| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2000-0531 | 0.03 | — | 0.00 | Nov 23, 1999 | Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets. | |||
| CVE-1999-1058 | 0.00 | — | 0.01 | Nov 22, 1999 | Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands. | |||
| CVE-1999-0818 | 0.03 | — | 0.01 | Nov 20, 1999 | Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable. | |||
| CVE-1999-0831 | 0.00 | — | 0.01 | Nov 19, 1999 | Denial of service in Linux syslogd via a large number of connections. | |||
| CVE-1999-0999 | 0.04 | — | 0.16 | Nov 19, 1999 | Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet. | |||
| CVE-1999-1475 | 0.00 | — | 0.00 | Nov 19, 1999 | ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command. | |||
| CVE-1999-0987 | 0.00 | — | 0.07 | Nov 18, 1999 | Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. | |||
| CVE-2000-0352 | 0.00 | — | 0.02 | Nov 18, 1999 | Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL. | |||
| CVE-1999-0793 | 0.05 | — | 0.23 | Nov 17, 1999 | Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. | |||
| CVE-1999-1092 | 0.00 | — | 0.00 | Nov 17, 1999 | tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file. | |||
| CVE-1999-1519 | 0.04 | — | 0.06 | Nov 17, 1999 | Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password. | |||
| CVE-2000-0073 | 0.06 | — | 0.34 | Nov 17, 1999 | Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word. | |||
| CVE-1999-1051 | 0.00 | — | 0.01 | Nov 16, 1999 | Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter. | |||
| CVE-1999-1457 | 0.00 | — | 0.01 | Nov 16, 1999 | Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function. | |||
| CVE-1999-1508 | 0.03 | — | 0.03 | Nov 16, 1999 | Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html. | |||
| CVE-1999-1549 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 1999 | Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands. | ||
| CVE-1999-1190 | 0.03 | — | 0.04 | Nov 15, 1999 | Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message. | |||
| CVE-1999-1110 | 0.05 | — | 0.23 | Nov 14, 1999 | Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. | |||
| CVE-1999-1528 | 0.00 | — | 0.00 | Nov 14, 1999 | ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session. | |||
| CVE-2000-0165 | 0.04 | — | 0.08 | Nov 13, 1999 | The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands. | |||
| CVE-1999-1050 | 0.03 | — | 0.05 | Nov 12, 1999 | Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template. | |||
| CVE-2000-0330 | 0.05 | — | 0.23 | Nov 12, 1999 | The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability. | |||
| CVE-2000-0329 | 0.04 | — | 0.07 | Nov 11, 1999 | A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability. | |||
| CVE-1999-0833 | 0.00 | — | 0.02 | Nov 10, 1999 | Buffer overflow in BIND 8.2 via NXT records. | |||
| CVE-1999-0835 | 0.00 | — | 0.01 | Nov 10, 1999 | Denial of service in BIND named via malformed SIG records. | |||
| CVE-1999-0837 | 0.00 | — | 0.01 | Nov 10, 1999 | Denial of service in BIND by improperly closing TCP sessions via so_linger. | |||
| CVE-1999-0848 | 0.04 | — | 0.10 | Nov 10, 1999 | Denial of service in BIND named via consuming more than "fdmax" file descriptors. | |||
| CVE-1999-0849 | 0.00 | — | 0.02 | Nov 10, 1999 | Denial of service in BIND named via maxdname. | |||
| CVE-1999-0851 | 0.00 | — | 0.00 | Nov 10, 1999 | Denial of service in BIND named via naptr. | |||
| CVE-1999-1511 | 0.00 | — | 0.02 | Nov 10, 1999 | Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service. | |||
| CVE-1999-1539 | 0.05 | — | 0.19 | Nov 10, 1999 | Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password. | |||
| CVE-1999-0832 | 0.00 | — | 0.01 | Nov 9, 1999 | Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname. | |||
| CVE-1999-0983 | 0.00 | — | 0.01 | Nov 9, 1999 | Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | |||
| CVE-1999-0984 | 0.00 | — | 0.01 | Nov 9, 1999 | Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | |||
| CVE-1999-0985 | 0.03 | — | 0.04 | Nov 9, 1999 | CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | |||
| CVE-1999-1111 | 0.00 | — | 0.01 | Nov 9, 1999 | Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry… | |||
| CVE-1999-1112 | 0.03 | — | 0.06 | Nov 9, 1999 | Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header. | |||
| CVE-1999-0821 | 0.03 | — | 0.00 | Nov 8, 1999 | FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument. | |||
| CVE-1999-0863 | 0.00 | — | 0.00 | Nov 8, 1999 | Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI. | |||
| CVE-1999-1530 | 0.00 | — | 0.00 | Nov 8, 1999 | cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system. | |||
| CVE-1999-1550 | 0.00 | — | 0.02 | Nov 8, 1999 | bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter. | |||
| CVE-2001-0679 | 0.04 | — | 0.11 | Nov 8, 1999 | A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server. | |||
| CVE-1999-1529 | 0.04 | — | 0.15 | Nov 7, 1999 | A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code. | |||
| CVE-1999-1533 | 0.04 | — | 0.10 | Nov 7, 1999 | Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service. | |||
| CVE-1999-0843 | 0.00 | — | 0.01 | Nov 4, 1999 | Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port. | |||
| CVE-1999-0887 | 0.03 | — | 0.04 | Nov 4, 1999 | FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack. | |||
| CVE-1999-0896 | 0.04 | — | 0.07 | Nov 4, 1999 | Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password. | |||
| CVE-1999-0898 | 0.00 | — | 0.04 | Nov 4, 1999 | Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request. | |||
| CVE-1999-0899 | 0.03 | — | 0.03 | Nov 4, 1999 | The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider. | |||
| CVE-1999-1065 | 0.00 | — | 0.01 | Nov 4, 1999 | Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode. |
- CVE-2000-0531Nov 23, 1999risk 0.03cvss —epss 0.00
Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.
- CVE-1999-1058Nov 22, 1999risk 0.00cvss —epss 0.01
Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands.
- CVE-1999-0818Nov 20, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
- CVE-1999-0831Nov 19, 1999risk 0.00cvss —epss 0.01
Denial of service in Linux syslogd via a large number of connections.
- CVE-1999-0999Nov 19, 1999risk 0.04cvss —epss 0.16
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
- CVE-1999-1475Nov 19, 1999risk 0.00cvss —epss 0.00
ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command.
- CVE-1999-0987Nov 18, 1999risk 0.00cvss —epss 0.07
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
- CVE-2000-0352Nov 18, 1999risk 0.00cvss —epss 0.02
Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.
- CVE-1999-0793Nov 17, 1999risk 0.05cvss —epss 0.23
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
- CVE-1999-1092Nov 17, 1999risk 0.00cvss —epss 0.00
tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.
- CVE-1999-1519Nov 17, 1999risk 0.04cvss —epss 0.06
Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password.
- CVE-2000-0073Nov 17, 1999risk 0.06cvss —epss 0.34
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
- CVE-1999-1051Nov 16, 1999risk 0.00cvss —epss 0.01
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
- CVE-1999-1457Nov 16, 1999risk 0.00cvss —epss 0.01
Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.
- CVE-1999-1508Nov 16, 1999risk 0.03cvss —epss 0.03
Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.
- risk 0.51cvss 7.8epss 0.00
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.
- CVE-1999-1190Nov 15, 1999risk 0.03cvss —epss 0.04
Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.
- CVE-1999-1110Nov 14, 1999risk 0.05cvss —epss 0.23
Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.
- CVE-1999-1528Nov 14, 1999risk 0.00cvss —epss 0.00
ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session.
- CVE-2000-0165Nov 13, 1999risk 0.04cvss —epss 0.08
The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.
- CVE-1999-1050Nov 12, 1999risk 0.03cvss —epss 0.05
Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.
- CVE-2000-0330Nov 12, 1999risk 0.05cvss —epss 0.23
The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.
- CVE-2000-0329Nov 11, 1999risk 0.04cvss —epss 0.07
A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability.
- CVE-1999-0833Nov 10, 1999risk 0.00cvss —epss 0.02
Buffer overflow in BIND 8.2 via NXT records.
- CVE-1999-0835Nov 10, 1999risk 0.00cvss —epss 0.01
Denial of service in BIND named via malformed SIG records.
- CVE-1999-0837Nov 10, 1999risk 0.00cvss —epss 0.01
Denial of service in BIND by improperly closing TCP sessions via so_linger.
- CVE-1999-0848Nov 10, 1999risk 0.04cvss —epss 0.10
Denial of service in BIND named via consuming more than "fdmax" file descriptors.
- CVE-1999-0849Nov 10, 1999risk 0.00cvss —epss 0.02
Denial of service in BIND named via maxdname.
- CVE-1999-0851Nov 10, 1999risk 0.00cvss —epss 0.00
Denial of service in BIND named via naptr.
- CVE-1999-1511Nov 10, 1999risk 0.00cvss —epss 0.02
Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service.
- CVE-1999-1539Nov 10, 1999risk 0.05cvss —epss 0.19
Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.
- CVE-1999-0832Nov 9, 1999risk 0.00cvss —epss 0.01
Buffer overflow in NFS server on Linux allows attackers to execute commands via a long pathname.
- CVE-1999-0983Nov 9, 1999risk 0.00cvss —epss 0.01
Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.
- CVE-1999-0984Nov 9, 1999risk 0.00cvss —epss 0.01
Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.
- CVE-1999-0985Nov 9, 1999risk 0.03cvss —epss 0.04
CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.
- CVE-1999-1111Nov 9, 1999risk 0.00cvss —epss 0.01
Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry…
- CVE-1999-1112Nov 9, 1999risk 0.03cvss —epss 0.06
Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.
- CVE-1999-0821Nov 8, 1999risk 0.03cvss —epss 0.00
FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.
- CVE-1999-0863Nov 8, 1999risk 0.00cvss —epss 0.00
Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI.
- CVE-1999-1530Nov 8, 1999risk 0.00cvss —epss 0.00
cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virtual site on the same system.
- CVE-1999-1550Nov 8, 1999risk 0.00cvss —epss 0.02
bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.
- CVE-2001-0679Nov 8, 1999risk 0.04cvss —epss 0.11
A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.
- CVE-1999-1529Nov 7, 1999risk 0.04cvss —epss 0.15
A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code.
- CVE-1999-1533Nov 7, 1999risk 0.04cvss —epss 0.10
Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service.
- CVE-1999-0843Nov 4, 1999risk 0.00cvss —epss 0.01
Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.
- CVE-1999-0887Nov 4, 1999risk 0.03cvss —epss 0.04
FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.
- CVE-1999-0896Nov 4, 1999risk 0.04cvss —epss 0.07
Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.
- CVE-1999-0898Nov 4, 1999risk 0.00cvss —epss 0.04
Buffer overflows in Windows NT 4.0 print spooler allow remote attackers to gain privileges or cause a denial of service via a malformed spooler request.
- CVE-1999-0899Nov 4, 1999risk 0.03cvss —epss 0.03
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.
- CVE-1999-1065Nov 4, 1999risk 0.00cvss —epss 0.01
Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.