The jj CGI program allows command execution via shell metacharacters.
Published
Dec 24, 1996
Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.
aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.
Dec 20, 1996
swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.
Dec 19, 1996
Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
Dec 18, 1996
Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.
Dec 13, 1996
Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.
Dec 12, 1996
List of arbitrary files on Web host via nph-test-cgi script.
Dec 10, 1996
Sendmail decode alias can be used to overwrite sensitive files.
Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).
Dec 5, 1996
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
Dec 4, 1996
fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.
Dec 3, 1996
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
Buffer overflow in HP-UX newgrp program.
Dec 1, 1996
Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.
Nov 26, 1996
Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includ
Nov 22, 1996
dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.
Nov 17, 1996
Local users can start Sendmail in daemon mode and gain root privileges.
Nov 16, 1996