| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0176 | 0.04 | — | 0.09 | Jul 10, 1997 | The Webgais program allows a remote user to execute arbitrary commands. | |||
| CVE-1999-1463 | 0.01 | — | 0.16 | Jul 10, 1997 | Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session. | |||
| CVE-1999-0031 | 0.01 | — | 0.18 | Jul 8, 1997 | JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. | |||
| CVE-1999-0196 | 0.04 | — | 0.13 | Jul 8, 1997 | websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable). | |||
| CVE-1999-1326 | 0.00 | — | 0.02 | Jul 4, 1997 | wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files. | |||
| CVE-1999-0074 | 0.01 | — | 0.08 | Jul 1, 1997 | Listening TCP ports are sequentially allocated, allowing spoofing attacks. | |||
| CVE-1999-0076 | 0.00 | — | 0.02 | Jul 1, 1997 | Buffer overflow in wu-ftp from PASV command causes a core dump. | |||
| CVE-1999-0111 | 0.00 | — | 0.01 | Jul 1, 1997 | RIP v1 is susceptible to spoofing. | |||
| CVE-1999-0147 | 0.04 | — | 0.09 | Jul 1, 1997 | The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands. | |||
| CVE-1999-0150 | 0.00 | — | 0.04 | Jul 1, 1997 | The Perl fingerd program allows arbitrary command execution from remote users. | |||
| CVE-1999-0153 | 0.05 | — | 0.21 | Jul 1, 1997 | Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke. | |||
| CVE-1999-0156 | 0.00 | — | 0.00 | Jul 1, 1997 | wu-ftpd FTP daemon allows any user and password combination. | |||
| CVE-1999-0169 | 0.00 | — | 0.02 | Jul 1, 1997 | NFS allows attackers to read and write any file on the system by specifying a false UID. | |||
| CVE-1999-0184 | 0.00 | — | 0.02 | Jul 1, 1997 | When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records. | |||
| CVE-1999-0195 | 0.00 | — | 0.02 | Jul 1, 1997 | Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1. | |||
| CVE-1999-0219 | 0.04 | — | 0.09 | Jul 1, 1997 | Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command. | |||
| CVE-1999-0250 | 0.00 | — | 0.02 | Jul 1, 1997 | Denial of service in Qmail through long SMTP commands. | |||
| CVE-1999-0526 | 0.05 | — | 0.21 | Jul 1, 1997 | An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server. | |||
| CVE-1999-0532 | — | 0.08 | — | 0.69 | Jul 1, 1997 | A DNS server allows zone transfers. | ||
| CVE-1999-0533 | — | 0.00 | — | 0.02 | Jul 1, 1997 | A DNS server allows inverse queries. | ||
| CVE-1999-0541 | — | 0.00 | — | 0.02 | Jul 1, 1997 | A password for accessing a WWW URL is guessable. | ||
| CVE-1999-0628 | 0.00 | — | 0.01 | Jul 1, 1997 | The rwho/rwhod service is running, which exposes machine status and user information. | |||
| CVE-1999-1423 | 0.03 | — | 0.01 | Jun 26, 1997 | ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i. | |||
| CVE-1999-1192 | 0.00 | — | 0.00 | Jun 24, 1997 | Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument. | |||
| CVE-1999-1483 | 0.03 | — | 0.01 | Jun 19, 1997 | Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable. | |||
| CVE-1999-0957 | 0.00 | — | 0.00 | Jun 18, 1997 | MajorCool mj_key_cache program allows local users to modify files via a symlink attack. | |||
| CVE-1999-1266 | 0.00 | — | 0.01 | Jun 13, 1997 | rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system. | |||
| CVE-1999-0033 | 0.00 | — | 0.01 | Jun 12, 1997 | Command execution in Sun systems via buffer overflow in the at program. | |||
| CVE-1999-0083 | 0.00 | — | 0.02 | Jun 11, 1997 | getcwd() file descriptor leak in FTP. | |||
| CVE-1999-0275 | 0.00 | — | 0.06 | Jun 10, 1997 | Denial of service in Windows NT DNS servers by flooding port 53 with too many characters. | |||
| CVE-1999-0189 | 0.00 | — | 0.01 | Jun 4, 1997 | Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111. | |||
| CVE-1999-0144 | 0.03 | — | 0.01 | Jun 1, 1997 | Denial of service in Qmail by specifying a large number of recipients with the RCPT command. | |||
| CVE-1999-0227 | 0.00 | — | 0.05 | Jun 1, 1997 | Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service. | |||
| CVE-1999-0281 | 0.04 | — | 0.13 | Jun 1, 1997 | Denial of service in IIS using long URLs. | |||
| CVE-1999-0799 | 0.00 | — | 0.02 | Jun 1, 1997 | Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location. | |||
| CVE-1999-0034 | 0.03 | — | 0.01 | May 29, 1997 | Buffer overflow in suidperl (sperl), Perl 4.x and 5.x. | |||
| CVE-1999-0035 | Med | 0.35 | 5.4 | 0.01 | May 29, 1997 | Race condition in signal handling routine in ftpd, allowing read/write arbitrary files. | ||
| CVE-1999-1143 | 0.00 | — | 0.00 | May 28, 1997 | Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs. | |||
| CVE-1999-0036 | Hig | 0.58 | 8.4 | 0.01 | May 26, 1997 | IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files. | ||
| CVE-1999-0064 | 0.03 | — | 0.01 | May 26, 1997 | Buffer overflow in AIX lquerylv program gives root access to local users. | |||
| CVE-1999-0259 | 0.00 | — | 0.01 | May 23, 1997 | cfingerd lists all users on a system via search.**@target. | |||
| CVE-1999-0037 | 0.00 | — | 0.04 | May 21, 1997 | Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail. | |||
| CVE-1999-1191 | 0.03 | — | 0.02 | May 19, 1997 | Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument. | |||
| CVE-1999-1449 | 0.00 | — | 0.00 | May 19, 1997 | SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device. | |||
| CVE-1999-1402 | 0.03 | — | 0.01 | May 17, 1997 | The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket. | |||
| CVE-1999-1232 | 0.00 | — | 0.00 | May 16, 1997 | Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program. | |||
| CVE-1999-1141 | 0.00 | — | 0.01 | May 15, 1997 | Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters. | |||
| CVE-1999-0962 | 0.00 | — | 0.01 | May 14, 1997 | Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option. | |||
| CVE-1999-1158 | 0.03 | — | 0.01 | May 13, 1997 | Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd. | |||
| CVE-1999-1184 | 0.03 | — | 0.01 | May 13, 1997 | Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable. |
- CVE-1999-0176Jul 10, 1997risk 0.04cvss —epss 0.09
The Webgais program allows a remote user to execute arbitrary commands.
- CVE-1999-1463Jul 10, 1997risk 0.01cvss —epss 0.16
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.
- CVE-1999-0031Jul 8, 1997risk 0.01cvss —epss 0.18
JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.
- CVE-1999-0196Jul 8, 1997risk 0.04cvss —epss 0.13
websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).
- CVE-1999-1326Jul 4, 1997risk 0.00cvss —epss 0.02
wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.
- CVE-1999-0074Jul 1, 1997risk 0.01cvss —epss 0.08
Listening TCP ports are sequentially allocated, allowing spoofing attacks.
- CVE-1999-0076Jul 1, 1997risk 0.00cvss —epss 0.02
Buffer overflow in wu-ftp from PASV command causes a core dump.
- CVE-1999-0111Jul 1, 1997risk 0.00cvss —epss 0.01
RIP v1 is susceptible to spoofing.
- CVE-1999-0147Jul 1, 1997risk 0.04cvss —epss 0.09
The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.
- CVE-1999-0150Jul 1, 1997risk 0.00cvss —epss 0.04
The Perl fingerd program allows arbitrary command execution from remote users.
- CVE-1999-0153Jul 1, 1997risk 0.05cvss —epss 0.21
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
- CVE-1999-0156Jul 1, 1997risk 0.00cvss —epss 0.00
wu-ftpd FTP daemon allows any user and password combination.
- CVE-1999-0169Jul 1, 1997risk 0.00cvss —epss 0.02
NFS allows attackers to read and write any file on the system by specifying a false UID.
- CVE-1999-0184Jul 1, 1997risk 0.00cvss —epss 0.02
When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.
- CVE-1999-0195Jul 1, 1997risk 0.00cvss —epss 0.02
Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
- CVE-1999-0219Jul 1, 1997risk 0.04cvss —epss 0.09
Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.
- CVE-1999-0250Jul 1, 1997risk 0.00cvss —epss 0.02
Denial of service in Qmail through long SMTP commands.
- CVE-1999-0526Jul 1, 1997risk 0.05cvss —epss 0.21
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
- CVE-1999-0532Jul 1, 1997risk 0.08cvss —epss 0.69
A DNS server allows zone transfers.
- CVE-1999-0533Jul 1, 1997risk 0.00cvss —epss 0.02
A DNS server allows inverse queries.
- CVE-1999-0541Jul 1, 1997risk 0.00cvss —epss 0.02
A password for accessing a WWW URL is guessable.
- CVE-1999-0628Jul 1, 1997risk 0.00cvss —epss 0.01
The rwho/rwhod service is running, which exposes machine status and user information.
- CVE-1999-1423Jun 26, 1997risk 0.03cvss —epss 0.01
ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.
- CVE-1999-1192Jun 24, 1997risk 0.00cvss —epss 0.00
Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
- CVE-1999-1483Jun 19, 1997risk 0.03cvss —epss 0.01
Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
- CVE-1999-0957Jun 18, 1997risk 0.00cvss —epss 0.00
MajorCool mj_key_cache program allows local users to modify files via a symlink attack.
- CVE-1999-1266Jun 13, 1997risk 0.00cvss —epss 0.01
rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.
- CVE-1999-0033Jun 12, 1997risk 0.00cvss —epss 0.01
Command execution in Sun systems via buffer overflow in the at program.
- CVE-1999-0083Jun 11, 1997risk 0.00cvss —epss 0.02
getcwd() file descriptor leak in FTP.
- CVE-1999-0275Jun 10, 1997risk 0.00cvss —epss 0.06
Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.
- CVE-1999-0189Jun 4, 1997risk 0.00cvss —epss 0.01
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
- CVE-1999-0144Jun 1, 1997risk 0.03cvss —epss 0.01
Denial of service in Qmail by specifying a large number of recipients with the RCPT command.
- CVE-1999-0227Jun 1, 1997risk 0.00cvss —epss 0.05
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
- CVE-1999-0281Jun 1, 1997risk 0.04cvss —epss 0.13
Denial of service in IIS using long URLs.
- CVE-1999-0799Jun 1, 1997risk 0.00cvss —epss 0.02
Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.
- CVE-1999-0034May 29, 1997risk 0.03cvss —epss 0.01
Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.
- risk 0.35cvss 5.4epss 0.01
Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.
- CVE-1999-1143May 28, 1997risk 0.00cvss —epss 0.00
Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.
- risk 0.58cvss 8.4epss 0.01
IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.
- CVE-1999-0064May 26, 1997risk 0.03cvss —epss 0.01
Buffer overflow in AIX lquerylv program gives root access to local users.
- CVE-1999-0259May 23, 1997risk 0.00cvss —epss 0.01
cfingerd lists all users on a system via search.**@target.
- CVE-1999-0037May 21, 1997risk 0.00cvss —epss 0.04
Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.
- CVE-1999-1191May 19, 1997risk 0.03cvss —epss 0.02
Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.
- CVE-1999-1449May 19, 1997risk 0.00cvss —epss 0.00
SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.
- CVE-1999-1402May 17, 1997risk 0.03cvss —epss 0.01
The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.
- CVE-1999-1232May 16, 1997risk 0.00cvss —epss 0.00
Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.
- CVE-1999-1141May 15, 1997risk 0.00cvss —epss 0.01
Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.
- CVE-1999-0962May 14, 1997risk 0.00cvss —epss 0.01
Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.
- CVE-1999-1158May 13, 1997risk 0.03cvss —epss 0.01
Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.
- CVE-1999-1184May 13, 1997risk 0.03cvss —epss 0.01
Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.