Количество 299 017
Количество 299 017

CVE-1999-1276
fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.

CVE-1999-1275
Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.

CVE-1999-1274
iPass RoamServer 3.1 creates temporary files with world-writable permissions.

CVE-1999-1273
Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences.

CVE-1999-1272
Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges.

CVE-1999-1271
Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.

CVE-1999-1270
KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.

CVE-1999-1269
Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.

CVE-1999-1268
Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.

CVE-1999-1267
KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.

CVE-1999-1266
rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.

CVE-1999-1265
SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a "(" (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO.

CVE-1999-1264
WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.

CVE-1999-1263
Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.

CVE-1999-1262
Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.

CVE-1999-1261
Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.

CVE-1999-1260
mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.

CVE-1999-1259
Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information.

CVE-1999-1258
rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information.

CVE-1999-1257
Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character, or (2) a ? (question mark).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-1999-1276 fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device. | CVSS2: 7.2 | 0% Низкий | больше 26 лет назад |
![]() | CVE-1999-1275 Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges. | CVSS2: 4.6 | 0% Низкий | почти 28 лет назад |
![]() | CVE-1999-1274 iPass RoamServer 3.1 creates temporary files with world-writable permissions. | CVSS2: 6.4 | 0% Низкий | больше 27 лет назад |
![]() | CVE-1999-1273 Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences. | CVSS2: 7.5 | 0% Низкий | больше 27 лет назад |
![]() | CVE-1999-1272 Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges. | CVSS2: 7.2 | 0% Низкий | больше 27 лет назад |
![]() | CVE-1999-1271 Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users. | CVSS2: 2.1 | 0% Низкий | около 27 лет назад |
![]() | CVE-1999-1270 KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps. | CVSS2: 4.6 | 0% Низкий | почти 27 лет назад |
![]() | CVE-1999-1269 Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file. | CVSS2: 2.1 | 0% Низкий | больше 27 лет назад |
![]() | CVE-1999-1268 Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices. | CVSS2: 7.2 | 0% Низкий | больше 26 лет назад |
![]() | CVE-1999-1267 KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server. | CVSS2: 5 | 0% Низкий | около 28 лет назад |
![]() | CVE-1999-1266 rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system. | CVSS2: 5 | 1% Низкий | около 28 лет назад |
![]() | CVE-1999-1265 SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a "(" (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO. | CVSS2: 5 | 1% Низкий | почти 27 лет назад |
![]() | CVE-1999-1264 WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled. | CVSS2: 7.5 | 1% Низкий | больше 26 лет назад |
![]() | CVE-1999-1263 Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file. | CVSS2: 2.6 | 0% Низкий | почти 22 года назад |
![]() | CVE-1999-1262 Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities. | CVSS2: 5.1 | 1% Низкий | почти 28 лет назад |
![]() | CVE-1999-1261 Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command. | CVSS2: 5 | 1% Низкий | больше 27 лет назад |
![]() | CVE-1999-1260 mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query. | CVSS2: 7.5 | 1% Низкий | больше 26 лет назад |
![]() | CVE-1999-1259 Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information. | CVSS2: 2.1 | 2% Низкий | больше 25 лет назад |
![]() | CVE-1999-1258 rpc.pwdauthd in SunOS 4.1.1 and earlier does not properly prevent remote access to the daemon, which allows remote attackers to obtain sensitive system information. | CVSS2: 5 | 1% Низкий | больше 34 лет назад |
![]() | CVE-1999-1257 Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character, or (2) a ? (question mark). | CVSS2: 7.5 | 0% Низкий | больше 27 лет назад |
Уязвимостей на страницу