Security
Headlines
HeadlinesLatestCVEs

Tag

#ibm

CVE-1999-0827: IBM X-Force Exchange

By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.

CVE
#ibm
CVE-1999-0830: IBM X-Force Exchange

Buffer overflow in SCO UnixWare Xsco command via a long argument.

CVE-1999-0829: IBM X-Force Exchange

HP Secure Web Console uses weak encryption.

CVE-1999-0882: IBM X-Force Exchange

Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.

CVE-1999-0879: IBM X-Force Exchange

Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.

CVE-1999-0880: IBM X-Force Exchange

Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.

CVE-1999-0817: IBM X-Force Exchange

Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.

CVE-1999-0813: IBM X-Force Exchange

Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.

CVE-1999-0810: IBM X-Force Exchange

Denial of service in Samba NETBIOS name service daemon (nmbd).

CVE-1999-0809: IBM X-Force Exchange

Netscape Communicator 4.x with Javascript enabled does not warn a user of cookie settings, even if they have selected the option to "Only accept cookies originating from the same server as the page being viewed".