|
363251
|
5.0 |
MEDIUM
|
dnstools_software
|
dnstools
|
DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.
|
NVD-CWE-Other
|
CVE-1999-1379
|
2016-10-18 11:03 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363252
|
7.5 |
HIGH
|
dbadmin
|
dbadmin
|
Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-1999-1381
|
2016-10-18 11:03 |
1998-10-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363253
|
7.2 |
HIGH
|
novell
|
netware
|
NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting…
|
NVD-CWE-Other
|
CVE-1999-1382
|
2016-10-18 11:03 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363254
|
4.6 |
MEDIUM
|
gnu tcsh
|
bash tcsh
|
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the direct…
|
CWE-264
認可・権限・アクセス制御
|
CVE-1999-1383
|
2016-10-18 11:03 |
1996-09-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363255
|
7.2 |
HIGH
|
sgi
|
irix
|
Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst …
|
NVD-CWE-Other
|
CVE-1999-1384
|
2016-10-18 11:03 |
1996-10-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363256
|
7.2 |
HIGH
|
freebsd
|
freebsd
|
Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-1999-1385
|
2016-10-18 11:03 |
1996-12-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363257
|
5.0 |
MEDIUM
|
microsoft
|
windows_nt
|
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the…
|
NVD-CWE-Other
|
CVE-1999-1387
|
2016-10-18 11:03 |
1997-04-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363258
|
7.5 |
HIGH
|
3com
|
total_control_netserver_card
|
US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attacker…
|
NVD-CWE-Other
|
CVE-1999-1389
|
2016-10-18 11:03 |
1998-05-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363259
|
2.1 |
LOW
|
bsd
|
bsd
|
BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system edi…
|
NVD-CWE-Other
|
CVE-1999-1394
|
2016-10-18 11:03 |
1999-07-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363260
|
4.6 |
MEDIUM
|
elm_development_group
|
elm
|
Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.
|
NVD-CWE-Other
|
CVE-1999-1184
|
2016-10-18 11:02 |
1997-05-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363261
|
7.2 |
HIGH
|
rxvt redhat slackware
|
rxvt linux slackware_linux
|
rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious pr…
|
NVD-CWE-Other
|
CVE-1999-1186
|
2016-10-18 11:02 |
1996-01-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363262
|
5.1 |
MEDIUM
|
network_associates
|
virusscan
|
NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to…
|
NVD-CWE-Other
|
CVE-1999-1195
|
2016-10-18 11:02 |
1999-05-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363263
|
5.0 |
MEDIUM
|
ascend
|
multilink_ppp_for_isdn
|
Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.
|
NVD-CWE-Other
|
CVE-1999-1203
|
2016-10-18 11:02 |
1999-02-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363264
|
7.5 |
HIGH
|
systemsoft
|
systemwizard
|
SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allow…
|
NVD-CWE-Other
|
CVE-1999-1206
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363265
|
10.0 |
HIGH
|
apache
|
http_server
|
mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.
|
NVD-CWE-Other
|
CVE-1999-1293
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363266
|
10.0 |
HIGH
|
redhat slackware
|
linux slackware_linux
|
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system call…
|
NVD-CWE-Other
|
CVE-1999-1299
|
2016-10-18 11:02 |
1997-02-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363267
|
4.6 |
MEDIUM
|
symantec
|
norton_antivirus
|
Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navi…
|
NVD-CWE-Other
|
CVE-1999-1323
|
2016-10-18 11:02 |
1999-04-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363268
|
7.2 |
HIGH
|
redhat
|
linux
|
Buffer overflow in linuxconf 1.11r11-rh2 on Red Hat Linux 5.1 allows local users to gain root privileges via a long LANG environmental variable.
|
NVD-CWE-Other
|
CVE-1999-1327
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363269
|
7.2 |
HIGH
|
redhat
|
linux
|
linuxconf before 1.11.r11-rh3 on Red Hat Linux 5.1 allows local users to overwrite arbitrary files and gain root access via a symlink attack.
|
NVD-CWE-Other
|
CVE-1999-1328
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363270
|
4.6 |
MEDIUM
|
debian redhat
|
debian_linux linux
|
The snprintf function in the db library 1.85.4 ignores the size parameter, which could allow attackers to exploit buffer overflows that would be prevented by a properly implemented snprintf.
|
NVD-CWE-Other
|
CVE-1999-1330
|
2016-10-18 11:02 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363271
|
5.0 |
MEDIUM
|
ibm
|
aix
|
inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attac…
|
NVD-CWE-Other
|
CVE-1999-1075
|
2016-10-18 11:01 |
1998-03-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363272
|
4.6 |
MEDIUM
|
ibm
|
aix
|
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
|
NVD-CWE-Other
|
CVE-1999-1079
|
2016-10-18 11:01 |
1999-05-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363273
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.
|
NVD-CWE-Other
|
CVE-1999-1082
|
2016-10-18 11:01 |
1999-10-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363274
|
5.0 |
MEDIUM
|
t._hauck
|
jana_web_server
|
Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.
|
NVD-CWE-Other
|
CVE-1999-1083
|
2016-10-18 11:01 |
1999-10-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363275
|
5.0 |
MEDIUM
|
ssh
|
secure_shell
|
SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream be…
|
NVD-CWE-Other
|
CVE-1999-1085
|
2016-10-18 11:01 |
1998-06-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363276
|
10.0 |
HIGH
|
novell
|
netware
|
Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets t…
|
NVD-CWE-Other
|
CVE-1999-1086
|
2016-10-18 11:01 |
1999-07-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363277
|
4.6 |
MEDIUM
|
iain_lea
|
tin
|
tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.
|
NVD-CWE-Other
|
CVE-1999-1092
|
2016-10-18 11:01 |
1999-11-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363278
|
7.2 |
HIGH
|
redhat slackware
|
linux slackware_linux
|
sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that…
|
NVD-CWE-Other
|
CVE-1999-1095
|
2016-10-18 11:01 |
1997-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363279
|
4.6 |
MEDIUM
|
microsoft
|
windows_95
|
Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.
|
NVD-CWE-Other
|
CVE-1999-1104
|
2016-10-18 11:01 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363280
|
5.0 |
MEDIUM
|
sendmail
|
sendmail
|
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands a…
|
NVD-CWE-Other
|
CVE-1999-1109
|
2016-10-18 11:01 |
1999-12-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363281
|
5.0 |
MEDIUM
|
eudora
|
internet_mail_server
|
Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a long USER command to port 106.
|
NVD-CWE-Other
|
CVE-1999-1113
|
2016-10-18 11:01 |
1998-04-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363282
|
10.0 |
HIGH
|
oracle
|
http_server
|
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gai…
|
NVD-CWE-Other
|
CVE-1999-1125
|
2016-10-18 11:01 |
1997-09-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363283
|
5.0 |
MEDIUM
|
netscape
|
enterprise_server
|
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command u…
|
NVD-CWE-Other
|
CVE-1999-1130
|
2016-10-18 11:01 |
1999-07-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363284
|
5.0 |
MEDIUM
|
microsoft
|
windows_nt
|
Windows NT 4.0 allows remote attackers to cause a denial of service (crash) via extra source routing data such as (1) a Routing Information Field (RIF) field with a hop count greater than 7, or (2) a…
|
NVD-CWE-Other
|
CVE-1999-1132
|
2016-10-18 11:01 |
1999-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363285
|
10.0 |
HIGH
|
hp
|
hp-ux
|
Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.
|
NVD-CWE-Other
|
CVE-1999-1160
|
2016-10-18 11:01 |
1997-02-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363286
|
7.5 |
HIGH
|
hp
|
9000
|
Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.
|
NVD-CWE-Other
|
CVE-1999-1163
|
2016-10-18 11:01 |
1999-11-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363287
|
5.0 |
MEDIUM
|
microsoft
|
outlook outlook_express
|
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.
|
NVD-CWE-Other
|
CVE-1999-1164
|
2016-10-18 11:01 |
1999-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363288
|
7.2 |
HIGH
|
gnu
|
fingerd
|
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) r…
|
NVD-CWE-Other
|
CVE-1999-1165
|
2016-10-18 11:01 |
1999-07-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363289
|
2.1 |
LOW
|
corel
|
wordperfect
|
Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working di…
|
NVD-CWE-Other
|
CVE-1999-1173
|
2016-10-18 11:01 |
1998-12-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363290
|
7.2 |
HIGH
|
aaron_ledbetter jidentd
|
cidentd jidentd
|
Buffer overflow in cidentd ident daemon allows local users to gain root privileges via a long line in the .authlie script.
|
NVD-CWE-Other
|
CVE-1999-1176
|
2016-10-18 11:01 |
1998-01-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363291
|
7.2 |
HIGH
|
delix caldera debian lst redhat suse
|
dld openlinux_lite debian_linux lst_power_linux linux suse_linux
|
Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.…
|
NVD-CWE-Other
|
CVE-1999-1182
|
2016-10-18 11:01 |
1997-07-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363292
|
7.2 |
HIGH
|
todd_miller
|
sudo
|
sudo 1.5.x allows local users to execute arbitrary commands via a .. (dot dot) attack.
|
NVD-CWE-Other
|
CVE-1999-0958
|
2016-10-18 11:00 |
1998-01-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363293
|
6.2 |
MEDIUM
|
hp
|
hp-ux
|
HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.
|
NVD-CWE-Other
|
CVE-1999-0961
|
2016-10-18 11:00 |
1996-09-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363294
|
7.2 |
HIGH
|
sco
|
unixware
|
The SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into _init before the privileged process is executed.
|
NVD-CWE-Other
|
CVE-1999-0979
|
2016-10-18 11:00 |
2000-04-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363295
|
5.0 |
MEDIUM
|
netscape
|
communicator
|
Netscape Navigator uses weak encryption for storing a user's Netscape mail password.
|
NVD-CWE-Other
|
CVE-1999-1002
|
2016-10-18 11:00 |
2000-01-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363296
|
5.0 |
MEDIUM
|
netscape novell
|
enterprise_server groupwise
|
Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.
|
NVD-CWE-Other
|
CVE-1999-1005
|
2016-10-18 11:00 |
1999-12-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363297
|
5.0 |
MEDIUM
|
novell
|
groupwise
|
Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.
|
NVD-CWE-Other
|
CVE-1999-1006
|
2016-10-18 11:00 |
1999-12-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363298
|
7.6 |
HIGH
|
vdonet
|
vdolive_player
|
Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.
|
NVD-CWE-Other
|
CVE-1999-1007
|
2016-10-18 11:00 |
1999-12-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363299
|
7.2 |
HIGH
|
freebsd mandrakesoft
|
freebsd mandrake_linux
|
xsoldier program allows local users to gain root access via a long argument.
|
NVD-CWE-Other
|
CVE-1999-1008
|
2016-10-18 11:00 |
2000-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363300
|
2.1 |
LOW
|
openbsd
|
openssh
|
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.
|
NVD-CWE-Other
|
CVE-1999-1010
|
2016-10-18 11:00 |
1999-12-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|