CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 103816 CVEs

CVE ID Severity Description EPSS Published
N/A

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

7.5% 1999-02-17
N/A

Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.

3.1% 1999-02-17
N/A

A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.

0.7% 1999-02-17
N/A

O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.

1.6% 1999-02-16
N/A

Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.

1.0% 1999-02-16
N/A

Debian GNU/Linux cfengine package is susceptible to a symlink attack.

0.1% 1999-02-16
N/A

mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.

0.6% 1999-02-15
N/A

Vulnerability in Compaq Tru64 UNIX edauth command.

0.1% 1999-02-15
N/A

Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.

5.8% 1999-02-14
N/A

Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.

0.7% 1999-02-12
N/A

The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.

6.3% 1999-02-12
N/A

FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

74.0% 1999-02-11
N/A

Lynx allows a local user to overwrite sensitive files through /tmp symlinks.

0.1% 1999-02-11
N/A

In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.

0.1% 1999-02-10
N/A

rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.

0.3% 1999-02-10
N/A

By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.

29.6% 1999-02-09
N/A

Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.

48.3% 1999-02-09
N/A

NetBSD netstat command allows local users to access kernel memory.

0.1% 1999-02-09
N/A

In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.

5.7% 1999-02-08
N/A

Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.

0.4% 1999-02-08
N/A

Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.

19.1% 1999-02-06
N/A

nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.

0.8% 1999-02-04
N/A

The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.

1.5% 1999-02-04
N/A

Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.

50.3% 1999-02-02
N/A

IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

0.0% 1999-02-02
N/A

ACC Tigris allows public access without a login.

0.5% 1999-02-02
N/A

SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.

1.1% 1999-02-02
N/A

WS_FTP server remote denial of service through cwd command.

0.1% 1999-02-02
N/A

Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.

0.1% 1999-02-01
N/A

A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.

0.4% 1999-02-01
N/A

Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.

0.1% 1999-02-01
N/A

Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.

0.0% 1999-02-01
N/A

FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client.

0.9% 1999-02-01
N/A

The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.

0.8% 1999-02-01
N/A

MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.

7.8% 1999-01-30
N/A

The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.

1.9% 1999-01-29
N/A

netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.

0.6% 1999-01-29
N/A

Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.

0.1% 1999-01-28
N/A

Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.

1.3% 1999-01-28
N/A

Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.

0.7% 1999-01-27
N/A

A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.

11.2% 1999-01-27
N/A

IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.

10.2% 1999-01-27
N/A

In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

25.3% 1999-01-26
N/A

The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.

36.2% 1999-01-26
N/A

Denial of service in Linux 2.2.0 running the ldd command on a core file.

1.0% 1999-01-26
N/A

Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.

3.2% 1999-01-26
N/A

Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.

0.0% 1999-01-25
N/A

Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.

9.5% 1999-01-25
N/A

ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.

0.3% 1999-01-25
N/A

ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.

0.0% 1999-01-25