CVE-1999-0 to CVE-1999-999
311 CVEs with public proof-of-concept exploits.
- CVE-1999-00011 PoCip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.
- CVE-1999-00021 PoCBuffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
- CVE-1999-00032 PoCsExecute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
- CVE-1999-00051 PoCArbitrary command execution via IMAP buffer overflow in authenticate command.
- CVE-1999-00062 PoCsBuffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.
- CVE-1999-00092 PoCsInverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
- CVE-1999-00141 PoCUnauthorized privileged access or denial of service via dtappgather program in CDE.
- CVE-1999-00151 PoCTeardrop IP denial of service.
- CVE-1999-00167 PoCsLand IP denial of service.
- CVE-1999-00181 PoCBuffer overflow in statd allows root privileges.
- CVE-1999-00211 PoCArbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.
- CVE-1999-00231 PoCLocal user gains root privileges via buffer overflow in rdist, via lookup() function.
- CVE-1999-00251 PoCroot privileges via buffer overflow in df command on SGI IRIX systems.
- CVE-1999-00261 PoCroot privileges via buffer overflow in pset command on SGI IRIX systems.
- CVE-1999-00273 PoCsroot privileges via buffer overflow in eject command on SGI IRIX systems.
- CVE-1999-00291 PoCroot privileges via buffer overflow in ordist command on SGI IRIX systems.
- CVE-1999-00302 PoCsroot privileges via buffer overflow in xlock command on SGI IRIX systems.
- CVE-1999-00322 PoCsBuffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C…
- CVE-1999-00344 PoCsBuffer overflow in suidperl (sperl), Perl 4.x and 5.x.
- CVE-1999-00362 PoCsIRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.
- CVE-1999-00382 PoCsBuffer overflow in xlock program allows local users to execute commands as root.
- CVE-1999-00391 PoCwebdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-1999-00405 PoCsBuffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
- CVE-1999-00412 PoCsBuffer overflow in NLS (Natural Language Service).
- CVE-1999-00421 PoCBuffer overflow in University of Washington's implementation of IMAP and POP servers.
- CVE-1999-00441 PoCfsdump command in IRIX allows local users to obtain root access by modifying sensitive files.
- CVE-1999-00451 PoCList of arbitrary files on Web host via nph-test-cgi script.
- CVE-1999-00461 PoCBuffer overflow of rlogin program using TERM environmental variable.
- CVE-1999-00501 PoCBuffer overflow in HP-UX newgrp program.
- CVE-1999-00513 PoCsArbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
- CVE-1999-00602 PoCsAttackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by…
- CVE-1999-00631 PoCCisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.
- CVE-1999-00641 PoCBuffer overflow in AIX lquerylv program gives root access to local users.
- CVE-1999-00661 PoCAnyForm CGI remote execution.
- CVE-1999-00671 PoCphf CGI program allows remote command execution through shell metacharacters.
- CVE-1999-00681 PoCCGI PHP mylog script allows an attacker to read any file on the target server.
- CVE-1999-00692 PoCsSolaris ufsrestore buffer overflow.
- CVE-1999-00701 PoCtest-cgi program allows an attacker to list files on the server.
- CVE-1999-00771 PoCPredictable TCP sequence numbers allow spoofing.
- CVE-1999-00921 PoCVarious vulnerabilities in the AIX portmir command allows local users to obtain root access.
- CVE-1999-00953 PoCsThe debug command in Sendmail is enabled, allowing attackers to execute commands as root.
- CVE-1999-01011 PoCBuffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
- CVE-1999-01031 PoCEcho and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.
- CVE-1999-01071 PoCBuffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests…
- CVE-1999-01081 PoCThe printers program in IRIX has a buffer overflow that gives root access to local users.
- CVE-1999-01091 PoCBuffer overflow in ffbconfig in Solaris 2.5.1.
- CVE-1999-01121 PoCBuffer overflow in AIX dtterm program for the CDE.
- CVE-1999-01131 PoCSome implementations of rlogin allow root access if given a -froot parameter.
- CVE-1999-01151 PoCAIX bugfiler program allows local users to gain root access.
- CVE-1999-01161 PoCDenial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the…
- CVE-1999-01181 PoCAIX infod allows local users to gain root access through an X display.
- CVE-1999-01221 PoCBuffer overflow in AIX lchangelv gives root access.
- CVE-1999-01252 PoCsBuffer overflow in SGI IRIX mailx program.
- CVE-1999-01261 PoCSGI IRIX buffer overflow in xterm and Xaw allows root access.
- CVE-1999-01281 PoCOversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
- CVE-1999-01301 PoCLocal users can start Sendmail in daemon mode and gain root privileges.
- CVE-1999-01372 PoCsThe dip program on many Linux systems allows local users to gain root access via a buffer overflow.
- CVE-1999-01401 PoCDenial of service in RAS/PPTP on NT systems.
- CVE-1999-01442 PoCsDenial of service in Qmail by specifying a large number of recipients with the RCPT command.
- CVE-1999-01452 PoCsSendmail WIZ command enabled, allowing root access.
- CVE-1999-01461 PoCThe campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return…
- CVE-1999-01471 PoCThe aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.
- CVE-1999-01481 PoCThe handler CGI program in IRIX allows arbitrary command execution.
- CVE-1999-01491 PoCThe wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.
- CVE-1999-01534 PoCsWindows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
- CVE-1999-01541 PoCIIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
- CVE-1999-01731 PoCFormMail CGI program can be used by web servers other than the host server that the program resides on.
- CVE-1999-01741 PoCThe view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-1999-01751 PoCThe convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by…
- CVE-1999-01761 PoCThe Webgais program allows a remote user to execute arbitrary commands.
- CVE-1999-01781 PoCBuffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary…
- CVE-1999-01821 PoCSamba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.
- CVE-1999-01911 PoCIIS newdsn.exe CGI script allows remote users to overwrite files.
- CVE-1999-01922 PoCsBuffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
- CVE-1999-01932 PoCsDenial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.
- CVE-1999-01961 PoCwebsendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter…
- CVE-1999-02041 PoCSendmail 8.6.9 allows remote attackers to execute root commands, using ident.
- CVE-1999-02071 PoCRemote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.
- CVE-1999-02082 PoCsrpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
- CVE-1999-02094 PoCsThe SunView (SunTools) selection_svc facility allows remote users to read files.
- CVE-1999-02102 PoCsAutomount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
- CVE-1999-02151 PoCRouted allows attackers to append data to files.
- CVE-1999-02191 PoCBuffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS…
- CVE-1999-02241 PoCDenial of service in Windows NT messenger service through a long username.
- CVE-1999-02331 PoCIIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
- CVE-1999-02352 PoCsBuffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
- CVE-1999-02361 PoCScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
- CVE-1999-02381 PoCphp.cgi allows attackers to read any file on the system.
- CVE-1999-02391 PoCNetscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.
- CVE-1999-02564 PoCsBuffer overflow in War FTP allows remote execution of commands.
- CVE-1999-02621 PoCHylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
- CVE-1999-02641 PoChtmlscript CGI program allows remote read access to files.
- CVE-1999-02662 PoCsThe info2www CGI script allows remote file access or remote command execution.
- CVE-1999-02673 PoCsBuffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.
- CVE-1999-02681 PoCMetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
- CVE-1999-02691 PoCNetscape Enterprise servers may list files through the PageServices query.
- CVE-1999-02781 PoCIn IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
- CVE-1999-02811 PoCDenial of service in IIS using long URLs.
- CVE-1999-02831 PoCThe Java Web Server would allow remote users to obtain the source code for CGI programs.
- CVE-1999-02843 PoCsDenial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
- CVE-1999-02872 PoCsVulnerability in the Wguest CGI program.
- CVE-1999-02881 PoCThe WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via…
- CVE-1999-02941 PoCAll records in a WINS database can be deleted through SNMP for a denial of service.
- CVE-1999-03011 PoCBuffer overflow in SunOS/Solaris ps command.
- CVE-1999-03062 PoCsbuffer overflow in HP xlock program.
- CVE-1999-03141 PoCioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.
- CVE-1999-03151 PoCBuffer overflow in Solaris fdformat command gives root access to local users.
- CVE-1999-03212 PoCsBuffer overflow in Solaris kcms_configure command allows local users to gain root access.
- CVE-1999-03281 PoCSGI permissions program allows local users to gain root privileges.
- CVE-1999-03471 PoCInternet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript…
- CVE-1999-03491 PoCA buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute…
- CVE-1999-03501 PoCRace condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.
- CVE-1999-03601 PoCMS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute…
- CVE-1999-03631 PoCSuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.
- CVE-1999-03682 PoCsBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
- CVE-1999-03691 PoCThe Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
- CVE-1999-03721 PoCThe installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
- CVE-1999-03761 PoCLocal users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
- CVE-1999-03811 PoCsuper 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.
- CVE-1999-03821 PoCThe screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs…
- CVE-1999-03861 PoCMicrosoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the…
- CVE-1999-03881 PoCDataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
- CVE-1999-03931 PoCRemote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
- CVE-1999-04001 PoCDenial of service in Linux 2.2.0 running the ldd command on a core file.
- CVE-1999-04041 PoCBuffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.
- CVE-1999-04052 PoCsA buffer overflow in lsof allows local users to obtain root privilege.
- CVE-1999-04091 PoCBuffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.
- CVE-1999-04101 PoCThe cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.
- CVE-1999-04121 PoCIn IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
- CVE-1999-04141 PoCIn Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully…
- CVE-1999-04161 PoCVulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET…
- CVE-1999-04171 PoC64 bit Solaris 7 procfs allows local users to perform a denial of service.
- CVE-1999-04261 PoCThe default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
- CVE-1999-04311 PoCLinux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.
- CVE-1999-04331 PoCXFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly…
- CVE-1999-04411 PoCRemote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.
- CVE-1999-04421 PoCSolaris ff.core allows local users to modify files.
- CVE-1999-04481 PoCIIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really…
- CVE-1999-04501 PoCIn IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
- CVE-1999-04511 PoCDenial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.
- CVE-1999-04551 PoCThe Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm,…
- CVE-1999-04601 PoCBuffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.
- CVE-1999-04672 PoCsThe Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter.
- CVE-1999-04701 PoCA weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.
- CVE-1999-04771 PoCThe Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm,…
- CVE-1999-04871 PoCThe DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.
- CVE-1999-04911 PoCThe prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to…
- CVE-1999-04921 PoCThe ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.
- CVE-1999-04931 PoCrpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn…
- CVE-1999-04971 PoCAnonymous FTP is enabled.
- CVE-1999-05022 PoCsA Unix account has a default, null, blank, or missing password.
- CVE-1999-05042 PoCsA Windows NT local user or administrator account has a default, null, blank, or missing password.
- CVE-1999-05061 PoCA Windows NT domain user or administrator account has a default, null, blank, or missing password.
- CVE-1999-05121 PoCA mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
- CVE-1999-05131 PoCICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
- CVE-1999-05171 PoCAn SNMP community name is the default (e.g. public), null, or missing.
- CVE-1999-05243 PoCsICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.
- CVE-1999-05261 PoCAn X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
- CVE-1999-05321 PoCA DNS server allows zone transfers.
- CVE-1999-05621 PoCThe registry in Windows NT can be accessed remotely by users who are not administrators.
- CVE-1999-06511 PoCThe rsh/rlogin service is running.
- CVE-1999-06611 PoCA system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP…
- CVE-1999-06671 PoCThe ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.
- CVE-1999-06681 PoCThe scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute…
- CVE-1999-06691 PoCThe Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary…
- CVE-1999-06711 PoCBuffer overflow in ToxSoft NextFTP client through CWD command.
- CVE-1999-06721 PoCBuffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.
- CVE-1999-06731 PoCBuffer overflow in ALMail32 POP3 client via From: or To: headers.
- CVE-1999-06741 PoCThe BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
- CVE-1999-06782 PoCsA default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation…
- CVE-1999-06791 PoCBuffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.
- CVE-1999-06811 PoCBuffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, allows remote…
- CVE-1999-06831 PoCDenial of service in Gauntlet Firewall via a malformed ICMP packet.
- CVE-1999-06851 PoCBuffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
- CVE-1999-06891 PoCThe CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
- CVE-1999-06911 PoCBuffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
- CVE-1999-06931 PoCBuffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.
- CVE-1999-06962 PoCsBuffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
- CVE-1999-07001 PoCBuffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
- CVE-1999-07021 PoCInternet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the…
- CVE-1999-07042 PoCsBuffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.
- CVE-1999-07051 PoCBuffer overflow in INN inews program.
- CVE-1999-07081 PoCBuffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.
- CVE-1999-07101 PoCThe Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows…
- CVE-1999-07111 PoCThe oratclsh interpreter in Oracle 8.x Intelligent Agent for Unix allows local users to execute Tcl commands as root.
- CVE-1999-07151 PoCBuffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed…
- CVE-1999-07161 PoCBuffer overflow in Windows NT 4.0 help file utility via a malformed help file.
- CVE-1999-07181 PoCIBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing…
- CVE-1999-07201 PoCThe pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.
- CVE-1999-07251 PoCWhen IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain…
- CVE-1999-07301 PoCThe zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.
- CVE-1999-07331 PoCBuffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.
- CVE-1999-07351 PoCKDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.
- CVE-1999-07361 PoCThe showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
- CVE-1999-07443 PoCsBuffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.
- CVE-1999-07451 PoCBuffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
- CVE-1999-07461 PoCA default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of…
- CVE-1999-07491 PoCBuffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
- CVE-1999-07501 PoCHotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail…
- CVE-1999-07511 PoCBuffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.
- CVE-1999-07521 PoCDenial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.
- CVE-1999-07531 PoCThe w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.
- CVE-1999-07551 PoCWindows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
- CVE-1999-07571 PoCThe ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.
- CVE-1999-07591 PoCBuffer overflow in FuseMAIL POP service via long USER and PASS commands.
- CVE-1999-07651 PoCSGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.
- CVE-1999-07675 PoCsBuffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
- CVE-1999-07682 PoCsBuffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
- CVE-1999-07691 PoCVixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
- CVE-1999-07701 PoCFirewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial…
- CVE-1999-07711 PoCThe web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot…
- CVE-1999-07731 PoCBuffer overflow in Solaris lpset program allows local users to gain root access.
- CVE-1999-07741 PoCBuffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.
- CVE-1999-07781 PoCBuffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.
- CVE-1999-07861 PoCThe dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
- CVE-1999-07871 PoCThe SSH authentication agent follows symlinks via a UNIX domain socket.
- CVE-1999-07891 PoCBuffer overflow in AIX ftpd in the libc library.
- CVE-1999-07911 PoCHybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the…
- CVE-1999-07931 PoCInternet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
- CVE-1999-08001 PoCThe GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.
- CVE-1999-08031 PoCThe fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.
- CVE-1999-08041 PoCDenial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.
- CVE-1999-08061 PoCBuffer overflow in Solaris dtprintinfo program.
- CVE-1999-08111 PoCBuffer overflow in Samba smbd program via a malformed message command.
- CVE-1999-08181 PoCBuffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
- CVE-1999-08191 PoCNTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
- CVE-1999-08201 PoCFreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.
- CVE-1999-08212 PoCsFreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.
- CVE-1999-08222 PoCsBuffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.
- CVE-1999-08231 PoCBuffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.
- CVE-1999-08251 PoCThe default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
- CVE-1999-08261 PoCBuffer overflow in FreeBSD angband allows local users to gain privileges.
- CVE-1999-08283 PoCsUnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.
- CVE-1999-08301 PoCBuffer overflow in SCO UnixWare Xsco command via a long argument.
- CVE-1999-08341 PoCBuffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.
- CVE-1999-08362 PoCsUnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
- CVE-1999-08381 PoCBuffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.
- CVE-1999-08411 PoCBuffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.
- CVE-1999-08421 PoCSymantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.
- CVE-1999-08442 PoCsDenial of service in MDaemon WorldClient and WebConfig services via a long URL.
- CVE-1999-08451 PoCBuffer overflow in SCO su program allows local users to gain root access via a long username.
- CVE-1999-08481 PoCDenial of service in BIND named via consuming more than "fdmax" file descriptors.
- CVE-1999-08551 PoCBuffer overflow in FreeBSD gdc program.
- CVE-1999-08571 PoCFreeBSD gdc program allows local users to modify files via a symlink attack.
- CVE-1999-08591 PoCSolaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
- CVE-1999-08601 PoCSolaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
- CVE-1999-08641 PoCUnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.
- CVE-1999-08661 PoCBuffer overflow in UnixWare xauto program allows local users to gain root privilege.
- CVE-1999-08671 PoCDenial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
- CVE-1999-08691 PoCInternet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.
- CVE-1999-08731 PoCBuffer overflow in Skyfull mail server via MAIL FROM command.
- CVE-1999-08746 PoCsBuffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM…
- CVE-1999-08751 PoCDHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
- CVE-1999-08771 PoCInternet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.
- CVE-1999-08791 PoCBuffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.
- CVE-1999-08851 PoCAlibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.
- CVE-1999-08861 PoCThe security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
- CVE-1999-08871 PoCFTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.
- CVE-1999-08882 PoCsdbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp…
- CVE-1999-08911 PoCThe "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.
- CVE-1999-08931 PoCuserOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.
- CVE-1999-08962 PoCsBuffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long…
- CVE-1999-08991 PoCThe Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to…
- CVE-1999-09041 PoCBuffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.
- CVE-1999-09051 PoCDenial of service in Axent Raptor firewall via malformed zero-length IP options.
- CVE-1999-09061 PoCBuffer overflow in sccw allows local users to gain root access via the HOME environmental variable.
- CVE-1999-09081 PoCDenial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls…
- CVE-1999-09112 PoCsBuffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that…
- CVE-1999-09121 PoCFreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.
- CVE-1999-09131 PoCdfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.
- CVE-1999-09141 PoCBuffer overflow in the FTP client in the Debian GNU/Linux netstd package.
- CVE-1999-09151 PoCURL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-1999-09183 PoCsDenial of service in various Windows systems via malformed, fragmented IGMP packets.
- CVE-1999-09202 PoCsBuffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.
- CVE-1999-09251 PoCUnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.
- CVE-1999-09261 PoCApache allows remote attackers to conduct a denial of service via a large number of MIME headers.
- CVE-1999-09271 PoCNTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-1999-09281 PoCBuffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.
- CVE-1999-09311 PoCBuffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.
- CVE-1999-09331 PoCTeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-1999-09341 PoCclassifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.
- CVE-1999-09351 PoCclassifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.
- CVE-1999-09431 PoCBuffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.
- CVE-1999-09441 PoCIBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.
- CVE-1999-09461 PoCBuffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.
- CVE-1999-09471 PoCAN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands…
- CVE-1999-09481 PoCBuffer overflow in uum program for Canna input system allows local users to gain root privileges.
- CVE-1999-09491 PoCBuffer overflow in canuum program for Canna input system allows local users to gain root privileges.
- CVE-1999-09502 PoCsBuffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested…
- CVE-1999-09511 PoCBuffer overflow in OmniHTTPd CGI program imagemap.exe allows remote attackers to execute commands.
- CVE-1999-09531 PoCWWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.
- CVE-1999-09591 PoCIRIX startmidi program allows local users to modify arbitrary files via a symlink attack.
- CVE-1999-09601 PoCIRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.
- CVE-1999-09683 PoCsBuffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
- CVE-1999-09702 PoCsThe OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number…
- CVE-1999-09712 PoCsBuffer overflow in Exim allows local users to gain root privileges via a long :include: option in a .forward file.
- CVE-1999-09721 PoCBuffer overflow in Xshipwars xsw program.
- CVE-1999-09731 PoCBuffer overflow in Solaris snoop program allows remote attackers to gain root privileges via a long domain name when snoop is running in…
- CVE-1999-09751 PoCThe Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT…
- CVE-1999-09775 PoCsBuffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
- CVE-1999-09791 PoCThe SCO UnixWare privileged process system allows local users to gain root privileges by using a debugger such as gdb to insert traps into…
- CVE-1999-09802 PoCsWindows NT Service Control Manager (SCM) allows remote attackers to cause a denial of service via a malformed argument in a resource…
- CVE-1999-09811 PoCInternet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to…
- CVE-1999-09851 PoCCC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.
- CVE-1999-09861 PoCThe ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.
- CVE-1999-09881 PoCUnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.
- CVE-1999-09891 PoCBuffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio…
- CVE-1999-09911 PoCBuffer overflow in GoodTech Telnet Server NT allows remote users to cause a denial of service via a long login name.
- CVE-1999-09961 PoCBuffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.
- CVE-1999-09971 PoCwu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to…
- CVE-1999-09991 PoCMicrosoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.