Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-1999-1349 | 1 Xlink Technology | 1 Omni-nfs X Enterprise | 2016-10-17 | 5.0 MEDIUM | N/A |
NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111. | |||||
CVE-1999-1350 | 1 Arcad Systemhaus | 1 Arcad | 2016-10-17 | 4.6 MEDIUM | N/A |
ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse. | |||||
CVE-1999-1351 | 1 Kvirc | 1 Irc Client | 2016-10-17 | 5.0 MEDIUM | N/A |
Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick <soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request. | |||||
CVE-1999-1352 | 1 Linux | 1 Linux Kernel | 2016-10-17 | 4.6 MEDIUM | N/A |
mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges. | |||||
CVE-1999-1354 | 1 Softarc | 1 Firstclass Internet Server | 2016-10-17 | 4.6 MEDIUM | N/A |
E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled. | |||||
CVE-1999-1356 | 1 Compaq | 1 Smartstart | 2016-10-17 | 4.6 MEDIUM | N/A |
Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy. | |||||
CVE-1999-1357 | 1 Netscape | 1 Communicator | 2016-10-17 | 7.5 HIGH | N/A |
Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters. | |||||
CVE-1999-1361 | 1 Microsoft | 1 Windows Nt | 2016-10-17 | 6.4 MEDIUM | N/A |
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages. | |||||
CVE-1999-1366 | 1 David Harris | 1 Pegasus Mail | 2016-10-17 | 3.6 LOW | N/A |
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail. | |||||
CVE-1999-1369 | 1 Realnetworks | 1 Realserver | 2016-10-17 | 4.6 MEDIUM | N/A |
Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges. | |||||
CVE-1999-1372 | 1 Triactive | 1 Remote Management | 2016-10-17 | 4.6 MEDIUM | N/A |
Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges. | |||||
CVE-1999-1373 | 1 Fore | 1 Powerhub Software | 2016-10-17 | 5.0 MEDIUM | N/A |
FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap. | |||||
CVE-1999-1374 | 1 Arpanet | 1 Perlshop | 2016-10-17 | 5.0 MEDIUM | N/A |
perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request. | |||||
CVE-1999-1375 | 1 Microsoft | 1 Internet Information Server | 2016-10-17 | 5.0 MEDIUM | N/A |
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. | |||||
CVE-1999-1376 | 1 Microsoft | 1 Internet Information Server | 2016-10-17 | 10.0 HIGH | N/A |
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. | |||||
CVE-1999-1378 | 1 Dbmlparser.exe | 1 Dbmlparser.exe | 2016-10-17 | 5.0 MEDIUM | N/A |
dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files. | |||||
CVE-1999-1379 | 1 Dnstools Software | 1 Dnstools | 2016-10-17 | 5.0 MEDIUM | N/A |
DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker. | |||||
CVE-1999-1381 | 1 Dbadmin | 1 Dbadmin | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands. | |||||
CVE-1999-1382 | 1 Novell | 1 Netware | 2016-10-17 | 7.2 HIGH | N/A |
NetWare NFS mode 1 and 2 implements the "Read Only" flag in Unix by changing the ownership of a file to root, which allows local users to gain root privileges by creating a setuid program and setting it to "Read Only," which NetWare-NFS changes to a setuid root program. | |||||
CVE-1999-1383 | 2 Gnu, Tcsh | 2 Bash, Tcsh | 2016-10-17 | 4.6 MEDIUM | N/A |
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable. |