Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a lar
Published
Dec 30, 1997
iPass RoamServer 3.1 creates temporary files with world-writable permissions.
Dec 29, 1997
Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the serv
Dec 24, 1997
Memory leak in Simple Network Management Protocol (SNMP) agent (snmp.exe) for Windows NT 4.0 before Service Pack 4 allows remote attackers to cause a
Dec 23, 1997
MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.
Dec 16, 1997
Teardrop IP denial of service.
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.
Buffer overflow in Cisco 7xx routers through the telnet service.
Dec 15, 1997
Buffer overflow in CrackLib 2.5 may allow local users to gain root privileges via a long GECOS field.
Dec 14, 1997
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
Dec 10, 1997
Buffer overflow in statd allows root privileges.
Dec 5, 1997
Land IP denial of service.
Dec 1, 1997
Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.
Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.
Buffer overflow in Linux Slackware crond program allows local users to gain root access.
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
Nov 26, 1997
Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character,
Vulnerability in scoterm in SCO OpenServer 5.0 and SCO Open Desktop/Open Server 3.0 allows local users to gain root privileges.
Nov 20, 1997
xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is creat
Nov 12, 1997
Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gai
Nov 10, 1997