CVE Database

Search and browse vulnerability records from NVD

Showing 50 of 176157 CVEs

CVE ID Severity Description EPSS Published
N/A

Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).

0.6% 1999-08-22
N/A

Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.

1.3% 1999-08-22
N/A

pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.

0.5% 1999-08-21
N/A

The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.

18.0% 1999-08-21
N/A

Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.

3.1% 1999-08-20
N/A

The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.

7.0% 1999-08-20
N/A

Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

0.1% 1999-08-20
N/A

Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.

0.0% 1999-08-20
N/A

Trn allows local users to overwrite other users' files via symlinks.

0.1% 1999-08-20
N/A

QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.

0.7% 1999-08-19
N/A

Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.

0.7% 1999-08-19
N/A

A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.

0.8% 1999-08-19
N/A

The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.

0.1% 1999-08-19
N/A

When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".

32.2% 1999-08-19
N/A

Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.

0.1% 1999-08-18
N/A

Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.

25.8% 1999-08-18
N/A

The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.

3.2% 1999-08-17
N/A

dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.

0.4% 1999-08-16
N/A

Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.

20.9% 1999-08-16
N/A

A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.

6.0% 1999-08-16
N/A

Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.

8.0% 1999-08-13
N/A

3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.

0.7% 1999-08-12
N/A

Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.

0.1% 1999-08-12
N/A

DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.

39.1% 1999-08-11
N/A

Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.

19.4% 1999-08-11
N/A

Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.

5.5% 1999-08-11
N/A

Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.

0.9% 1999-08-11
N/A

Denial of service in AIX ptrace system call allows local users to crash the system.

0.1% 1999-08-11
N/A

Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.

0.1% 1999-08-10
N/A

Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.

6.0% 1999-08-09
N/A

sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.

0.1% 1999-08-09
N/A

Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.

0.6% 1999-08-09
N/A

The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.

0.4% 1999-08-09
N/A

The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.

0.9% 1999-08-08
N/A

Buffer overflow in ALMail32 POP3 client via From: or To: headers.

5.8% 1999-08-08
N/A

FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.

0.6% 1999-08-07
N/A

A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.

0.6% 1999-08-06
N/A

Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.

14.4% 1999-08-06
N/A

dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.

4.3% 1999-08-05
N/A

The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.

0.1% 1999-08-05
N/A

OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.

0.1% 1999-08-03
N/A

The WebRamp web administration utility has a default password.

0.5% 1999-08-03
N/A

Buffer overflow in ToxSoft NextFTP client through CWD command.

5.8% 1999-08-03
N/A

FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.

0.1% 1999-08-01
N/A

Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.

5.8% 1999-08-01
N/A

.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.

0.1% 1999-07-30
N/A

Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.

0.1% 1999-07-30
N/A

Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.

7.0% 1999-07-30
N/A

Denial of service in Gauntlet Firewall via a malformed ICMP packet.

5.5% 1999-07-30
N/A

WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.

1.0% 1999-07-29