CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 93710 CVEs

CVE ID Severity Description EPSS Published
N/A

The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.

2.4% 1999-12-08
N/A

Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect."

4.6% 1999-12-08
N/A

Sendmail allows local users to reinitialize the aliases database via the newaliases command, then cause a denial of service by interrupting Sendmail.

0.1% 1999-12-07
N/A

Buffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in verbose mode.

7.3% 1999-12-07
N/A

Buffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.

6.4% 1999-12-06
N/A

Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.

7.0% 1999-12-06
N/A

Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.

0.1% 1999-12-05
N/A

The Sun Web-Based Enterprise Management (WBEM) installation script stores a password in plaintext in a world readable file.

0.1% 1999-12-05
N/A

UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.

0.4% 1999-12-04
N/A

ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.

0.7% 1999-12-03
N/A

ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.

0.4% 1999-12-03
N/A

Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.

0.2% 1999-12-03
N/A

Buffer overflow in UnixWare xauto program allows local users to gain root privilege.

0.6% 1999-12-03
N/A

Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port.

0.6% 1999-12-03
N/A

UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.

0.5% 1999-12-03
N/A

The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.

0.3% 1999-12-03
N/A

dump in Debian GNU/Linux 2.1 does not properly restore symlinks, which allows a local user to modify the ownership of arbitrary files.

0.1% 1999-12-02
N/A

Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.

0.1% 1999-12-02
N/A

Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server.

11.9% 1999-12-02
N/A

IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.

0.0% 1999-12-02
N/A

The default permissions for Endymion MailMan allow local users to read email or modify files.

0.1% 1999-12-02
N/A

UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.

0.4% 1999-12-02
N/A

Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.

0.6% 1999-12-01
N/A

ZBServer Pro allows remote attackers to read source code for executable files by inserting a . (dot) into the URL.

0.6% 1999-12-01
N/A

FreeBSD mount_union command allows local users to gain root privileges via a symlink attack.

0.1% 1999-12-01
N/A

Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.

0.3% 1999-12-01
N/A

Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.

0.3% 1999-12-01
N/A

FreeBSD gdc program allows local users to modify files via a symlink attack.

0.4% 1999-12-01
N/A

login in Slackware 7.0 allows remote attackers to identify valid users on the system by reporting an encryption error when an account is locked or does not exist.

0.2% 1999-12-01
N/A

Buffer overflow in FreeBSD gdc program.

1.1% 1999-12-01
N/A

Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.

0.9% 1999-12-01
N/A

Denial of service in MDaemon 2.7 via a large number of connection attempts.

0.5% 1999-12-01
N/A

Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.

6.4% 1999-12-01
N/A

Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.

3.2% 1999-12-01
N/A

Buffer overflow in FreeBSD angband allows local users to gain privileges.

0.4% 1999-12-01
N/A

Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.

0.4% 1999-12-01
N/A

FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.

0.9% 1999-12-01
N/A

NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.

56.5% 1999-12-01
N/A

Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.

0.3% 1999-11-30
N/A

Buffer overflow in CDE dtmail and dtmailpr programs allows local users to gain privileges via a long -f option.

0.2% 1999-11-30
N/A

A Windows NT user can use SUBST to map a drive letter to a folder, which is not unmapped after the user logs off, potentially allowing that user to modify the location of folders accessed by later users.

0.3% 1999-11-30
N/A

Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.

7.2% 1999-11-30
N/A

Buffer overflow in free internet chess server (FICS) program, xboard.

0.5% 1999-11-29
N/A

Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.

3.8% 1999-11-29
N/A

Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.

0.8% 1999-11-29
N/A

A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.

19.4% 1999-11-29
N/A

Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.

0.6% 1999-11-25
N/A

Buffer overflow in SCO su program allows local users to gain root access via a long username.

0.2% 1999-11-25
N/A

Buffer overflow in Linux su command gives root access to local users.

0.2% 1999-11-25
N/A

Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit.

0.5% 1999-11-24