Latest CVE Feed
-
10.0
HIGHCVE-1999-1588
Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.... Read more
Affected Products : solaris- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1474
PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.... Read more
Affected Products : powerpoint- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1279
An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.... Read more
Affected Products : sna_server- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1043
Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).... Read more
Affected Products : exchange_server- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1364
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1074
Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.... Read more
Affected Products : webmin- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1175
Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048.... Read more
Affected Products : ios- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1294
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permiss... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1332
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.... Read more
Affected Products : linux- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1333
automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.... Read more
Affected Products : linux- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1473
When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."... Read more
Affected Products : internet_explorer- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1585
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.... Read more
Affected Products : sunos- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-1999-1042
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.... Read more
Affected Products : resource_manager- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1325
SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.... Read more
Affected Products : sas_system- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-1999-1386
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.... Read more
Affected Products : perl- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1456
thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.... Read more
Affected Products : thttpd_http_server- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-1999-1320
Vulnerability in Novell NetWare 3.x and earlier allows local users to gain privileges via packet spoofing.... Read more
Affected Products : netware- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1329
Buffer overflow in SysVInit in Red Hat Linux 5.1 and earlier allows local users to gain privileges.... Read more
Affected Products : linux- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1132
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a list containing duplicate Token Ring IDs.... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1316
Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025