Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 299 025

Количество 299 025

nvd логотип

CVE-1999-1424

больше 27 лет назад

Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-1999-1423

около 28 лет назад

ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1422

больше 26 лет назад

The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1421

почти 27 лет назад

NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-1999-1420

почти 27 лет назад

NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-1999-1419

почти 28 лет назад

Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1418

около 26 лет назад

ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1417

почти 27 лет назад

Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1416

почти 27 лет назад

AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1415

почти 34 года назад

Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1414

около 26 лет назад

IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1413

почти 29 лет назад

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1412

около 26 лет назад

A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-1999-1411

больше 26 лет назад

The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1410

около 28 лет назад

addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-1999-1409

почти 27 лет назад

The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1408

больше 28 лет назад

Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1407

больше 27 лет назад

ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1406

почти 27 лет назад

dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1405

больше 26 лет назад

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-1999-1424

Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.

CVSS2: 6.2
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1423

ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.

CVSS2: 2.1
0%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1422

The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.

CVSS2: 7.2
0%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1421

NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.

CVSS2: 6.4
1%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1420

NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.

CVSS2: 10
2%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1419

Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.

CVSS2: 7.2
0%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1418

ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").

CVSS2: 5
1%
Низкий
около 26 лет назад
nvd логотип
CVE-1999-1417

Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.

CVSS2: 7.5
1%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1416

AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.

CVSS2: 5
1%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1415

Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
почти 34 года назад
nvd логотип
CVE-1999-1414

IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

CVSS2: 7.2
1%
Низкий
около 26 лет назад
nvd логотип
CVE-1999-1413

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

CVSS2: 4.6
0%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1412

A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

CVSS2: 5
12%
Средний
около 26 лет назад
nvd логотип
CVE-1999-1411

The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.

CVSS2: 7.5
1%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1410

addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.

CVSS2: 6.2
0%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1409

The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.

CVSS2: 2.1
0%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1408

Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

CVSS2: 2.1
0%
Низкий
больше 28 лет назад
nvd логотип
CVE-1999-1407

ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

CVSS2: 2.1
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1406

dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.

CVSS2: 2.1
0%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1405

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

CVSS2: 10
4%
Низкий
больше 26 лет назад

Уязвимостей на страницу