CVE-2000-1074 – Netscape iCal 2.1 Patch2 - iPlanet iCal 'csstart' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2000-1074
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory. • https://www.exploit-db.com/exploits/20276 http://www.atstake.com/research/advisories/2000/a100900-1.txt http://www.osvdb.org/7209 http://www.securityfocus.com/bid/1769 https://exchange.xforce.ibmcloud.com/vulnerabilities/5757 •
CVE-2000-1073
https://notcve.org/view.php?id=CVE-2000-1073
csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory. • http://www.atstake.com/research/advisories/2000/a100900-1.txt http://www.osvdb.org/7210 http://www.securityfocus.com/bid/1769 https://exchange.xforce.ibmcloud.com/vulnerabilities/5757 •
CVE-2000-1071
https://notcve.org/view.php?id=CVE-2000-1071
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges. • http://www.atstake.com/research/advisories/2000/a100900-1.txt http://www.osvdb.org/7213 http://www.securityfocus.com/bid/1767 https://exchange.xforce.ibmcloud.com/vulnerabilities/5752 •
CVE-2000-1075 – iPlanet Certificate Management System 4.2 - Directory Traversal
https://notcve.org/view.php?id=CVE-2000-1075
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services. • https://www.exploit-db.com/exploits/20324 https://www.exploit-db.com/exploits/20325 http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html http://www.iplanet.com/downloads/patches/0122.html http://www.osvdb.org/4086 http://www.osvdb.org/486 http://www.securityfocus.com/bid/1839 https://exchange.xforce.ibmcloud.com/vulnerabilities/5421 •
CVE-2000-1076
https://notcve.org/view.php?id=CVE-2000-1076
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server. • http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html https://exchange.xforce.ibmcloud.com/vulnerabilities/5422 •