CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 186845 CVEs

CVE ID Severity Description EPSS Published
N/A

Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.

7.2% 1999-12-22
N/A

Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.

1.3% 1999-12-22
N/A

Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.

4.6% 1999-12-21
N/A

IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.

34.9% 1999-12-21
N/A

IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.

12.2% 1999-12-21
N/A

Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.

1.4% 1999-12-21
N/A

Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.

1.1% 1999-12-21
N/A

Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.

8.9% 1999-12-21
N/A

Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.

1.4% 1999-12-21
N/A

DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.

1.9% 1999-12-20
N/A

wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.

6.2% 1999-12-20
N/A

Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.

1.5% 1999-12-19
N/A

Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.

7.9% 1999-12-19
N/A

Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.

2.0% 1999-12-16
N/A

Cisco Cache Engine allows a remote attacker to gain access via a null username and password.

1.4% 1999-12-16
N/A

The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.

2.0% 1999-12-16
N/A

Cisco Cache Engine allows an attacker to replace content in the cache.

1.3% 1999-12-16
N/A

Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request."

21.8% 1999-12-16
N/A

Windows NT with SYSKEY reuses the keystream that is used for encrypting SAM password hashes, allowing an attacker to crack passwords.

7.2% 1999-12-16
N/A

Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.

7.7% 1999-12-15
N/A

classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.

9.8% 1999-12-15
N/A

classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.

6.8% 1999-12-15
N/A

The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.

0.3% 1999-12-14
N/A

daynad program in Intel InBusiness E-mail Station does not require authentication, which allows remote attackers to modify its configuration, delete files, or read mail.

1.5% 1999-12-14
N/A

An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.

1.4% 1999-12-14
N/A

Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.

3.5% 1999-12-13
N/A

War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.

1.9% 1999-12-13
N/A

Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.

6.9% 1999-12-13
N/A

The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.

1.5% 1999-12-12
N/A

The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.

3.6% 1999-12-12
N/A

Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.

12.6% 1999-12-10
N/A

The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed.

2.7% 1999-12-10
N/A

htdig allows remote attackers to execute commands via filenames with shell metacharacters.

1.8% 1999-12-09
N/A

Buffer overflow in Solaris snoop allows remote attackers to gain root privileges via GETQUOTA requests to the rpc.rquotad service.

3.2% 1999-12-09
N/A

Buffer overflow in Xshipwars xsw program.

2.1% 1999-12-09
N/A

The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.

4.3% 1999-12-08
N/A

Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."

13.1% 1999-12-08
N/A

Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.

0.3% 1999-12-07
N/A

Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.

3.5% 1999-12-07
N/A

Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.

2.5% 1999-12-06
N/A

Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.

11.9% 1999-12-06
N/A

Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.

0.4% 1999-12-05
N/A

The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.

0.4% 1999-12-05
N/A

UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.

0.8% 1999-12-04
N/A

ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.

1.9% 1999-12-03
N/A

ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.

1.6% 1999-12-03
N/A

Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.

0.6% 1999-12-03
N/A

Buffer overflow in UnixWare xauto program allows local users to gain root privilege.

0.8% 1999-12-03
N/A

Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.

1.5% 1999-12-03
N/A

UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.

0.7% 1999-12-03