| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0476 | 0.00 | — | 0.00 | Mar 1, 1999 | A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user. | |||
| CVE-1999-0381 | 0.03 | — | 0.01 | Feb 26, 1999 | super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access. | |||
| CVE-1999-0380 | 0.00 | — | 0.00 | Feb 25, 1999 | SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user. | |||
| CVE-1999-0483 | 0.00 | — | 0.00 | Feb 25, 1999 | OpenBSD crash using nlink value in FFS and EXT2FS filesystems. | |||
| CVE-1999-0408 | 0.00 | — | 0.02 | Feb 25, 1999 | Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server. | |||
| CVE-1999-1247 | 0.00 | — | 0.01 | Feb 24, 1999 | Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges. | |||
| CVE-1999-0484 | 0.00 | — | 0.00 | Feb 23, 1999 | Buffer overflow in OpenBSD ping. | |||
| CVE-1999-0378 | 0.00 | — | 0.01 | Feb 22, 1999 | InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands. | |||
| CVE-1999-0377 | 0.00 | — | 0.02 | Feb 22, 1999 | Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services. | |||
| CVE-1999-0441 | 0.03 | — | 0.06 | Feb 22, 1999 | Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service. | |||
| CVE-1999-0379 | 0.00 | — | 0.06 | Feb 22, 1999 | Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. | |||
| CVE-1999-1049 | 0.00 | — | 0.02 | Feb 21, 1999 | ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password. | |||
| CVE-1999-1168 | 0.00 | — | 0.01 | Feb 20, 1999 | install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file. | |||
| CVE-1999-0376 | 0.03 | — | 0.02 | Feb 20, 1999 | Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs. | |||
| CVE-1999-0485 | 0.00 | — | 0.01 | Feb 19, 1999 | Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD. | |||
| CVE-1999-1372 | 0.00 | — | 0.00 | Feb 19, 1999 | Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges. | |||
| CVE-1999-1101 | 0.00 | — | 0.00 | Feb 19, 1999 | Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges. | |||
| CVE-1999-0460 | 0.03 | — | 0.01 | Feb 19, 1999 | Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service. | |||
| CVE-1999-0412 | 0.04 | — | 0.10 | Feb 19, 1999 | In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. | |||
| CVE-1999-0406 | 0.00 | — | 0.00 | Feb 19, 1999 | Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege. | |||
| CVE-1999-1255 | 0.00 | — | 0.01 | Feb 19, 1999 | Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter. | |||
| CVE-1999-1482 | 0.00 | — | 0.00 | Feb 19, 1999 | SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes. | |||
| CVE-2000-0367 | 0.00 | — | 0.00 | Feb 18, 1999 | Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges. | |||
| CVE-1999-0405 | 0.03 | — | 0.01 | Feb 18, 1999 | A buffer overflow in lsof allows local users to obtain root privilege. | |||
| CVE-1999-1495 | 0.00 | — | 0.00 | Feb 18, 1999 | xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file. | |||
| CVE-1999-1405 | 0.03 | — | 0.03 | Feb 17, 1999 | snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd… | |||
| CVE-1999-0396 | 0.00 | — | 0.01 | Feb 17, 1999 | A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service. | |||
| CVE-1999-1060 | 0.00 | — | 0.02 | Feb 17, 1999 | Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname. | |||
| CVE-1999-0375 | 0.00 | — | 0.03 | Feb 16, 1999 | Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands. | |||
| CVE-1999-0374 | 0.00 | — | 0.00 | Feb 16, 1999 | Debian GNU/Linux cfengine package is susceptible to a symlink attack. | |||
| CVE-1999-1180 | 0.00 | — | 0.02 | Feb 16, 1999 | O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat. | |||
| CVE-1999-1260 | 0.00 | — | 0.01 | Feb 15, 1999 | mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query. | |||
| CVE-1999-0714 | 0.00 | — | 0.00 | Feb 15, 1999 | Vulnerability in Compaq Tru64 UNIX edauth command. | |||
| CVE-1999-0404 | 0.04 | — | 0.10 | Feb 14, 1999 | Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution. | |||
| CVE-1999-1203 | 0.00 | — | 0.02 | Feb 12, 1999 | Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier. | |||
| CVE-1999-0372 | 0.03 | — | 0.04 | Feb 12, 1999 | The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. | |||
| CVE-1999-1375 | 0.05 | — | 0.31 | Feb 11, 1999 | FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. | |||
| CVE-1999-0371 | 0.00 | — | 0.00 | Feb 11, 1999 | Lynx allows a local user to overwrite sensitive files through /tmp symlinks. | |||
| CVE-1999-0353 | 0.00 | — | 0.02 | Feb 10, 1999 | rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory. | |||
| CVE-1999-0370 | 0.00 | — | 0.00 | Feb 10, 1999 | In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files. | |||
| CVE-1999-0407 | 0.00 | — | 0.05 | Feb 9, 1999 | By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. | |||
| CVE-1999-0368 | 0.06 | — | 0.40 | Feb 9, 1999 | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | |||
| CVE-1999-0367 | 0.00 | — | 0.00 | Feb 9, 1999 | NetBSD netstat command allows local users to access kernel memory. | |||
| CVE-1999-0350 | 0.03 | — | 0.01 | Feb 8, 1999 | Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits. | |||
| CVE-1999-0366 | 0.00 | — | 0.04 | Feb 8, 1999 | In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. | |||
| CVE-1999-1201 | 0.01 | — | 0.14 | Feb 6, 1999 | Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka… | |||
| CVE-1999-0365 | 0.00 | — | 0.04 | Feb 4, 1999 | The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry. | |||
| CVE-1999-1169 | 0.00 | — | 0.01 | Feb 4, 1999 | nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets. | |||
| CVE-1999-1453 | 0.04 | — | 0.11 | Feb 2, 1999 | Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. | |||
| CVE-1999-0362 | 0.00 | — | 0.02 | Feb 2, 1999 | WS_FTP server remote denial of service through cwd command. |
- CVE-1999-0476Mar 1, 1999risk 0.00cvss —epss 0.00
A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.
- CVE-1999-0381Feb 26, 1999risk 0.03cvss —epss 0.01
super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.
- CVE-1999-0380Feb 25, 1999risk 0.00cvss —epss 0.00
SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.
- CVE-1999-0483Feb 25, 1999risk 0.00cvss —epss 0.00
OpenBSD crash using nlink value in FFS and EXT2FS filesystems.
- CVE-1999-0408Feb 25, 1999risk 0.00cvss —epss 0.02
Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.
- CVE-1999-1247Feb 24, 1999risk 0.00cvss —epss 0.01
Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.
- CVE-1999-0484Feb 23, 1999risk 0.00cvss —epss 0.00
Buffer overflow in OpenBSD ping.
- CVE-1999-0378Feb 22, 1999risk 0.00cvss —epss 0.01
InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.
- CVE-1999-0377Feb 22, 1999risk 0.00cvss —epss 0.02
Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.
- CVE-1999-0441Feb 22, 1999risk 0.03cvss —epss 0.06
Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.
- CVE-1999-0379Feb 22, 1999risk 0.00cvss —epss 0.06
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
- CVE-1999-1049Feb 21, 1999risk 0.00cvss —epss 0.02
ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.
- CVE-1999-1168Feb 20, 1999risk 0.00cvss —epss 0.01
install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file.
- CVE-1999-0376Feb 20, 1999risk 0.03cvss —epss 0.02
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
- CVE-1999-0485Feb 19, 1999risk 0.00cvss —epss 0.01
Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.
- CVE-1999-1372Feb 19, 1999risk 0.00cvss —epss 0.00
Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges.
- CVE-1999-1101Feb 19, 1999risk 0.00cvss —epss 0.00
Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges.
- CVE-1999-0460Feb 19, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.
- CVE-1999-0412Feb 19, 1999risk 0.04cvss —epss 0.10
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
- CVE-1999-0406Feb 19, 1999risk 0.00cvss —epss 0.00
Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.
- CVE-1999-1255Feb 19, 1999risk 0.00cvss —epss 0.01
Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter.
- CVE-1999-1482Feb 19, 1999risk 0.00cvss —epss 0.00
SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes.
- CVE-2000-0367Feb 18, 1999risk 0.00cvss —epss 0.00
Vulnerability in eterm 0.8.8 in Debian GNU/Linux allows an attacker to gain root privileges.
- CVE-1999-0405Feb 18, 1999risk 0.03cvss —epss 0.01
A buffer overflow in lsof allows local users to obtain root privilege.
- CVE-1999-1495Feb 18, 1999risk 0.00cvss —epss 0.00
xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.
- CVE-1999-1405Feb 17, 1999risk 0.03cvss —epss 0.03
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd…
- CVE-1999-0396Feb 17, 1999risk 0.00cvss —epss 0.01
A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.
- CVE-1999-1060Feb 17, 1999risk 0.00cvss —epss 0.02
Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.
- CVE-1999-0375Feb 16, 1999risk 0.00cvss —epss 0.03
Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.
- CVE-1999-0374Feb 16, 1999risk 0.00cvss —epss 0.00
Debian GNU/Linux cfengine package is susceptible to a symlink attack.
- CVE-1999-1180Feb 16, 1999risk 0.00cvss —epss 0.02
O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.
- CVE-1999-1260Feb 15, 1999risk 0.00cvss —epss 0.01
mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.
- CVE-1999-0714Feb 15, 1999risk 0.00cvss —epss 0.00
Vulnerability in Compaq Tru64 UNIX edauth command.
- CVE-1999-0404Feb 14, 1999risk 0.04cvss —epss 0.10
Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.
- CVE-1999-1203Feb 12, 1999risk 0.00cvss —epss 0.02
Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.
- CVE-1999-0372Feb 12, 1999risk 0.03cvss —epss 0.04
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
- CVE-1999-1375Feb 11, 1999risk 0.05cvss —epss 0.31
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
- CVE-1999-0371Feb 11, 1999risk 0.00cvss —epss 0.00
Lynx allows a local user to overwrite sensitive files through /tmp symlinks.
- CVE-1999-0353Feb 10, 1999risk 0.00cvss —epss 0.02
rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.
- CVE-1999-0370Feb 10, 1999risk 0.00cvss —epss 0.00
In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.
- CVE-1999-0407Feb 9, 1999risk 0.00cvss —epss 0.05
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.
- CVE-1999-0368Feb 9, 1999risk 0.06cvss —epss 0.40
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
- CVE-1999-0367Feb 9, 1999risk 0.00cvss —epss 0.00
NetBSD netstat command allows local users to access kernel memory.
- CVE-1999-0350Feb 8, 1999risk 0.03cvss —epss 0.01
Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.
- CVE-1999-0366Feb 8, 1999risk 0.00cvss —epss 0.04
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.
- CVE-1999-1201Feb 6, 1999risk 0.01cvss —epss 0.14
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka…
- CVE-1999-0365Feb 4, 1999risk 0.00cvss —epss 0.04
The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.
- CVE-1999-1169Feb 4, 1999risk 0.00cvss —epss 0.01
nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.
- CVE-1999-1453Feb 2, 1999risk 0.04cvss —epss 0.11
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.
- CVE-1999-0362Feb 2, 1999risk 0.00cvss —epss 0.02
WS_FTP server remote denial of service through cwd command.