Latest CVE Feed
-
7.2
HIGHCVE-2000-0078
The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.... Read more
Affected Products : hp-ux- Published: Jan. 02, 2000
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-0964
Buffer overflow in FreeBSD setlocale in the libc module allows attackers to execute arbitrary code via a long PATH_LOCALE environment variable.... Read more
Affected Products : freebsd- Published: Jan. 01, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0069
The recover program in Solstice Backup allows local users to restore sensitive files.... Read more
Affected Products : solstice_backup- Published: Jan. 01, 2000
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2000-0120
The Remote Access Service invoke.cfm template in Allaire Spectra 1.0 allows users to bypass authentication via the bAuthenticated parameter.... Read more
Affected Products : spectra- Published: Jan. 01, 2000
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-1999-1386
Perl 5.004_04 and earlier follows symbolic links when running with the -e option, which allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl-eaXXXXX file.... Read more
Affected Products : perl- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1333
automatic download option in ncftp 2.4.2 FTP client in Red Hat Linux 5.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the names of files that are to be downloaded.... Read more
Affected Products : linux- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1585
The (1) rcS and (2) mountall programs in Sun Solaris 2.x, possibly before 2.4, start a privileged shell on the system console if fsck fails while the system is booting, which allows attackers with physical access to gain root privileges.... Read more
Affected Products : sunos- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1456
thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.... Read more
Affected Products : thttpd_http_server- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1332
gzexe in the gzip package on Red Hat Linux 5.0 and earlier allows local users to overwrite files of other users via a symlink attack on a temporary file.... Read more
Affected Products : linux- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1325
SAS System 5.18 on VAX/VMS is installed with insecure permissions for its directories and startup file, which allows local users to gain privileges.... Read more
Affected Products : sas_system- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1473
When a Web site redirects the browser to another site, Internet Explorer 3.02 and 4.0 automatically resends authentication information to the second site, aka the "Page Redirect Issue."... Read more
Affected Products : internet_explorer- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1316
Passfilt.dll in Windows NT SP2 allows users to create a password that contains the user's name, which could make it easier for an attacker to guess.... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-0815
Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1177
Directory traversal vulnerability in nph-publish before 1.2 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the pathname for an upload operation.... Read more
Affected Products : nph-publish- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-1465
Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a log... Read more
Affected Products : ios- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1444
genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.... Read more
Affected Products : alibaba- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-1999-0808
Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.... Read more
Affected Products : dhcp_client- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-1999-1167
Cross-site scripting vulnerability in Third Voice Web annotation utility allows remote users to read sensitive data and generate fake web pages for other Third Voice users by injecting malicious Javascript into an annotation.... Read more
Affected Products : third_voice_web- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-1999-1307
Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.... Read more
Affected Products : unixware- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-1999-1035
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.... Read more
Affected Products : internet_information_server- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025