Количество 316 542
Количество 316 542
CVE-1999-0202
The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.
CVE-1999-0201
A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.
CVE-1999-0200
Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.
CVE-1999-0199
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
CVE-1999-0198
finger .@host on some systems may print information on some user accounts.
CVE-1999-0197
finger 0@host on some systems may print information on some user accounts.
CVE-1999-0196
websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).
CVE-1999-0195
Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
CVE-1999-0194
Denial of service in in.comsat allows attackers to generate messages.
CVE-1999-0193
Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.
CVE-1999-0192
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
CVE-1999-0191
IIS newdsn.exe CGI script allows remote users to overwrite files.
CVE-1999-0190
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.
CVE-1999-0189
Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.
CVE-1999-0188
The passwd command in Solaris can be subjected to a denial of service.
CVE-1999-0187
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-1999-0186
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.
CVE-1999-0185
In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.
CVE-1999-0184
When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.
CVE-1999-0183
Linux implementations of TFTP would allow access to files outside the restricted directory.
Уязвимостей на страницу
Уязвимость  | CVSS  | EPSS  | Опубликовано  | |
|---|---|---|---|---|
CVE-1999-0202 The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.  | CVSS2: 7.5  | 1% Низкий | почти 29 лет назад | |
CVE-1999-0201 A quote cwd command on FTP servers can reveal the full path of the home directory of the "ftp" user.  | CVSS2: 6.4  | 1% Низкий | почти 29 лет назад | |
CVE-1999-0200 Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.  | CVSS2: 10  | 0% Низкий | почти 27 лет назад | |
CVE-1999-0199 manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.  | CVSS3: 9.8  | 1% Низкий | около 5 лет назад | |
CVE-1999-0198 finger .@host on some systems may print information on some user accounts.  | CVSS2: 10  | 0% Низкий | почти 27 лет назад | |
CVE-1999-0197 finger 0@host on some systems may print information on some user accounts.  | CVSS2: 10  | 0% Низкий | почти 27 лет назад | |
CVE-1999-0196 websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).  | CVSS2: 5  | 6% Низкий | больше 28 лет назад | |
CVE-1999-0195 Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.  | CVSS2: 5  | 0% Низкий | больше 28 лет назад | |
CVE-1999-0194 Denial of service in in.comsat allows attackers to generate messages.  | CVSS2: 5  | 1% Низкий | больше 26 лет назад | |
CVE-1999-0193 Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.  | CVSS2: 5  | 6% Низкий | почти 28 лет назад | |
CVE-1999-0192 Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.  | CVSS2: 10  | 7% Низкий | около 28 лет назад | |
CVE-1999-0191 IIS newdsn.exe CGI script allows remote users to overwrite files.  | CVSS2: 6.4  | 62% Средний | около 28 лет назад | |
CVE-1999-0190 Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.  | CVSS2: 7.2  | 0% Низкий | больше 27 лет назад | |
CVE-1999-0189 Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.  | CVSS2: 7.5  | 0% Низкий | больше 28 лет назад | |
CVE-1999-0188 The passwd command in Solaris can be subjected to a denial of service.  | CVSS2: 7.2  | 0% Низкий | почти 27 лет назад | |
CVE-1999-0187 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage  | почти 27 лет назад | |||
CVE-1999-0186 In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.  | CVSS2: 10  | 2% Низкий | около 27 лет назад | |
CVE-1999-0185 In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.  | CVSS2: 7.5  | 1% Низкий | около 28 лет назад | |
CVE-1999-0184 When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.  | CVSS2: 6.4  | 1% Низкий | больше 28 лет назад | |
CVE-1999-0183 Linux implementations of TFTP would allow access to files outside the restricted directory.  | CVSS2: 6.4  | 1% Низкий | около 28 лет назад | 
Уязвимостей на страницу