Unknown · CVSS Not scored
In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Linux ftpwatch program allows local users to gain root privileges.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
ftp on HP-UX 11.00 allows local users to gain privileges.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the "noexec" flag set.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
64 bit Solaris 7 procfs allows local users to perform a denial of service.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A buffer overflow in lsof allows local users to obtain root privilege.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
WS_FTP server remote denial of service through cwd command.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in Thomas Boutell's cgic library version up to 1.05.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
ppl program in HP-UX allows local users to create root files through symlinks.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
All records in a WINS database can be deleted through SNMP for a denial of service.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Debian GNU/Linux cfengine package is susceptible to a symlink attack.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Linux PAM modules allow local users to gain root access using temporary files.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
SGI syserr program allows local users to corrupt files.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
AAA authentication on Cisco systems allows attackers to execute commands without authorization.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Buffer overflow in the Linux mail program "deliver" allows local users to gain root access.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
Lynx allows a local user to overwrite sensitive files through /tmp symlinks.
Published Sep 29, 1999 · Updated Aug 1, 2024
Unknown · CVSS Not scored
In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.
Published Sep 29, 1999 · Updated Aug 1, 2024