/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/opencve.csv
101 строка33 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
CVE-1999-1022
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.
6.20
d45fa0cf60733a6ca7abd92de1b11f6002d564dfa2fbfda6bdf591d162432fca
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.675527+03:00
CVE-1999-1016
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell.
5.00
8aa6468a677152fb3a618bd9f8a73e56739e5fabda0152fa2bd4f4c2d97692bb
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.675760+03:00
CVE-1999-1023
useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.
4.60
966de4ce1c47e898c57025e57e1dfd10457d84ab43000e1339da040fa8040cd6
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.675987+03:00
CVE-1999-1021
NFS on SunOS 4.1 through 4.1.2 ignores the high order 16 bits in a 32 bit UID, which allows a local user to gain root access if the lower 16 bits are set to 0, as fixed by the NFS jumbo patch upgrade.
7.20
c5f3a71dab880c084e75eecc2ed94fe1f8f5a303ce58b3b743fa05e275bdbda6
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.676172+03:00
CVE-1999-1026
aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.
7.20
8af282763187a9ee42c9de83ee0a59d0815fb19cc373b73c0c832874f485be22
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.676399+03:00
CVE-1999-1025
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.
4.60
da1cc49efc424b96c7f8aaf9a87fd8515a6e449886aaddfcedff113f244e6ae4
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.676590+03:00
CVE-1999-1024
ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infinite loop and core dump when tcpdump prints the packet.
7.50
905b0686d1716220ccf3b3ef3467315fb65367870b10301b42f743df5ea3c228
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.676797+03:00
CVE-1999-1027
Solaris 2.6 HW3/98 installs admintool with world-writable permissions, which allows local users to gain privileges by replacing it with a Trojan horse program.
7.20
e090e6735c925ee45167b584243b588c2c986b81f7948e7fade8f396b2efe2a9
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.676978+03:00
CVE-1999-1030
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.
5.00
49e4498766e9f647a863d2b68cd513feb1a2812e3aa00803b8eeb4e47fba53aa
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.698472+03:00
CVE-1999-1028
Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.
5.00
d673c715e62ade925e7845411e797e937771080f904cd6a8ec5763c84cc0c5d4
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.719736+03:00
CVE-1999-1029
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.
7.50
3c0f70164b78f9a3b746f666cbfe52ca1d88b6168a5cd7eaf5d3943ee03bc57b
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.761535+03:00
CVE-1999-1033
Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.
5.00
6530711cdba7ac5de5aa2b22e0d5c0bce8130c6f97efe1e0636d5ef313da870e
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.787559+03:00
CVE-1999-1031
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.
5.00
64dfc525dbfc2fba8e03f892c1ed37dff1e919c622405cfbab87aa68a04a0638
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.793967+03:00
CVE-1999-1032
Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.
10.00
b37bc5a3f4736f499fac882516d4fae7c8d95534a0c79f9c9cfaf92c1bc58a34
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.847665+03:00
CVE-1999-1034
Vulnerability in login in AT&T System V Release 4 allows local users to gain privileges.
7.20
89c5f20cc2274500d60c42d80ad28d2aedf1a94b02d5aeedfe15a8f8165960c6
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.857062+03:00
CVE-1999-1037
rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.
7.20
06f64e5fc74cd189eb3cb1569e1664586c039a06c4db5d981176a397bb055c69
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.859853+03:00
CVE-1999-1035
IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.
5.00
9ebcb98c433242dd1328c16eb5e68ce6152bb1324d5fed3429a001fc6725d64a
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.870245+03:00
CVE-1999-1036
COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk.
7.20
ca3f49ca3a804a31188a25006e5dff958bb8a7225a02637b99ad6c4a0fcf4992
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.879046+03:00
CVE-1999-1040
Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable.
7.20
f386dc195c866729e5ccc84b322386dd820b8e326e3fd55dbe5bee8bae7ba7b9
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.913384+03:00
CVE-1999-1038
Tiger 2.2.3 allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger's default working directory, as defined by the WORKDIR variable.
7.20
4a5548ee7296e3fbb655bcfd9eee41ac9eab1bbe6c31932c2f3192de04cb223e
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.974527+03:00
CVE-1999-1039
Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise.
7.20
41085d4096829495b2736a677e3519f79d07d2f66d5ab5eec7e8ef1d2d711975
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:13.999181+03:00
CVE-1999-1043
Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).
5.00
4988edc4bbbce5cc1add794b56ccd7a0e1fdcf1c94ecb8d3c7db67b28d8d7b19
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.017652+03:00
CVE-1999-1042
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.
1.20
7f52890f87b7a3ca98d0e78c2aee2036f76a61472a9469137f6e738a0d45bdaa
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.019939+03:00
CVE-1999-1047
When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.
7.50
b1424e65bda1f3ddec7d8e259fca4cbbd1d4b7725aea937e8cc840d19c96d751
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.055256+03:00
CVE-1999-1041
Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.
7.20
7404260679185b6526682b0a5f797c4edc09bc37f8bf3263e35b32576eeb7653
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.071846+03:00
CVE-1999-1045
pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.
7.80
fdeb7ede112e0e3630b032a4dad1b97789bb343db8b608314df1b17950969fab
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.082375+03:00
CVE-1999-1046
Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.
10.00
59da248f07d8660390178bee59e068b4556c152d80d1e9cbbc4b773f65b8841e
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.102363+03:00
CVE-1999-1048
Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.
4.60
138138c74f93650d4ee8110a4556eef5a8176f76ac06737bec3fa8a58f8fc0dd
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.147317+03:00
CVE-1999-1044
Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.
4.60
2974722394b98abd1a88f6d79da79f8f5a0172b8649fdc46db308b8a33dede4d
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.149708+03:00
CVE-1999-1052
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.
5.00
22683b803e5a2fee4184ec97b1f03530a3012064fd37cb8973876e99269e9201
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.173037+03:00
CVE-1999-1050
Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.
5.00
b21d01a563b48f02347d55035657c49d68bb682c1263fa3e5da92a206bee4b96
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.185542+03:00
CVE-1999-1053
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
7.50
0cd59140ed1394b67c753c4df63c789dcae8dc83add3c45af410158443da791a
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.196539+03:00
CVE-1999-1051
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
5.00
ac0421da759908d565c06b6a4c39080c0d04bc08a76319864acb852d900d7e30
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.207667+03:00
CVE-1999-1049
ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.
10.00
3d8de6eb3391b618e65dc1a3f2efdf18230c834b403865877bab35fababe382a
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.275948+03:00
CVE-1999-1056
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1395. Reason: This candidate is a duplicate of CVE-1999-1395. Notes: All CVE users should reference CVE-1999-1395 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
e4796ad496de411952f50555de147efaf1baf914d8c5abf6d56fb1f6cbb3143f
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.304309+03:00
CVE-1999-1059
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.
10.00
dc7ca930ddc4938d351081afa4d956abd52a4c12599f9c8d1bfdac3cbfc1d92c
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.312472+03:00
CVE-1999-1058
Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands.
7.50
146df0df8d405751827fdebed686ba26d6e20ee60b4c28b3e09d39ece7edfa14
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.347761+03:00
CVE-1999-1055
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."
7.50
b13b920aedfbfea29dd80fb9d8fcd3b67d7a170a81c2b589eb8e2de339edd55d
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.370170+03:00
CVE-1999-1061
HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.
7.50
91ab1daf3420657627ac799c9bd7adf6ca0ce38d468d29e9b6d3fff88b7eebe8
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.372529+03:00
CVE-1999-1060
Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.
5.00
8c1c61a6f01fe62f2866f17dda99412f59eae6b51fa64477f1b6b89596018416
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.388040+03:00
CVE-1999-1057
VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.
4.60
268584f07ad2cbadc018e946c59cb57c2dcbec9d4ae6c3be672f1149df6b85b2
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.410911+03:00
CVE-1999-1062
HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.
7.50
d3c4d837149cbf8d5b6a10bb1341f584bd839ddd3007bf93de9907c32ca57a79
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.419159+03:00
CVE-1999-1054
The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.
5.00
c178f9529b69580ecf3ea4e1b656fd8c3da8b937e4fcf4ec883df2baf29fff10
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.425548+03:00
CVE-1999-1063
CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.
10.00
4afc78427d2fbac375080464b7cc3f4275c63c0a21bea6cd92223cf52bd974d2
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.451103+03:00
CVE-1999-1067
SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.
5.00
b051936d7cb6834ffcd88514087f9cf98a208c3201d5ea023960d7eded20b46e
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.482103+03:00
CVE-1999-1065
Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.
7.50
b5a01942d7fc13d8bad1faf8319a5970d650ecea141f6900989dc8062e34c4f6
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.491638+03:00
CVE-1999-1068
Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.
5.00
86cbc49514e998794da1b43f46c1ea4b1f834a66afea8506720b68c1d4c8c590
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.499074+03:00
CVE-1999-1066
Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.
5.00
3554a64a94e4753a6c04df0db35ac48b21c0c767c654c4dd52979a68e159c0de
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.578038+03:00
CVE-1999-1064
Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).
10.00
c73a3d7d06a3b4150bcbc0e190a744d42532a85e667e3393ebbeed68c0fe564b
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.586549+03:00
CVE-1999-1069
Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.
5.00
5a4445ac800067fef64ff49c6c2cd6ececbf6ec06df305087706e6fbf809dafc
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.595910+03:00
CVE-1999-1071
Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.
7.20
988bf54698053e1d8afe05e8e2a4f6f39431d3d295d69a04e1201a165523587b
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.622457+03:00
CVE-1999-1073
Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.
7.20
1b18a0935bf16705dd139d07cd409723223701de6a77a978692c3010735f5263
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.635866+03:00
CVE-1999-1074
Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.
7.50
63c87c4ef6a96b5970f880d02ebf1b97c485a7bbcad3111b0c0fb87237a54fbd
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.690107+03:00
CVE-1999-1070
Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.
5.00
dca1d17bbdcebc5f4ce7dd4c3b079049693c1d60d40c588fb15abf943555e503
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.691073+03:00
CVE-1999-1076
Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session.
4.60
ab999bd83ba208acb671baf5bec5f98cd0202f3a76a013c001b4bf6eb2327b2e
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.723509+03:00
CVE-1999-1075
inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.
5.00
68b6ab6b101cd1cc9e87552bf5df6155cddcb99f485ddb62a0709bb52f707758
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.723730+03:00
CVE-1999-1078
WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.
7.50
21a9b72dfaaf3de4309a4d0538cb2fef5a3368d3c89ed767274f11eab162547b
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.740513+03:00
CVE-1999-1072
Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.
7.20
ad6d283eacc1c0b7e0a151049f25e963d9a858e5f6865c40b53311509da6e522
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.760638+03:00
CVE-1999-1079
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
4.60
ab66760bbb3d3b66c40a47a9048066769b47038baea8241d7f1f1d3f275d6665
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.782590+03:00
CVE-1999-1077
Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.
4.60
83e426232d18a38c65a927ab5ff2093b15e873e84448890105e533eb25aadb9f
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.819742+03:00
CVE-1999-1083
Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.
5.00
8a637d8768dd81a57220a6f8513a5d8a080d9a6fd99ec661d9ce32b378fa8b2b
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.851789+03:00
CVE-1999-1081
Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.
5.00
e404a611313450ce602a9a00861752aeb8d32ddf99d2c7aac3b9f4dc6f039bfb
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.875757+03:00
CVE-1999-0029
root privileges via buffer overflow in ordist command on SGI IRIX systems.
8.40
67f167ae8b2035352044fc7cfe596b57d9874004a4cd1ae89c1896b69fcd6fc6
2026-05-29 01:04:13.597982+03:00
2026-05-29 01:03:54.522108+03:00
CVE-1999-1082
Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.
5.00
81b29d135caae161043cfd897f8c96265d70401c6e0d720b1bea393beed9d5ee
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.878192+03:00
CVE-1999-1086
Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.
10.00
3414ced0ebc50c0075f3d7c5dd2f187799bde1d20a9591818a8aa60aeeb5d533
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.879624+03:00
CVE-1999-1084
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.
4.60
611316a9d9e91420fc97fa81e93cc630b713ea260aa9be09720f31ea6b6618b9
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.893239+03:00
CVE-1999-1080
rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.
7.20
d00ec9a676cef8297b41f5f231cb9e2ee7b9fc1c04a66ee0498432fa5c985e47
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.897343+03:00
CVE-1999-1088
Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.
7.20
f5a7a9e291b7521cb6cd3a1b2d9a084dfd8b9ef4df0f04e28be970742ce07eed
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.928163+03:00
CVE-1999-1087
Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP address for their server.
7.50
6ca00d80ce9a40e145522767aac8030cd09645e0c1ce487b10ed137324a346e3
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.930350+03:00
CVE-1999-1091
UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.
5.00
e3ad744ad3cb009a2c0446809dd6f4f20fef67de027b800ceb4668c0dc77dfeb
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.978423+03:00
CVE-1999-1085
SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack."
5.00
70a3994c4a035a63e9c7f273905d65b0e27a4f136c45d69c2f3ba6f260557bf9
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.984857+03:00
CVE-1999-1090
The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which allows remote attackers to read and modify arbitrary files.
7.50
2763fef1fcc93fb7855adef41d5df4de2157cd66acddefabbfde917219504caa
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.992523+03:00
CVE-1999-1089
Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.
7.20
9eedaf38e3922a1b1ed6aea2d94ce74a4920b73821824ac0f7c9d6906dd5f9e4
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:14.994572+03:00
CVE-2013-5240
This candidate is unused by its CNA.
85272106984709b650af4e100b394443eaf5a31a0aaa7bc17bb4b04e97cdc3e5
2026-05-29 01:33:43.495519+03:00
2026-05-29 01:33:07.222661+03:00
CVE-1999-1094
Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue."
7.50
ac0531c2e505d124d3bf581968852672d03a8effbc06907672640f8e2e6bb299
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.037272+03:00
CVE-1999-1092
tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.
4.60
692c3e77ba047f1650e97d47b50016c28f7e231d15773fc6dc092f1ea2a6b44f
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.049580+03:00
CVE-1999-1095
sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.
7.20
87f461f4dba11778e223046659ab9b09a67b9c8a690e5abfb0b92b8ae80a0431
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.063128+03:00
CVE-1999-1093
Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page.
5.10
5188b02c717c3b5c1d601e9f971e5bbde4b27a0e1a57fbcec1bd2068cbb31c55
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.078827+03:00
CVE-1999-1099
Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.
5.00
883faf6f2bd51854d491cbca84ed202812528b697db59762f977d50f5a16316d
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.158097+03:00
CVE-1999-1097
Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.
6.40
d93cd8307f73376bf85dc94ce29b321289a076b7380de20027357f4f62e0f889
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.158749+03:00
CVE-1999-1098
Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.
5.00
47d1b4472a6afbe6499728f74f7f89702dcc974bd7490c2dc08ee133b6ffeca8
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.191195+03:00
CVE-1999-1101
Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges.
4.60
73a3da6862d90d0018ec81ce3438d210f530f51b0a4a6e7d565c3373d60f4060
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.229204+03:00
CVE-1999-1100
Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via a brute force attack.
7.50
3ff4a96a15bb4e50be6ca0f1756964092eeb43f97a72e20580aa8d49a843b0a6
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.237715+03:00
CVE-1999-1096
Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.
7.20
0a4b9a3d0a544cd501a97490cd318aa644c8812177c0deeb334d7e8572fc6ae9
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.245032+03:00
CVE-1999-1103
dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.
4.60
731210ddd9c2e7548fc9a39e1e72b27ab360d923f77f807f47d6a4bd27e6fc01
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.304103+03:00
CVE-1999-1104
Windows 95 uses weak encryption for the password list (.pwl) file used when password caching is enabled, which allows local users to gain privileges by decrypting the passwords.
4.60
14d3a3d44e1bed90560fec1b9beeb66e4abcd1fe9eac11072adb480a2cfeaf8b
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.310130+03:00
CVE-1999-1107
Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.
7.20
478a00b6b20bb8fd87df2e82a04883b8627b5eb7b4f8fdd2ebe812d43e13c087
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.311670+03:00
CVE-1999-1105
Windows 95, when Remote Administration and File Sharing for NetWare Networks is enabled, creates a share (C$) when an administrator logs in remotely, which allows remote attackers to read arbitrary files by mapping the network drive.
5.00
a55468a9b541234bad0ed6ac7cb5ec9fbdf8506cdc54979b0f3ab015af8107bf
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.331531+03:00
CVE-1999-1106
Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument.
7.20
b4a43aa7e353432e751719bbc5ee375c7d200e3e308ba3cedeefe29bf1c2eb98
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.373717+03:00
CVE-1999-1102
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.
2.10
13ede61fbbacfaf122893b1b8dcec9f2e1c4fd865929dec4ad5cdb74021db4b4
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.387042+03:00
CVE-1999-1111
Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.
7.50
72107fe892518249a2872e3c7284cc0610941493f4ff45f8eb2926e0d93eff46
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.399684+03:00
CVE-1999-1110
Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.
5.00
e29619491449de6ea491d563fa036cb41cb39f14e05a9478799fbffb44990547
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.408128+03:00
CVE-1999-1108
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1107. Reason: This candidate is a duplicate of CVE-1999-1107. Notes: All CVE users should reference CVE-1999-1107 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
7b231472ff9c18bc2bd5c755feac4291b190b1794864551d0bf2322631f421c8
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.474911+03:00
CVE-1999-1112
Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.
7.50
2bdf95dc6c456440fd362e63108557d7b4c4f44aa6f886cdd8cf228aa82d5441
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.501411+03:00
CVE-1999-1113
Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a long USER command to port 106.
5.00
d6b606cfb31df373dfe582b575cd866f69f03be40932e6ce1667f671cbbde3d4
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.508248+03:00
CVE-1999-1114
Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.
7.20
df98897e763cd804dccfcc1839cc6d642bed56a470b19ec95f6cc690c1ab5c42
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.510250+03:00
CVE-1999-1115
Vulnerability in the /etc/suid_exec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).
7.20
d8e4bbe7f388f86b680c5fee70de18cc3113fd2e660681856dff9fb675c8622f
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.594394+03:00
CVE-1999-1109
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.
5.00
7ce86f4f73b7222dc637d08714cf76d2b36d089675970a28f078b85aadafc101
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.597314+03:00
CVE-1999-1118
ndd in Solaris 2.6 allows local users to cause a denial of service by modifying certain TCP/IP parameters.
2.10
14591d3368172a0ac757a8d55cf8e008bf2844856d2532817665e8d72697f660
2026-05-29 01:04:34.546271+03:00
2026-05-29 01:04:15.607986+03:00
CVE-2013-5292
This candidate is unused by its CNA.
c0ba6ab66101f5aaaf0d2e0c599a1b45f5f073e3d2ceb4fed4826fac52b5b431
2026-05-29 01:33:43.495519+03:00
2026-05-29 01:33:08.773621+03:00