Security News
-
Security Reviews
-
Exploits
-
Tools
-
UNIX Focus
-
Windows Focus
Ask the Team
Mailing Lists
Advertising Info
Advisories
About SecuriTeam
Blogs
Brought to you by:
Suppliers of:
Website Testing Tools
Network Testing Tools
Software Testing Tools
SecuriTeam in Your Inbox
New vulnerability?
New tool?
Tell us
(Our
PGP key
).
Windows NT Focus Archive 2000
Select Year:
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
December
2000
SmartServer3 vulnerable to a remote buffer overflow (command & USER)
1st Up Mail Server Buffer Overflow Vulnerability (Large MAIL FROM)
"Configure Your Server" tool creates blank password for Directory Service Restore Mode
Lack of Secure Session ID Support May Lead to IIS Web Session Hijacking
IIS "Malformed Web Form Submission" Vulnerability (Patch Available)
Infinite InterChange DoS (Large POST)
Stealth Viruses can prevent being detected by Norton Anti Virus
Bea WebLogic Server dotdot-overflow
MDaemon vulnerable to a DoS (large string)
Severed Windows Media Server Connection Vulnerability (Patch Available)
ActiveX control in Indexing Services can expose file properties
Microsoft IIS File Disclosure vulnerability (Far East Editions)
Microsoft Windows NT MSTask.exe code error vulnerability (DoS)
Command line mailer suffer from significant security vulnerabilities
Multiple Vulnerabilities in AOL Instant Messenger
Cold Fusion DoS vulnerability in sample script
PHP with Apache on Windows 2000 vulnerable to directory traversal
Weak default registry permission in Windows NT/2000
Offline Explorer exposes local file system
HomeSeer Directory Traversal vulnerability
Denial of Service attack against IPswitch IMail server (short AUTH)
Vulnerability found in Microsoft PhoneBook Server (Patch available)
Serv-U FTP directory traversal vulnerability (%20 vulnerability)
Windows 2000 Telnet Service DoS (incomplete connections)
Microsoft Media Player 7 allows execution of Arbitrary Code (WHS)
Microsoft SQL Server extended stored procedure vulnerability (technical explanation and exploit code)
Patch available for the Internet Explorer 5 "Browser Print Template" and "File Upload via Form" vulnerabilities
Incomplete TCP/IP Packet vulnerability (Patch available)
Extended Stored Procedure Parameter Parsing vulnerability (Patch available)
Microsoft Office Secrets
November
2000
IIS with File Request Parsing patch is still vulnerable to arbitrary commands execution
Bypassing restricted directories on 24Link Web server
Winsock FTPd chroot escaping
Resin server exposes JSP source code (../, %2E, .. etc)
Windows 2000 .ASX and .WMS buffer overrun (Exploit and Patch available)
OBJECT TYPE="text/html" vulnerability in IE 5.5 allows arbitrary command execution
Additional information on the IIS CGI File name vulnerability
Bypassing Domain Account Lockout (Patch available)
IE vulnerability allows execution of arbitrary programs (.chm files and temporary file folder)
SmartServer3 SMTP and POP DoS
Exchange User Account vulnerability (Patch available)
Netsnap Webcam remote buffer overflow
InoculateIT Anti-Virus for MS Exchange Server can be bypassed
IE and Win2000 Indexing service vulnerability
Windows Terminal Server GINA buffer overflow (RegAPI.DLL)
Microsoft IIS 4.0/5.0 CGI File Name Inspection details
Additional details on the System Monitor ActiveX buffer overflow
Web Server File Request Parsing vulnerability (Patch available)
IIS ASP exploit leads to machine compromise
Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent
ActiveX Parameter Validation vulnerability (Patch available)
Indexing Services Cross Site Scripting (Patch available)
Buffer overflow in Network Monitor allows code execution (Patch available)
Netscape Servers heap buffer overflow can lead to remote code execution (context)
Exchange Server Malformed MIME Header vulnerability (Patch available)
October
2000
Index Server cross-site scripting vulnerability (.htw)
Remote Retrieval of IIS Session Cookies from web browsers
I-Gear for Microsoft Proxy long URL vulnerability
Non-WebRoot requests security issue (Patch available)
New Variant of VM File Reading vulnerability
Registry Permissions reminder - local privilege escalation on Windows NT
Session ID Cookie marking vulnerability (Patch available)
HyperTerminal Buffer Overflow vulnerability (Patch available)
IE/Outlook java security vulnerability exposes local files
TransSoft's Broker FTP Server Remote DoS attack
Web Server Folder Traversal vulnerability (Patch available, exploit)
Security issues with Compaq Easy Access Keyboard software
Wingate security vulnerability (file retrieval)
WinU Backdoor passwords revealed
NetMeeting Desktop Sharing vulnerability (Patch available)
Internet Explorer Cached Web Credentials vulnerability (Patch available)
Remote Retrieval of Authentication Data from Internet Explorer
Shambala DoS and password storage vulnerabilities
All-Mail buffer overrun vulnerability
Internet Explorer "square" security hole
Microsoft VM ActiveX Component vulnerability (Patch available)
Patch available for the Malformed IPX NMPI Packet vulnerability
WebTV for Windows Denial of Service (Patch available)
Share Level Password vulnerability (Patch available)
QuotaAdvisor allows complete file listing by unprivileged users
Word Mail Merge vulnerability (Patch available)
com.ms.activeX.ActiveXComponent allows arbitrary command execution
Unauthorized "Directory Listings" under IIS 5.0
Multiple LPC and LPC Ports Vulnerabilities (Patch available)
Pegasus mail file reading vulnerability
Price modification vulnerability in CyberOffice Shopping Cart
Wingate 4.0.1 DoS (Winsock Redirector)
The Simplified Chinese IME State Recognition Vulnerability (Patch Available)
September
2000
Bypassing QuotaAdvisor 4.1 quotas using alternative data streams
Malformed Embedded Windows Media Player 7 "OCX Attachment" Vulnerability
Multiple issues with Talentsoft WebPlus Application Server for NT
IE 5.5 exposes local user files (GetObject)
Multiple Vulnerabilities in CiscoSecure ACS
DoS found in BrowseGate (Authorization, Referer)
Microsoft Internet Information Server 4.0 Security Checklist
Double clicking on Office documents may execute arbitrary programs (DLL)
Exchange Server Attachment DoS attack (boundary)
Microsoft releases a patch for the telnet Client NTLM Authentication problem
Win2k Telnet.exe malicious server vulnerability (NTLM)
How IIS Authenticates Browser Clients
Closing down Windows NT NetBIOS services
Windows NT Event Log explained
WebTV vulnerable to a DoS
Malformed RPC Packet vulnerability (Patch available)
DoS in Faststream FTP++
WebClerk Denial of Service vulnerability
Still Image Service Privilege Escalation vulnerability (Patch available)
Microsoft Windows 9x NETBIOS password verification vulnerability
Windows Malformed IPX packet Denial of Service
Windows NetBIOS client driver type comparing DoS
Unicast Service Race Condition vulnerability (Patch available)
IIS Invalid URL vulnerability (Patch available)
IE Cross Frame security vulnerability (Web Browser Control's Navigate method)
Vulnerability in Outlook 2000's vCard import
File association feature enables Word Viruses to hide from Virus scanners
Remote DoS attack on eEye's IRIS and SpyNet CaptureNet
August
2000
WebSite Pro allows unauthorized file uploads (uploader.exe)
Windows NetBIOS Unsolicited Cache Corruption
Stalker's CGImail gives read access to local server files
Win2k Local Security Policy Corruption (Patch available)
Viking security vulnerabilities enable remote code execution (long URL, date parsing)
IIS Cross-Site scripting vulnerability (Patch available)
Money Password vulnerability (Patch available)
Directory Traversal & Denial-of-Service problems in Worm HTTP Server
FrontPage extensions shtml.exe DoS and path exposure
Microsoft FrontPage 2000 Server Extensions gets updated (SR1.2)
Java VM identity hijacking vulnerability (Patch available)
IIS 5.0 cross site scripting vulnerability - using .shtml files or /_vti_bin/shtml.dll
Translate:f vulnerability exposes IIS files source
Microsoft releases safeguard guide for the MS SQL blank 'sa' vulnerability
WinU 4/5 weak password encryption leads to system compromise
Denial of Service attack against MS Exchange servers (DCOM, ncacn_http)
IE executes arbitrary files thru Microsoft Network
IIS Specialized Header vulnerability exposes ASP source (Patch available)
Tumbleweed Messaging Management System leaves sa's password blank
Alt-N's MDaemon Session hijacking (Static Session IDs)
IIS File Permission Canonicalization vulnerability (Patch available)
Microsoft Office HTML Object Tag vulnerability (Patch available)
IE Scriptlet Rendering vulnerability (Patch available)
Proof of concept exploit code for the Win2k Service Control vulnerability
A combination of MS Word and MS Access allows executing of arbitrary code
Norton Antivirus Scheduler enables privileges elavation (navlu32)
Non standard ICMP Timestamps identifies Windows machines
NetBIOS Name Server Protocol Spoofing (Patch available)
Malformed IPX Ping Packet vulnerability (Patch available)
Excel REGISTER.ID Function vulnerability (Patch available)
Additional details on the Named Pipe Service Control Impersonation
Additional Details on the Windows NetBIOS Name Conflicts vulnerability
Service Control Manager Named Pipe Impersonation vulnerability (Patch available)
July
2000
Microsoft Office's AutoRecovery mechanism poses a security threat
Windows executable path searching vulnerability
Logon DoS when Windows 2000 is combined with EFS
The "Persistent Mail-Browser Link" vulnerability (Patch available)
Outlook "Cache Bypass" vulnerability (Patch available)
Eeye releases nmap for Windows
Buffer overrun in O'Reilly Website Pro (httpd32)
eEye releases the Retina Network Security Scanner
Outlook "Malformed E-mail Header" vulnerability (Patch available)
Attacking Windows 9x with Loadable Kernel Modules (detailed article)
IIS ISM.DLL truncation exposes file content
Buffer overflow in MS Outlook & Outlook Express Email clients (Date parsing)
Additional details have been disclosed regarding the "Absent Directory Browser Argument" DoS
IIS vulnerable to Absent Directory Browser Argument vulnerability (Patch available)
IE 5.5 local text file reading vulnerability (DHTMLED)
Patch Available for the "Office HTML Script" Vulnerability and a Workaround for "The IE Script" Vulnerability
ITAfrica's WebACTIVE vulnerable to a DoS
Microsoft Access 97 password remover
Excel 2000 allows executing programs via XLS files
Blackboard CourseInfo saves password in the clear
WorldClient vulnerable to dotdotdot directory traversal bug
SQL Server's Stored Procedure Permissions vulnerability (Patch Available)
Front Page 2000 DoS attack
Any LAN user can crash Sygate
Active Setup Download vulnerability enables arbitrary file overwrite (Patch available)
Denial of Service vulnerability in Microsoft Windows 2000 Telnet Server
June
2000
IE 5 with Office 2000 vulnerable to remote command execution
Windows DNS servers leaks administrative user names
Detecting Windows machines with ICMP packets
WinProxy vulnerable to an exploitable buffer overflow
Force Feeding files to Internet Explorer
NetWin dMailWeb open relay problem
Workaround available for the JRun code sample vulnerabilities
HP releases patch for the JetAdmin vulnerability (DoS)
BEA WebLogic /file/ showcode vulnerability
BlackICE default configuration does not block Back Orifice
WebShield SMTP and MS-TNEF don't mix
Several buffer overflow problems in WebBBS HTTP Server (large filename, GET)
CERT advisory: HHCtrl ActiveX Control Allows Local File to be Executed
Norton Antivirus for Exchange allows infected attachments to pass through
Microsoft Outlook Malicious URL Vulnerability
MSSQL DTS Password vulnerability (patch available)
Microsoft Access VBA Trojan: The overlooked "Macro Virus"
Windows 2000 Desktop Separation Vulnerability (patch available)
Microsoft Outlook Denial of Service bug (empty BCC and Reply-To)
WebLogic exposes JSP source code
SessionWall-3 Password recovery hole
Microsoft releases long awaited security patch for Outlook
Remote Registry Access Authentication vulnerability (Patch available)
Buffer overflow in i-drive Filo software
Source view vulnerability in Unify eWave ServletExec
HP OpenView Network Node Manager buffer overflow problem (TCP 2345, long string)
Denial of Service attack and a Buffer overflow problem in CMail WebMail
SSL Certificate Validation vulnerability (patch released)
IE 5 Cross-frame security vulnerability using IFRAME and WebBrowser control
Bypassing warnings for Invalid SSL Certificates in IE
IE Frame Domain Verification exploit code released
Why You Should Upgrade To NT4 SP4 or Windows 2000
IE HTML Help File Vulnerability (patch available)
Windows 2000 Protected Store Key Length Vulnerability
Stealing MSSQL passwords using SQL Server EM
ICQ's Guest book CGI long name buffer overflow
May
2000
Patch Available for the "SQL Server 7.0 Service Pack Password" vulnerability
Malformed Windows Media Encoder Request vulnerability
Microsoft Windows Computer Browser Reset
Buffer overflow in NAI WebShield SMTP Management Tool
Patch Available for the "ResetBrowser Frame" and "HostAnnouncement Flooding" vulnerabilities
HP Web JetAdmin remote DoS
Carello Web shopping cart exposes ASP source code
Rockliffe Mailsite vulnerability allows remote code execution
Patch Available for the "IP Fragment Reassembly" Vulnerability
Patch Available for the "Frame Domain Verification", "Unauthorized Cookie Access", and "Malformed Component Attribute" Vulnerabilities
Ways to cope with active content in e-mail
E-Serv vulnerable to directory traversal (dotdotdot)
Export version of Windows 2000 IPsec silently uses weaker encryption
Microsoft IIS Remote Denial of Service Attack (IISADMPWD)
NTMail 3 relay problem
Default SYSKEY configuration compromises encrypting file system
Patch Available for the "Office 2000 UA Control" Vulnerability
Cold Fusion Server DoS (CFCACHE)
Microsoft Outlook Express 4.x JPG/BMP Long Filename Vulnerability
NTMail and Proxy do not mix (Proxy bypassing)
Microsoft IIS shtml.exe path disclosure vulnerability
Allaire ClusterCATS URL Redirect Vulnerability
Patch Available for the "Malformed Extension Data in URL" DoS
Patch Available for the "Undelimited .HTR Request" and the "File Fragment Reading via .HTR" Vulnerabilities
IIS ISM.DLL buffer truncation exposes files
Love Virus analysis and cure
Preventing nmap OS detection for Windows NT
Jana WebServer is vulnerable to dotdotdot traversing
Newdsn IIS Denial of Service vulnerability
Using Access databases on IIS opens up a Denial-of-Service hole (ODBC)
April
2000
Atrium Mercur Mailserver vulnerable to directory traversing
Procedure Available to Eliminate "Server-Side Image Map Components" Vulnerability
Patch Available for "Mixed Object Access" Vulnerability
Patch Available for "Malformed Environment Variable" Vulnerability
Timbuktu Pro vulnerable to remote DoS
How to eliminate the "Link View Server-Side Component" Vulnerability
Tighten your registry settings to fix the OffloadModExpo vulnerability
PcAnywhere weak password encryption
Patch Available for Allaire Forums 2.0.5 security issue
Patch Available for the XLM Text Macro Vulnerability
March
2000
Patch Available for the Virtualized UNC Share Vulnerability
Patch Available for the Malformed TCP/IP Print Request DoS
Windows gives unprotected read access to c:windowssystem when printer sharing is used
Outlook 98 shows hidden drives bypassing system policy (Q242092)
Patch Available for the "OfficeScan Unauthenticated CGI Usage" Vulnerability
Patch Available for the "Chunked Encoding Post" Vulnerability
Patch Available for the "Malformed Media License Request" Vulnerability
Patch Available for the "DOS Device in Path Name" Vulnerability
Patch Available for the OfficeScan DoS & Message Replay Vulnerability
IE and Outlook 5.x .eml file vulnerability allows execution of arbitrary commands
Oracle Web Listener 4.0.x CGI vulnerability
Vulnerability in SQL Server 7.0 login ID Encryption
Patch Available for the Registry Permissions Vulnerability
Patch Available for the SQL Query Abuse Vulnerability
Patch Available for the Clip Art Buffer Overrun Vulnerability
NAI/McAfee Viruscan Engine does not scan .VBS files by default
MS Windows 95/98/SE remote DoS (device path string)
February
2000
WordPad is vulnerable a DoS attack
Allaire fixes Cross-Site Scripting security vulnerability
IE Image Source Redirect Vulnerability (patch available)
W2K administrative share vulnerability during installation
ASP scripts create temporary files that aren't automatically removed
BTT Software SNMP Trap Watcher remote DoS attack
Internet Anywhere Mail Server vulnerable to a DoS attacks (connect())
Patch improves the TCP Initial Sequence Number Randomness
MSN Messenger encryption algorithm cracked
Microsoft Java Virtual Machine allows reading of local files (getSystemResourceAsStream)
RightFax Web Client vulnerable to session Hijacking
Patch Available for the Recycle Bin Creation Vulnerability
War FTP Denial of Service (MKD/CWD)
January
2000
Allaire Spectra Authentication vulnerability (invoke.cfm)
Exploit details for the IIS "Malformed Hit-Highlighting Argument" vulnerability
Microsoft Index Server allows attackers to view local files (Malformed Hit-Highlighting Argument)
Patch Available for the RDISK Registry Enumeration File Vulnerability
ASP Request Object reveals sensitive information about an IIS server
Patch Available for the Malformed Conversion Data Vulnerability
Timbuktu Pro 32 sends user IDs and passwords in clear text.
Patch available for the Malformed RTF Control Word Vulnerability
MS IIS 5.0 crashes when handling long URL Strings (.ida)
IIS reveals directory structure of web sites
Patch Available for the Spoofed LPC Port Request Vulnerability
A security problem in NtImpersonateClientOfPort system call on NT 4
WarFTP vulnerability compromises server security (ODBC)
Patch Available for the Malformed IMAP Request Vulnerability
Allaire Spectra vulnerable to a remote DoS attack (repeated indexing)
Allaire Spectra allows remote users to break outside bounding directories
ColdFusion Information Exposure (CFCACHE Tag)
Default security permissions of SMS 2.0 Remote Control opens a security hole
Select Year:
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
Security News
-
Security Reviews
-
Exploits
-
Tools
-
UNIX Focus
-
Windows Focus
All Sections
Security News
Unix focus
Exploits
Tools
Windows focus
Security Reviews
Mozilla Bugzilla Multiple Vulnerabilities
Real Networks RealPlayer Compressed GIF Handling Integer Overflow
RealNetworks RealPlayer 11 HTTP Chunked Encoding Vulnerability
RealNetworks RealPlayer CMediumBlockAllocator Integer Overflow Vulnerability
HP OpenVMS RMS Local Escalation of Privilege
Asterisk T.38 Remote Crash Vulnerability
HP-UX running HP CIFS Server Remote Unauthorized Access
HP Enterprise Cluster Master Toolkit Local Unauthorized Access
Apple Webkit Blink Event Dangling Pointer Remote Code Execution Vulnerability
SAP MaxDB Malformed Handshake Request Remote Code Execution Vulnerability
More ›››
Featured Articles
Microsoft Embedded OpenType Font Engine Heap Buffer Overflow (MS09-029)
Virtualmin Multiple Vulnerabilities
Microsoft WordPad Word97 Converter Stack Buffer Overflow Vulnerability (MS09-010)
WordPress Unchecked Privileges in admin.php and Multiple Information Disclosures
Microsoft PowerPoint Conversion Filter Heap Corruption Vulnerability (MS09-017)
Adobe Shockwave Player Director File Parsing Pointer Overwrite
Mozilla Firefox Java Applet Loading Vulnerability
Copyright © 1998-2007
Beyond Security
All rights reserved.
Terms of Use
Site Privacy Statement
.