269961
|
- |
|
sun
|
cobalt_raq_2 cobalt_raq_3i
|
cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another vir…
|
NVD-CWE-Other
|
CVE-1999-1530
|
2016-10-18 11:05 |
1999-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269962
|
- |
|
ibm
|
homepageprint
|
Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.
|
NVD-CWE-Other
|
CVE-1999-1531
|
2016-10-18 11:05 |
1999-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269963
|
- |
|
netscape
|
messaging_server
|
Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.
|
NVD-CWE-Other
|
CVE-1999-1532
|
2016-10-18 11:05 |
1999-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269964
|
- |
|
knox_software
|
arkeia
|
Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.
|
NVD-CWE-Other
|
CVE-1999-1534
|
2016-10-18 11:05 |
1999-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269965
|
- |
|
acushop
|
salesbuilder
|
.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.
|
NVD-CWE-Other
|
CVE-1999-1536
|
2016-10-18 11:05 |
1999-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269966
|
- |
|
microsoft
|
internet_information_server
|
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensiti…
|
NVD-CWE-Other
|
CVE-1999-1538
|
2016-10-18 11:05 |
1999-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269967
|
- |
|
microsoft
|
internet_information_server
|
Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.
|
NVD-CWE-Other
|
CVE-1999-1544
|
2016-10-18 11:05 |
1999-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269968
|
- |
|
joes_own_editor
|
joe
|
Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users.
|
NVD-CWE-Other
|
CVE-1999-1545
|
2016-10-18 11:05 |
1999-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269969
|
- |
|
oracle
|
web_listener
|
Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.
|
CWE-20
Improper Input Validation
|
CVE-1999-1547
|
2016-10-18 11:05 |
1999-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
269970
|
- |
|
microsoft
|
index_server
|
Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physic…
|
NVD-CWE-Other
|
CVE-1999-1397
|
2016-10-18 11:04 |
1999-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|