CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 115178 CVEs

CVE ID Severity Description EPSS Published
N/A

ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.

1.2% 1999-12-30
N/A

The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by modifying or replacing the program.

1.0% 1999-12-29
N/A

Buffer overflow in CSM mail server allows remote attackers to cause a denial of service or execute commands via a long HELO command.

1.7% 1999-12-29
N/A

AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program.

3.6% 1999-12-29
N/A

The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which allows local users to execute arbitrary commands.

0.3% 1999-12-29
N/A

Trend Micro PC-Cillin does not restrict access to its internal proxy port, allowing remote attackers to conduct a denial of service.

0.7% 1999-12-29
N/A

Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.

0.5% 1999-12-28
N/A

Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.

0.2% 1999-12-28
N/A

resend command in Majordomo allows local users to gain privileges via shell metacharacters.

0.3% 1999-12-28
N/A

Denial of service in Savant web server via a null character in the requested URL.

4.1% 1999-12-28
N/A

Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.

1.1% 1999-12-28
N/A

Buffer overflow in aVirt Rover POP3 server 1.1 allows remote attackers to cause a denial of service via a long user name.

1.0% 1999-12-27
N/A

InterScan VirusWall SMTP scanner does not properly scan messages with malformed attachments.

0.6% 1999-12-27
N/A

UnixWare pis and mkpis commands allow local users to gain privileges via a symlink attack.

0.1% 1999-12-27
N/A

IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.

1.7% 1999-12-27
N/A

Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.

4.6% 1999-12-27
N/A

WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.

5.3% 1999-12-26
N/A

FTPPro allows local users to read sensitive information, which is stored in plain text.

0.1% 1999-12-26
N/A

strace allows local users to read arbitrary files via memory mapped file names.

0.2% 1999-12-25
N/A

The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.

6.9% 1999-12-25
N/A

The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.

9.1% 1999-12-25
N/A

Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.

0.1% 1999-12-24
N/A

glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.

0.4% 1999-12-23
N/A

glFtpD includes a default glftpd user account with a default password and a UID of 0.

3.0% 1999-12-23
N/A

Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

19.2% 1999-12-23
N/A

RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.

3.9% 1999-12-23
N/A

The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection.

1.0% 1999-12-22
N/A

Outlook Express 5 for Macintosh downloads attachments to HTML mail without prompting the user, aka the "HTML Mail Attachment" vulnerability.

19.7% 1999-12-22
N/A

Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."

0.6% 1999-12-22
N/A

Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.

2.6% 1999-12-22
N/A

Solaris dmispd dmi_cmd allows local users to fill up restricted disk space by adding files to the /var/dmi/db database.

0.4% 1999-12-22
N/A

wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.

0.4% 1999-12-22
N/A

Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.

9.3% 1999-12-22
N/A

Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.

7.7% 1999-12-22
N/A

Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.

0.7% 1999-12-22
N/A

Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password authorization string.

8.0% 1999-12-21
N/A

IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.

46.0% 1999-12-21
N/A

IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.

12.0% 1999-12-21
N/A

Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.

0.7% 1999-12-21
N/A

Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.

0.6% 1999-12-21
N/A

Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.

3.4% 1999-12-21
N/A

Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.

0.5% 1999-12-21
N/A

DNS PRO allows remote attackers to conduct a denial of service via a large number of connections.

0.7% 1999-12-20
N/A

wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.

3.8% 1999-12-20
N/A

Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.

0.3% 1999-12-19
N/A

Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.

1.7% 1999-12-19
N/A

Buffer overflow in the POP server POProxy for the Norton Anti-Virus protection NAV2000 program via a large USER command.

0.7% 1999-12-16
N/A

Cisco Cache Engine allows a remote attacker to gain access via a null username and password.

0.3% 1999-12-16
N/A

The web administration interface for Cisco Cache Engine allows remote attackers to view performance statistics.

0.4% 1999-12-16
N/A

Cisco Cache Engine allows an attacker to replace content in the cache.

0.6% 1999-12-16