|
354851
|
4.6 |
MEDIUM
|
midnight_commander
|
midnight_commander
|
FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.
|
NVD-CWE-Other
|
CVE-1999-1337
|
2016-10-18 11:03 |
1999-08-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354852
|
5.0 |
MEDIUM
|
delegate
|
delegate
|
Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.
|
NVD-CWE-Other
|
CVE-1999-1338
|
2016-10-18 11:03 |
1999-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354853
|
5.0 |
MEDIUM
|
freebsd linux
|
freebsd linux_kernel
|
Vulnerability when Network Address Translation (NAT) is enabled in Linux 2.2.10 and earlier with ipchains, or FreeBSD 3.2 with ipfw, allows remote attackers to cause a denial of service (kernel panic…
|
NVD-CWE-Other
|
CVE-1999-1339
|
2016-10-18 11:03 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354854
|
7.2 |
HIGH
|
hylafax
|
hylafax
|
Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.
|
NVD-CWE-Other
|
CVE-1999-1340
|
2016-10-18 11:03 |
1999-11-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354855
|
5.0 |
MEDIUM
|
icq
|
activelist_server
|
ICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server's UDP port.
|
NVD-CWE-Other
|
CVE-1999-1342
|
2016-10-18 11:03 |
1999-10-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354856
|
5.0 |
MEDIUM
|
xerox
|
docucolor_4lp
|
HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters.
|
NVD-CWE-Other
|
CVE-1999-1343
|
2016-10-18 11:03 |
1999-10-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354857
|
7.5 |
HIGH
|
auto_ftp
|
auto_ftp
|
Auto_FTP.pl script in Auto_FTP 0.2 stores usernames and passwords in plaintext in the auto_ftp.conf configuration file.
|
NVD-CWE-Other
|
CVE-1999-1344
|
2016-10-18 11:03 |
1999-10-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354858
|
4.6 |
MEDIUM
|
auto_ftp
|
auto_ftp
|
Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in …
|
NVD-CWE-Other
|
CVE-1999-1345
|
2016-10-18 11:03 |
1999-10-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354859
|
7.5 |
HIGH
|
redhat
|
linux
|
PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has …
|
NVD-CWE-Other
|
CVE-1999-1346
|
2016-10-18 11:03 |
1999-10-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354860
|
4.6 |
MEDIUM
|
redhat
|
linux
|
Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.
|
NVD-CWE-Other
|
CVE-1999-1347
|
2016-10-18 11:03 |
1999-10-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354861
|
2.1 |
LOW
|
redhat
|
linux
|
Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.
|
NVD-CWE-Other
|
CVE-1999-1348
|
2016-10-18 11:03 |
1999-06-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354862
|
5.0 |
MEDIUM
|
xlink_technology
|
omni-nfs_x_enterprise
|
NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.
|
NVD-CWE-Other
|
CVE-1999-1349
|
2016-10-18 11:03 |
1999-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354863
|
4.6 |
MEDIUM
|
arcad_systemhaus
|
arcad
|
ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse.
|
NVD-CWE-Other
|
CVE-1999-1350
|
2016-10-18 11:03 |
1999-09-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354864
|
5.0 |
MEDIUM
|
kvirc
|
irc_client
|
Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick <soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC …
|
NVD-CWE-Other
|
CVE-1999-1351
|
2016-10-18 11:03 |
1999-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354865
|
4.6 |
MEDIUM
|
linux
|
linux_kernel
|
mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.
|
NVD-CWE-Other
|
CVE-1999-1352
|
2016-10-18 11:03 |
1999-09-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354866
|
4.6 |
MEDIUM
|
softarc
|
firstclass_internet_server
|
E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FC…
|
NVD-CWE-Other
|
CVE-1999-1354
|
2016-10-18 11:03 |
1999-08-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354867
|
4.6 |
MEDIUM
|
compaq
|
smartstart
|
Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, …
|
NVD-CWE-Other
|
CVE-1999-1356
|
2016-10-18 11:03 |
1999-09-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354868
|
7.5 |
HIGH
|
netscape
|
communicator
|
Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" sign, which could all…
|
NVD-CWE-Other
|
CVE-1999-1357
|
2016-10-18 11:03 |
1999-10-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354869
|
6.4 |
MEDIUM
|
microsoft
|
windows_nt
|
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the serv…
|
NVD-CWE-Other
|
CVE-1999-1361
|
2016-10-18 11:03 |
1998-05-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354870
|
3.6 |
LOW
|
david_harris
|
pegasus_mail
|
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.
|
NVD-CWE-Other
|
CVE-1999-1366
|
2016-10-18 11:03 |
1999-05-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354871
|
4.6 |
MEDIUM
|
realnetworks
|
realserver
|
Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-1999-1369
|
2016-10-18 11:03 |
1999-04-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354872
|
4.6 |
MEDIUM
|
triactive
|
remote_management
|
Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-1999-1372
|
2016-10-18 11:03 |
1999-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354873
|
5.0 |
MEDIUM
|
fore
|
powerhub_software
|
FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.
|
NVD-CWE-Other
|
CVE-1999-1373
|
2016-10-18 11:03 |
2005-01-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354874
|
5.0 |
MEDIUM
|
arpanet
|
perlshop
|
perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP req…
|
NVD-CWE-Other
|
CVE-1999-1374
|
2016-10-18 11:03 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354875
|
5.0 |
MEDIUM
|
microsoft
|
internet_information_server
|
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
|
NVD-CWE-Other
|
CVE-1999-1375
|
2016-10-18 11:03 |
1999-02-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354876
|
10.0 |
HIGH
|
microsoft
|
internet_information_server
|
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-1999-1376
|
2016-10-18 11:03 |
1999-01-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354877
|
5.0 |
MEDIUM
|
dbmlparser.exe
|
dbmlparser.exe
|
dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.
|
NVD-CWE-Other
|
CVE-1999-1378
|
2016-10-18 11:03 |
1999-07-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354878
|
5.0 |
MEDIUM
|
dnstools_software
|
dnstools
|
DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.
|
NVD-CWE-Other
|
CVE-1999-1379
|
2016-10-18 11:03 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354879
|
7.5 |
HIGH
|
dbadmin
|
dbadmin
|
Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-1999-1381
|
2016-10-18 11:03 |
1998-10-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354880
|
7.2 |
HIGH
|
novell
|
netware
|
NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting…
|
NVD-CWE-Other
|
CVE-1999-1382
|
2016-10-18 11:03 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354881
|
4.6 |
MEDIUM
|
gnu tcsh
|
bash tcsh
|
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the direct…
|
CWE-264
認可・権限・アクセス制御
|
CVE-1999-1383
|
2016-10-18 11:03 |
1996-09-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354882
|
7.2 |
HIGH
|
sgi
|
irix
|
Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst …
|
NVD-CWE-Other
|
CVE-1999-1384
|
2016-10-18 11:03 |
1996-10-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354883
|
7.2 |
HIGH
|
freebsd
|
freebsd
|
Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-1999-1385
|
2016-10-18 11:03 |
1996-12-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354884
|
5.0 |
MEDIUM
|
microsoft
|
windows_nt
|
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the…
|
NVD-CWE-Other
|
CVE-1999-1387
|
2016-10-18 11:03 |
1997-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354885
|
7.5 |
HIGH
|
3com
|
total_control_netserver_card
|
US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attacker…
|
NVD-CWE-Other
|
CVE-1999-1389
|
2016-10-18 11:03 |
1998-05-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354886
|
2.1 |
LOW
|
bsd
|
bsd
|
BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system edi…
|
NVD-CWE-Other
|
CVE-1999-1394
|
2016-10-18 11:03 |
1999-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354887
|
4.6 |
MEDIUM
|
elm_development_group
|
elm
|
Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.
|
NVD-CWE-Other
|
CVE-1999-1184
|
2016-10-18 11:02 |
1997-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354888
|
7.2 |
HIGH
|
rxvt redhat slackware
|
rxvt linux slackware_linux
|
rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious pr…
|
NVD-CWE-Other
|
CVE-1999-1186
|
2016-10-18 11:02 |
1996-01-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354889
|
5.1 |
MEDIUM
|
network_associates
|
virusscan
|
NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to…
|
NVD-CWE-Other
|
CVE-1999-1195
|
2016-10-18 11:02 |
1999-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354890
|
5.0 |
MEDIUM
|
ascend
|
multilink_ppp_for_isdn
|
Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.
|
NVD-CWE-Other
|
CVE-1999-1203
|
2016-10-18 11:02 |
1999-02-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354891
|
7.5 |
HIGH
|
systemsoft
|
systemwizard
|
SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allow…
|
NVD-CWE-Other
|
CVE-1999-1206
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354892
|
10.0 |
HIGH
|
apache
|
http_server
|
mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
|
NVD-CWE-Other
|
CVE-1999-1293
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354893
|
10.0 |
HIGH
|
redhat slackware
|
linux slackware_linux
|
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system call…
|
NVD-CWE-Other
|
CVE-1999-1299
|
2016-10-18 11:02 |
1997-02-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354894
|
4.6 |
MEDIUM
|
symantec
|
norton_antivirus
|
Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navi…
|
NVD-CWE-Other
|
CVE-1999-1323
|
2016-10-18 11:02 |
1999-04-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354895
|
7.2 |
HIGH
|
redhat
|
linux
|
Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.
|
NVD-CWE-Other
|
CVE-1999-1327
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354896
|
7.2 |
HIGH
|
redhat
|
linux
|
linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.
|
NVD-CWE-Other
|
CVE-1999-1328
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354897
|
4.6 |
MEDIUM
|
debian redhat
|
debian_linux linux
|
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
|
NVD-CWE-Other
|
CVE-1999-1330
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354898
|
5.0 |
MEDIUM
|
ibm
|
aix
|
inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attac…
|
NVD-CWE-Other
|
CVE-1999-1075
|
2016-10-18 11:01 |
1998-03-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354899
|
4.6 |
MEDIUM
|
ibm
|
aix
|
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
|
NVD-CWE-Other
|
CVE-1999-1079
|
2016-10-18 11:01 |
1999-05-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354900
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.
|
NVD-CWE-Other
|
CVE-1999-1082
|
2016-10-18 11:01 |
1999-10-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|