|
348701
|
5.0 |
MEDIUM
|
xylogics
|
annex
|
Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.
|
NVD-CWE-Other
|
CVE-1999-1070
|
2008-09-6 05:18 |
1998-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348702
|
7.5 |
HIGH
|
ipswitch
|
ws_ftp_pro
|
WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.
|
NVD-CWE-Other
|
CVE-1999-1078
|
2008-09-6 05:18 |
1999-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348703
|
5.0 |
MEDIUM
|
bsd
|
bsd
|
Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.
|
NVD-CWE-Other
|
CVE-1999-1098
|
2008-09-6 05:18 |
1995-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348704
|
2.1 |
LOW
|
sgi apple bsd sun
|
irix a_ux bsd sunos
|
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000…
|
NVD-CWE-Other
|
CVE-1999-1102
|
2008-09-6 05:18 |
1999-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348705
|
4.6 |
MEDIUM
|
digital
|
osf_1
|
dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.
|
NVD-CWE-Other
|
CVE-1999-1103
|
2008-09-6 05:18 |
1996-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348706
|
5.0 |
MEDIUM
|
microsoft
|
windows_95
|
Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary f…
|
NVD-CWE-Other
|
CVE-1999-1105
|
2008-09-6 05:18 |
1999-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348707
|
7.2 |
HIGH
|
hp
|
apollo_domain_os
|
Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).
|
NVD-CWE-Other
|
CVE-1999-1115
|
2008-09-6 05:18 |
1990-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348708
|
7.5 |
HIGH
|
allaire
|
coldfusion
|
HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which reques…
|
NVD-CWE-Other
|
CVE-1999-1124
|
2008-09-6 05:18 |
1999-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348709
|
6.4 |
MEDIUM
|
sco
|
open_desktop unix
|
Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.
|
NVD-CWE-Other
|
CVE-1999-1162
|
2008-09-6 05:18 |
1993-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348710
|
7.2 |
HIGH
|
linux
|
linux_kernel
|
Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.
|
NVD-CWE-Other
|
CVE-1999-1166
|
2008-09-6 05:18 |
1999-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348711
|
7.2 |
HIGH
|
iss
|
internet_security_scanner
|
install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file.
|
NVD-CWE-Other
|
CVE-1999-1168
|
2008-09-6 05:18 |
1999-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348712
|
5.0 |
MEDIUM
|
maximizer
|
maximizer_enterprise
|
By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.
|
NVD-CWE-Other
|
CVE-1999-1172
|
2008-09-6 05:18 |
1999-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348713
|
7.5 |
HIGH
|
sysadmin_magazine
|
man.sh
|
Vulnerability in man.sh CGI script, included in May 1998 issue of SysAdmin Magazine, allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-1999-1179
|
2008-09-6 05:18 |
1998-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348714
|
7.2 |
HIGH
|
sgi
|
irix
|
Vulnerability in On-Line Customer Registration software for IRIX 6.2 through 6.4 allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-1999-1181
|
2008-09-6 05:18 |
1998-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348715
|
10.0 |
HIGH
|
admiral_systems
|
emailclub
|
Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.
|
NVD-CWE-Other
|
CVE-1999-1190
|
2008-09-6 05:18 |
1999-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348716
|
5.0 |
MEDIUM
|
hummingbird
|
exceed
|
Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.
|
NVD-CWE-Other
|
CVE-1999-1196
|
2008-09-6 05:18 |
1999-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348717
|
5.0 |
MEDIUM
|
hummingbird
|
exceed
|
Upgrade to a non-vulnerable version of Exceed (Hummingbird Exceed 6.0.1 Hummingbird Exceed 6.0.2 Hummingbird Exceed 6.1)
|
NVD-CWE-Other
|
CVE-1999-1196
|
2008-09-6 05:18 |
1999-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348718
|
7.2 |
HIGH
|
sun
|
sunos
|
TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.
|
NVD-CWE-Other
|
CVE-1999-1197
|
2008-09-6 05:18 |
1990-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348719
|
7.2 |
HIGH
|
next
|
next
|
BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-1999-1198
|
2008-09-6 05:18 |
1990-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348720
|
4.6 |
MEDIUM
|
linux
|
linux_kernel
|
Denial of service in Linux 2.2.0 running the ldd command on a core file.
|
NVD-CWE-Other
|
CVE-1999-0400
|
2008-09-6 05:17 |
1999-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348721
|
2.1 |
LOW
|
linux
|
linux_kernel
|
Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.
|
NVD-CWE-Other
|
CVE-1999-0451
|
2008-09-6 05:17 |
1999-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348722
|
2.1 |
LOW
|
linux
|
linux_kernel
|
Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.
|
NVD-CWE-Other
|
CVE-1999-0460
|
2008-09-6 05:17 |
1999-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348723
|
7.5 |
HIGH
|
allaire
|
coldfusion_server
|
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
|
NVD-CWE-Other
|
CVE-1999-0477
|
2008-09-6 05:17 |
1999-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348724
|
7.5 |
HIGH
|
netscape
|
enterprise_server fasttrack_server
|
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.
|
NVD-CWE-Other
|
CVE-1999-0744
|
2008-09-6 05:17 |
2000-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348725
|
5.0 |
MEDIUM
|
oracle
|
database_server
|
Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.
|
NVD-CWE-Other
|
CVE-1999-0784
|
2008-09-6 05:17 |
2001-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348726
|
5.0 |
MEDIUM
|
freebsd
|
freebsd
|
TCP RST denial of service in FreeBSD.
|
NVD-CWE-Other
|
CVE-1999-0053
|
2008-09-6 05:16 |
1998-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348727
|
10.0 |
HIGH
|
ssh
|
ssh
|
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
|
NVD-CWE-Other
|
CVE-1999-0248
|
2008-09-6 05:16 |
1999-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348728
|
9.3 |
HIGH
|
freebsd
|
freebsd
|
Buffer overflow in FreeBSD lpd through long DNS hostnames.
|
NVD-CWE-Other
|
CVE-1999-0299
|
2008-09-6 05:16 |
1997-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348729
|
10.0 |
HIGH
|
futuresoft
|
tftp_server_2000
|
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Re…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2005-1812
|
2008-09-5 13:00 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348730
|
7.8 |
HIGH
|
futuresoft
|
tftp_server_2000
|
Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (…
|
CWE-22
Path Traversal
|
CVE-2005-1813
|
2008-09-5 13:00 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348731
|
5.0 |
MEDIUM
|
apache
|
derby
|
Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL functio…
|
CWE-200
Information Exposure
|
CVE-2005-4849
|
2008-09-5 13:00 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348732
|
7.5 |
HIGH
|
macromedia
|
jrun
|
Session fixation vulnerability in Macromedia JRun 4.0 allows remote attackers to hijack user sessions by pre-setting the user session ID information used by the session server.
|
CWE-287
Improper Authentication
|
CVE-2004-2182
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348733
|
2.1 |
LOW
|
intersystems
|
cache
|
Unspecified vulnerability in the %XML.Utils.SchemaServer class in InterSystems Cache' 5.0 allows attackers to access arbitrary files on a server.
|
NVD-CWE-noinfo
|
CVE-2004-2683
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348734
|
2.1 |
LOW
|
intersystems
|
cache_database
|
Unspecified vulnerability in the %template package in InterSystems Cache' 5.0 allows attackers to access certain files on a server, including (1) cache.key and (2) cache.dat, related to .csp files un…
|
NVD-CWE-noinfo
|
CVE-2004-2684
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348735
|
9.3 |
HIGH
|
apple samba
|
xcode samba
|
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed …
|
CWE-16
Configuration
|
CVE-2004-2687
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348736
|
9.0 |
HIGH
|
aspdotnetstorefront
|
aspdotnetstorefront
|
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-2700
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348737
|
5.0 |
MEDIUM
|
phrozensmoke
|
gyach_enhanced
|
Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2004-2706
|
2008-09-5 13:00 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348738
|
7.2 |
HIGH
|
ibm
|
aix
|
Unspecified vulnerability in crontab in IBM AIX 3.2 allows local users to gain root privileges via unknown attack vectors.
|
NVD-CWE-noinfo
|
CVE-1999-1589
|
2008-09-5 13:00 |
1999-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348739
|
5.0 |
MEDIUM
|
coxco_support
|
a-cart metacart midicart_asp midicart_asp_maxi midicart_asp_plus salescart-pro salescart-std
|
MidiCart stores the midicart.mdb database file under the Web document root, which allows remote attackers to steal sensitive information by directly requesting the database.
|
CWE-200
Information Exposure
|
CVE-2002-1432
|
2008-09-5 13:00 |
2003-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348740
|
4.3 |
MEDIUM
|
ikonboard
|
ikonboard
|
Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via a private message with a javascript: URL in the IMG tag, in which the UR…
|
CWE-79
Cross-site Scripting
|
CVE-2002-2230
|
2008-09-5 13:00 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348741
|
0.0 |
LOW
|
-
|
-
|
The echo service is running.
|
NVD-CWE-Other
|
CVE-1999-0635
|
2007-07-13 13:00 |
1999-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348742
|
0.0 |
LOW
|
-
|
-
|
This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System …
|
NVD-CWE-Other
|
CVE-1999-0635
|
2007-07-13 13:00 |
1999-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348743
|
0.0 |
LOW
|
-
|
-
|
The Echo Service is an unsecured and obsolete protocol and it should be disabled. Historically it has been used to perform denial of service attacks.
|
NVD-CWE-Other
|
CVE-1999-0635
|
2007-07-13 13:00 |
1999-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348744
|
5.0 |
MEDIUM
|
-
|
-
|
Multiple vulnerabilities in multiple vendor implementations of the X.400 protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an X.400 message containi…
|
NVD-CWE-Other
|
CVE-2003-0565
|
2005-10-20 13:00 |
2003-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348745
|
5.1 |
MEDIUM
|
-
|
-
|
Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.
|
NVD-CWE-Other
|
CVE-2000-0889
|
2005-10-20 13:00 |
2001-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348746
|
10.0 |
HIGH
|
-
|
-
|
Buffer overflow in post-query sample CGI program allows remote attackers to execute arbitrary commands via an HTTP POST request that contains at least 10001 parameters.
|
NVD-CWE-Other
|
CVE-2001-0291
|
2005-10-20 13:00 |
2001-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|