CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 93578 CVEs

CVE ID Severity Description EPSS Published
N/A

Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.

1.3% 1999-01-28
N/A

Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.

0.7% 1999-01-27
N/A

A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.

11.2% 1999-01-27
N/A

IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.

13.2% 1999-01-27
N/A

In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

25.3% 1999-01-26
N/A

The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.

36.2% 1999-01-26
N/A

Denial of service in Linux 2.2.0 running the ldd command on a core file.

1.0% 1999-01-26
N/A

Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.

3.2% 1999-01-26
N/A

Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.

0.0% 1999-01-25
N/A

Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.

7.3% 1999-01-25
N/A

ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.

0.3% 1999-01-25
N/A

ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.

0.0% 1999-01-25
N/A

Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.

6.8% 1999-01-24
N/A

WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.

0.6% 1999-01-21
N/A

Buffer overflow in dtaction command gives root access.

0.1% 1999-01-21
N/A

Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.

0.4% 1999-01-19
N/A

Windows NT 4.0 beta allows users to read and delete shares.

11.7% 1999-01-19
N/A

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

20.4% 1999-01-17
N/A

Linux ftpwatch program allows local users to gain root privileges.

0.1% 1999-01-17
N/A

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.

50.3% 1999-01-14
N/A

Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

47.3% 1999-01-14
N/A

By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.

0.6% 1999-01-14
N/A

Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.

12.1% 1999-01-11
N/A

Buffer overflow in Thomas Boutell's cgic library version up to 1.05.

0.6% 1999-01-10
N/A

Solaris ff.core allows local users to modify files.

0.2% 1999-01-07
N/A

Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.

0.1% 1999-01-06
N/A

L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.

0.1% 1999-01-06
N/A

The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.

4.5% 1999-01-05
N/A

Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.

0.1% 1999-01-04
N/A

Buffer overflow in Dosemu Slang library in Linux.

0.1% 1999-01-04
N/A

search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.

3.6% 1999-01-03
N/A

Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.

0.9% 1999-01-03
N/A

Buffer overflow in the bootp server in the Debian Linux netstd package.

0.1% 1999-01-03
N/A

HP-UX aserver program allows local users to gain privileges via a symlink attack.

0.1% 1999-01-02
N/A

The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.

0.1% 1999-01-02
N/A

IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

0.0% 1999-01-02
N/A

wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.

0.5% 1999-01-02
7.5 HIGH

Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.

1.4% 1999-01-01
N/A

Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.

0.7% 1999-01-01
N/A

PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.

0.1% 1999-01-01
N/A

Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.

0.5% 1999-01-01
N/A

An application-critical Windows NT registry key has an inappropriate value.

0.5% 1999-01-01
N/A

An application-critical Windows NT registry key has inappropriate permissions.

0.4% 1999-01-01
N/A

A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.

0.5% 1999-01-01
N/A

A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete.

0.5% 1999-01-01
N/A

A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.

6.4% 1999-01-01
N/A

WinGate is being used.

0.6% 1999-01-01
N/A

The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.

0.2% 1999-01-01
N/A

The OS/2 or POSIX subsystem in NT is enabled.

0.5% 1999-01-01
N/A

A component service related to NIS+ is running.

0.5% 1999-01-01