SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.
Published
Dec 29, 1998
mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the us
Dec 27, 1998
Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /
Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
Dec 26, 1998
Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.
nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain comma
Dec 25, 1998
BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local
Dec 24, 1998
Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perf
Dec 18, 1998
The passwd command in Solaris can be subjected to a denial of service.
Dec 17, 1998
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
Dec 12, 1998
RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privilege
Dec 10, 1998
fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console de
Dec 7, 1998
Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.
Dec 4, 1998
Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent p
BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.
Dec 3, 1998
BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.
Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext i
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
Dec 2, 1998
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
Dec 1, 1998
Buffer overflow in NetMeeting allows denial of service and remote command execution.