Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-1999-1411 | 1 Debian | 1 Debian Linux | 2016-10-17 | 7.5 HIGH | N/A |
The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp. | |||||
CVE-1999-1414 | 1 Ibm | 1 Netfinity Remote Control | 2016-10-17 | 7.2 HIGH | N/A |
IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges. | |||||
CVE-1999-1420 | 1 N-base | 5 Nh2012, Nh2012r, Nh2015 and 2 more | 2016-10-17 | 10.0 HIGH | N/A |
NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration. | |||||
CVE-1999-1421 | 1 N-base | 2 Nh208, Nh215 | 2016-10-17 | 6.4 MEDIUM | N/A |
NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names. | |||||
CVE-1999-1422 | 1 Slackware | 1 Slackware Linux | 2016-10-17 | 7.2 HIGH | N/A |
The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users. | |||||
CVE-1999-1429 | 1 Dit | 1 Transferpro | 2016-10-17 | 2.1 LOW | N/A |
DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver. | |||||
CVE-1999-1430 | 1 Royal | 1 Davinci | 2016-10-17 | 2.1 LOW | N/A |
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access. | |||||
CVE-1999-1431 | 1 Microsoft | 1 Zero Administration Kit | 2016-10-17 | 4.6 MEDIUM | N/A |
ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe. | |||||
CVE-1999-1433 | 1 Hp | 1 Jetadmin | 2016-10-17 | 7.2 HIGH | N/A |
HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file. | |||||
CVE-1999-1434 | 1 Slackware | 1 Slackware Linux | 2016-10-17 | 7.2 HIGH | N/A |
login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server. | |||||
CVE-1999-1435 | 1 Nec | 1 Socks 5 | 2016-10-17 | 7.2 HIGH | N/A |
Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables. | |||||
CVE-1999-1436 | 1 Ray Chan | 1 Www Authorization Gateway | 2016-10-17 | 7.5 HIGH | N/A |
Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter. | |||||
CVE-1999-1437 | 1 Ralf S. Engelschall | 1 Eperl | 2016-10-17 | 7.5 HIGH | N/A |
ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml. | |||||
CVE-1999-1439 | 1 Gcc | 1 Gcc | 2016-10-17 | 2.1 LOW | N/A |
gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files. | |||||
CVE-1999-1440 | 1 Mirabilis | 1 Icq 98a | 2016-10-17 | 5.1 MEDIUM | N/A |
Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client. | |||||
CVE-1999-1441 | 1 Linux | 1 Linux Kernel | 2016-10-17 | 2.1 LOW | N/A |
Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it. | |||||
CVE-1999-1443 | 1 Micah Software | 1 Full Armor | 2016-10-17 | 4.6 MEDIUM | N/A |
Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using <CTRL><ALT><DEL> and kill the process using the task manager, (2) booting the system from a separate disk, or (3) interrupting certain processes that execute while the system is booting. | |||||
CVE-1999-1445 | 1 Slackware | 1 Slackware Linux | 2016-10-17 | 5.0 MEDIUM | N/A |
Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords. | |||||
CVE-1999-1448 | 1 Qualcomm | 2 Eudora, Eudora Light | 2016-10-17 | 5.0 MEDIUM | N/A |
Eudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user's mailbox via an e-mail message with certain dates, such as (1) dates before 1970, which cause a Divide By Zero error, or (2) dates that are 100 years after the current date, which causes a segmentation fault. | |||||
CVE-1999-1454 | 1 Macromedia | 1 Matrix Screen Saver | 2016-10-17 | 4.6 MEDIUM | N/A |
Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key. |