Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 342 694

Количество 342 694

nvd логотип

CVE-1999-1053

больше 26 лет назад

guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".

CVSS2: 7.5
EPSS: Критический
nvd логотип

CVE-1999-1052

больше 26 лет назад

Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-1999-1051

больше 26 лет назад

Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1050

больше 26 лет назад

Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1049

около 27 лет назад

ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-1999-1048

больше 27 лет назад

Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1047

больше 26 лет назад

When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1046

около 27 лет назад

Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-1999-1045

около 28 лет назад

pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-1999-1044

почти 28 лет назад

Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1043

больше 26 лет назад

Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1042

больше 26 лет назад

Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-1999-1041

больше 27 лет назад

Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1040

около 28 лет назад

Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1039

почти 28 лет назад

Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1038

почти 28 лет назад

Tiger 2.2.3 allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger's default working directory, as defined by the WORKDIR variable.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1037

почти 28 лет назад

rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1036

почти 28 лет назад

COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1035

больше 26 лет назад

IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-1999-1034

почти 35 лет назад

Vulnerability in login in AT&T System V Release 4 allows local users to gain privileges.

CVSS2: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-1999-1053

guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".

CVSS2: 7.5
91%
Критический
больше 26 лет назад
nvd логотип
CVE-1999-1052

Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.

CVSS2: 5
37%
Средний
больше 26 лет назад
nvd логотип
CVE-1999-1051

Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.

CVSS2: 5
1%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1050

Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.

CVSS2: 5
5%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1049

ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.

CVSS2: 10
0%
Низкий
около 27 лет назад
nvd логотип
CVE-1999-1048

Buffer overflow in bash 2.0.0, 1.4.17, and other versions allows local attackers to gain privileges by creating an extremely large directory name, which is inserted into the password prompt via the \w option in the PS1 environmental variable when another user changes into that directory.

CVSS2: 4.6
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1047

When BSDI patches for Gauntlet 5.0 BSDI are installed in a particular order, Gauntlet allows remote attackers to bypass firewall access restrictions, and does not log the activities.

CVSS2: 7.5
0%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1046

Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.

CVSS2: 10
5%
Низкий
около 27 лет назад
nvd логотип
CVE-1999-1045

pnserver in RealServer 5.0 and earlier allows remote attackers to cause a denial of service by sending a short, malformed request.

CVSS2: 7.8
2%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1044

Vulnerability in Advanced File System Utility (advfs) in Digital UNIX 4.0 through 4.0d allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1043

Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).

CVSS2: 5
6%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1042

Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.

CVSS2: 1.2
0%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1041

Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.

CVSS2: 7.2
1%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1040

Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable.

CVSS2: 7.2
0%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1039

Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise.

CVSS2: 7.2
0%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1038

Tiger 2.2.3 allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger's default working directory, as defined by the WORKDIR variable.

CVSS2: 7.2
0%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1037

rex.satan in SATAN 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rex.$$ file.

CVSS2: 7.2
0%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1036

COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk.

CVSS2: 7.2
0%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1035

IIS 3.0 and 4.0 on x86 and Alpha allows remote attackers to cause a denial of service (hang) via a malformed GET request, aka the IIS "GET" vulnerability.

CVSS2: 5
18%
Средний
больше 26 лет назад
nvd логотип
CVE-1999-1034

Vulnerability in login in AT&T System V Release 4 allows local users to gain privileges.

CVSS2: 7.2
0%
Низкий
почти 35 лет назад

Уязвимостей на страницу