Количество 316 043
Количество 316 043
CVE-1999-0203
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.
CVE-1999-0202
The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.
CVE-1999-0201
A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.
CVE-1999-0200
Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.
CVE-1999-0199
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
CVE-1999-0198
finger .@host on some systems may print information on some user accounts.
CVE-1999-0197
finger 0@host on some systems may print information on some user accounts.
CVE-1999-0196
websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).
CVE-1999-0195
Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
CVE-1999-0194
Denial of service in in.comsat allows attackers to generate messages.
CVE-1999-0193
Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.
CVE-1999-0192
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
CVE-1999-0191
IIS newdsn.exe CGI script allows remote users to overwrite files.
CVE-1999-0190
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
CVE-1999-0189
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
CVE-1999-0188
The passwd command in Solaris can be subjected to a denial of service.
CVE-1999-0187
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-1999-0186
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
CVE-1999-0185
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
CVE-1999-0184
When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-1999-0203 In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program. | CVSS2: 10 | 0% Низкий | около 30 лет назад | |
CVE-1999-0202 The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands. | CVSS2: 7.5 | 1% Низкий | почти 29 лет назад | |
CVE-1999-0201 A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user. | CVSS2: 6.4 | 1% Низкий | почти 29 лет назад | |
CVE-1999-0200 Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password. | CVSS2: 10 | 0% Низкий | почти 27 лет назад | |
CVE-1999-0199 manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999. | CVSS3: 9.8 | 1% Низкий | около 5 лет назад | |
CVE-1999-0198 finger .@host on some systems may print information on some user accounts. | CVSS2: 10 | 0% Низкий | почти 27 лет назад | |
CVE-1999-0197 finger 0@host on some systems may print information on some user accounts. | CVSS2: 10 | 0% Низкий | почти 27 лет назад | |
CVE-1999-0196 websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable). | CVSS2: 5 | 7% Низкий | больше 28 лет назад | |
CVE-1999-0195 Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1. | CVSS2: 5 | 0% Низкий | больше 28 лет назад | |
CVE-1999-0194 Denial of service in in.comsat allows attackers to generate messages. | CVSS2: 5 | 1% Низкий | больше 26 лет назад | |
CVE-1999-0193 Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option. | CVSS2: 5 | 6% Низкий | почти 28 лет назад | |
CVE-1999-0192 Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable. | CVSS2: 10 | 7% Низкий | около 28 лет назад | |
CVE-1999-0191 IIS newdsn.exe CGI script allows remote users to overwrite files. | CVSS2: 6.4 | 62% Средний | около 28 лет назад | |
CVE-1999-0190 Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access. | CVSS2: 7.2 | 0% Низкий | больше 27 лет назад | |
CVE-1999-0189 Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111. | CVSS2: 7.5 | 0% Низкий | больше 28 лет назад | |
CVE-1999-0188 The passwd command in Solaris can be subjected to a denial of service. | CVSS2: 7.2 | 0% Низкий | почти 27 лет назад | |
CVE-1999-0187 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage | почти 27 лет назад | |||
CVE-1999-0186 In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters. | CVSS2: 10 | 2% Низкий | около 27 лет назад | |
CVE-1999-0185 In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution. | CVSS2: 7.5 | 1% Низкий | около 28 лет назад | |
CVE-1999-0184 When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records. | CVSS2: 6.4 | 1% Низкий | больше 28 лет назад |
Уязвимостей на страницу