter Stack Buffer Overflow Vulnerability (MS09-010)
WordPress Unchecked Privileges in admin.php and Multiple Information Disclosures
Microsoft PowerPoint Conversion Filter Heap Corruption Vulnerability (MS09-017)
Adobe Shockwave Player Director File Parsing Pointer Overwrite
Mozilla Firefox Java Applet Loading Vulnerability
Copyright © 1998-2007
Beyond Security
All rights reserved.
Terms of Use
Site Privacy Statement
.