Total
281583 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-1999-1067 | 1 Sgi | 1 Irix | 2024-11-20 | N/A |
SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities. | ||||
CVE-1999-1066 | 1 Sgi | 1 Quake 1 Server | 2024-11-20 | N/A |
Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request. | ||||
CVE-1999-1065 | 1 Palm Pilot | 1 Hotsync Manager | 2024-11-20 | N/A |
Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode. | ||||
CVE-1999-1064 | 1 Windowmaker | 1 Windowmaker | 2024-11-20 | N/A |
Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]). | ||||
CVE-1999-1063 | 1 Cdomain | 1 Cdomainfree | 2024-11-20 | N/A |
CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter. | ||||
CVE-1999-1062 | 1 Hp | 1 Jetdirect | 2024-11-20 | N/A |
HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100. | ||||
CVE-1999-1061 | 1 Hp | 1 Jetdirect | 2024-11-20 | N/A |
HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging. | ||||
CVE-1999-1060 | 1 Tetrix | 1 Tetrinet | 2024-11-20 | N/A |
Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname. | ||||
CVE-1999-1059 | 1 Att | 1 Svr4 | 2024-11-20 | N/A |
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands. | ||||
CVE-1999-1058 | 1 Arcane Software | 1 Vermillion Ftp Daemon | 2024-11-20 | N/A |
Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands. | ||||
CVE-1999-1057 | 1 Digital | 1 Vms | 2024-11-20 | N/A |
VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command. | ||||
CVE-1999-1055 | 1 Microsoft | 1 Excel | 2024-11-20 | N/A |
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability." | ||||
CVE-1999-1054 | 1 Globetrotter | 1 Flexlm | 2024-11-20 | N/A |
The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command. | ||||
CVE-1999-1053 | 2 Apache, Matt Wright | 2 Http Server, Matt Wright Guestbook | 2024-11-20 | N/A |
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->". | ||||
CVE-1999-1052 | 1 Microsoft | 1 Frontpage | 2024-11-20 | N/A |
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users. | ||||
CVE-1999-1051 | 1 Matt Wright | 1 Formhandler.cgi | 2024-11-20 | N/A |
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter. | ||||
CVE-1999-1050 | 1 Matt Wright | 1 Formhandler.cgi | 2024-11-20 | N/A |
Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template. | ||||
CVE-1999-1049 | 1 Broadcom | 1 Arcserve Backup | 2024-11-20 | N/A |
ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password. | ||||
CVE-1999-1048 | 2 Debian, Redhat | 2 Debian Linux, Linux | 2024-11-20 | N/A |
Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory. | ||||
CVE-1999-1047 | 1 Bsdi | 1 Gauntlet | 2024-11-20 | N/A |
When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities. |