Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 173

Количество 376 173

nvd логотип

CVE-1999-1432

около 28 лет назад

Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1431

больше 21 года назад

ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1430

больше 27 лет назад

PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1429

больше 28 лет назад

DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1428

почти 29 лет назад

Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-1999-1427

почти 29 лет назад

Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-1999-1426

почти 29 лет назад

Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-1999-1425

почти 29 лет назад

Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-1999-1424

почти 29 лет назад

Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-1999-1423

около 29 лет назад

ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1422

больше 27 лет назад

The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1421

около 28 лет назад

NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-1999-1420

около 28 лет назад

NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-1999-1419

около 29 лет назад

Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1418

больше 27 лет назад

ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1417

почти 28 лет назад

Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1416

почти 28 лет назад

AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1415

почти 35 лет назад

Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1414

около 27 лет назад

IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1413

около 30 лет назад

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-1999-1432

Power management (Powermanagement) on Solaris 2.4 through 2.6 does not start the xlock process until after the sys-suspend has completed, which allows an attacker with physical access to input characters to the last active application from the keyboard for a short period after the system is restoring, which could lead to increased privileges.

CVSS2: 7.5
2%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1431

ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.

CVSS2: 4.6
10%
Низкий
больше 21 года назад
nvd логотип
CVE-1999-1430

PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.

CVSS2: 2.1
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1429

DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver.

CVSS2: 2.1
0%
Низкий
больше 28 лет назад
nvd логотип
CVE-1999-1428

Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.

CVSS2: 6.2
0%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1427

Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.

CVSS2: 6.2
0%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1426

Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.

CVSS2: 6.2
0%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1425

Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.

CVSS2: 6.2
0%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1424

Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.

CVSS2: 6.2
0%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1423

ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.

CVSS2: 2.1
1%
Низкий
около 29 лет назад
nvd логотип
CVE-1999-1422

The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.

CVSS2: 7.2
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1421

NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.

CVSS2: 6.4
2%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1420

NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.

CVSS2: 10
3%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1419

Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.

CVSS2: 7.2
0%
Низкий
около 29 лет назад
nvd логотип
CVE-1999-1418

ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").

CVSS2: 5
1%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1417

Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.

CVSS2: 7.5
2%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1416

AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.

CVSS2: 5
1%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1415

Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
почти 35 лет назад
nvd логотип
CVE-1999-1414

IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

CVSS2: 7.2
1%
Низкий
около 27 лет назад
nvd логотип
CVE-1999-1413

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

CVSS2: 4.6
1%
Низкий
около 30 лет назад

Уязвимостей на страницу