CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 198134 CVEs

CVE ID Severity Description EPSS Published
N/A

DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.

10.2% 1999-08-11
N/A

Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.

21.5% 1999-08-11
N/A

Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.

3.2% 1999-08-11
N/A

Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.

2.3% 1999-08-11
N/A

Denial of service in AIX ptrace system call allows local users to crash the system.

0.3% 1999-08-11
N/A

Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.

0.5% 1999-08-10
N/A

Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.

5.7% 1999-08-09
N/A

sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.

0.3% 1999-08-09
N/A

Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.

1.4% 1999-08-09
N/A

The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.

0.8% 1999-08-09
N/A

The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.

2.3% 1999-08-08
N/A

Buffer overflow in ALMail32 POP3 client via From: or To: headers.

1.6% 1999-08-08
N/A

FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.

1.3% 1999-08-07
N/A

A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.

1.0% 1999-08-06
N/A

Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.

26.1% 1999-08-06
N/A

dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.

9.7% 1999-08-05
N/A

The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.

0.4% 1999-08-05
N/A

OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.

0.3% 1999-08-03
N/A

The WebRamp web administration utility has a default password.

1.1% 1999-08-03
N/A

Buffer overflow in ToxSoft NextFTP client through CWD command.

1.7% 1999-08-03
N/A

FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.

0.3% 1999-08-01
N/A

Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.

1.6% 1999-08-01
N/A

.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.

0.3% 1999-07-30
N/A

Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.

0.3% 1999-07-30
N/A

Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.

3.1% 1999-07-30
N/A

Denial of service in Gauntlet Firewall via a malformed ICMP packet.

2.4% 1999-07-30
N/A

WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.

1.8% 1999-07-29
N/A

Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.

1.1% 1999-07-29
N/A

Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.

2.9% 1999-07-29
N/A

The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.

5.5% 1999-07-28
N/A

Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.

1.1% 1999-07-28
N/A

IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.

7.2% 1999-07-27
N/A

The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.

11.6% 1999-07-25
N/A

Denial of service in Windows NT messenger service through a long username.

16.8% 1999-07-23
N/A

Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.

1.0% 1999-07-21
N/A

GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.

0.5% 1999-07-21
N/A

Buffer overflow in Samba smbd program via a malformed message command.

2.6% 1999-07-21
N/A

Denial of service in Samba NETBIOS name service daemon (nmbd).

2.1% 1999-07-21
N/A

Vulnerability in a script in Texas A&M University (TAMU) Tiger allows local users to execute arbitrary commands as the Tiger user, usually root.

0.4% 1999-07-20
N/A

Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.

3.7% 1999-07-20
N/A

Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.

8.5% 1999-07-20
N/A

dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.

1.3% 1999-07-19
N/A

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.

77.1% 1999-07-19
N/A

The default configuration of the Array Services daemon (arrayd) disables authentication, allowing remote users to gain root privileges.

2.4% 1999-07-19
N/A

Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.

3.1% 1999-07-15
N/A

Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.

2.6% 1999-07-15
N/A

Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users.

0.3% 1999-07-14
N/A

BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.

0.9% 1999-07-13
N/A

Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.

1.0% 1999-07-11
N/A

MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.

0.8% 1999-07-10