Количество 299 017
Количество 299 017

CVE-1999-1296
Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.

CVE-1999-1295
Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.

CVE-1999-1294
Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission.

CVE-1999-1293
mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.

CVE-1999-1292
Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL.

CVE-1999-1291
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.

CVE-1999-1290
Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.

CVE-1999-1289
ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.

CVE-1999-1288
Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program.

CVE-1999-1287
Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface.

CVE-1999-1286
addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.

CVE-1999-1285
Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.

CVE-1999-1284
NukeNabber allows remote attackers to cause a denial of service by connecting to the NukeNabber port (1080) without sending any data, which causes the CPU usage to rise to 100% from the report.exe program that is executed upon the connection.

CVE-1999-1283
Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.

CVE-1999-1282
RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.

CVE-1999-1281
Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.

CVE-1999-1280
Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.

CVE-1999-1279
An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.

CVE-1999-1278
nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.

CVE-1999-1277
BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-1999-1296 Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable. | CVSS2: 7.2 | 0% Низкий | около 28 лет назад |
![]() | CVE-1999-1295 Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS. | CVSS2: 4.6 | 0% Низкий | почти 29 лет назад |
![]() | CVE-1999-1294 Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission. | CVSS2: 2.1 | 1% Низкий | больше 25 лет назад |
![]() | CVE-1999-1293 mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core. | CVSS2: 10 | 1% Низкий | больше 25 лет назад |
![]() | CVE-1999-1292 Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL. | CVSS2: 7.5 | 1% Низкий | почти 27 лет назад |
![]() | CVE-1999-1291 TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target. | CVSS2: 5 | 9% Низкий | больше 26 лет назад |
![]() | CVE-1999-1290 Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string. | CVSS2: 5.1 | 1% Низкий | больше 25 лет назад |
![]() | CVE-1999-1289 ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration. | CVSS2: 7.5 | 1% Низкий | больше 26 лет назад |
![]() | CVE-1999-1288 Samba 1.9.18 inadvertently includes a prototype application, wsmbconf, which is installed with incorrect permissions including the setgid bit, which allows local users to read and write files and possibly gain privileges via bugs in the program. | CVSS2: 4.6 | 0% Низкий | больше 26 лет назад |
![]() | CVE-1999-1287 Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface. | CVSS2: 5 | 1% Низкий | больше 25 лет назад |
![]() | CVE-1999-1286 addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file. | CVSS2: 7.2 | 0% Низкий | около 28 лет назад |
![]() | CVE-1999-1285 Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed. | CVSS2: 2.1 | 0% Низкий | больше 26 лет назад |
![]() | CVE-1999-1284 NukeNabber allows remote attackers to cause a denial of service by connecting to the NukeNabber port (1080) without sending any data, which causes the CPU usage to rise to 100% from the report.exe program that is executed upon the connection. | CVSS2: 5 | 1% Низкий | больше 26 лет назад |
![]() | CVE-1999-1283 Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag. | CVSS2: 5 | 1% Низкий | почти 27 лет назад |
![]() | CVE-1999-1282 RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges. | CVSS2: 4.6 | 0% Низкий | больше 26 лет назад |
![]() | CVE-1999-1281 Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program. | CVSS2: 5 | 1% Низкий | больше 26 лет назад |
![]() | CVE-1999-1280 Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file. | CVSS2: 7.5 | 0% Низкий | больше 26 лет назад |
![]() | CVE-1999-1279 An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU. | CVSS2: 5 | 14% Средний | больше 25 лет назад |
![]() | CVE-1999-1278 nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl. | CVSS2: 7.5 | 1% Низкий | больше 26 лет назад |
![]() | CVE-1999-1277 BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password. | CVSS2: 4.6 | 0% Низкий | больше 26 лет назад |
Уязвимостей на страницу