Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 376 565

Количество 376 565

nvd логотип

CVE-1999-1084

больше 26 лет назад

The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1083

почти 27 лет назад

Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1082

почти 27 лет назад

Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1081

больше 24 лет назад

Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1080

больше 31 года назад

rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1079

больше 27 лет назад

Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1078

около 27 лет назад

WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1077

почти 27 лет назад

Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1076

почти 27 лет назад

Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1075

больше 28 лет назад

inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1074

больше 26 лет назад

Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1073

больше 27 лет назад

Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1072

больше 27 лет назад

Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1071

больше 27 лет назад

Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1070

около 28 лет назад

Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1069

почти 29 лет назад

Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1068

около 29 лет назад

Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1067

больше 29 лет назад

SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1066

больше 26 лет назад

Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1065

почти 27 лет назад

Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-1999-1084

The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

CVSS2: 4.6
4%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1083

Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.

CVSS2: 5
3%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1082

Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.

CVSS2: 5
7%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1081

Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.

CVSS2: 5
3%
Низкий
больше 24 лет назад
nvd логотип
CVE-1999-1080

rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.

CVSS2: 7.2
0%
Низкий
больше 31 года назад
nvd логотип
CVE-1999-1079

Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.

CVSS2: 4.6
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1078

WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.

CVSS2: 7.5
2%
Низкий
около 27 лет назад
nvd логотип
CVE-1999-1077

Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.

CVSS2: 4.6
0%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1076

Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session.

CVSS2: 4.6
0%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1075

inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.

CVSS2: 5
1%
Низкий
больше 28 лет назад
nvd логотип
CVE-1999-1074

Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.

CVSS2: 7.5
2%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1073

Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.

CVSS2: 7.2
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1072

Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.

CVSS2: 7.2
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1071

Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.

CVSS2: 7.2
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1070

Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.

CVSS2: 5
1%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1069

Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.

CVSS2: 5
8%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1068

Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.

CVSS2: 5
2%
Низкий
около 29 лет назад
nvd логотип
CVE-1999-1067

SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.

CVSS2: 5
1%
Низкий
больше 29 лет назад
nvd логотип
CVE-1999-1066

Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.

CVSS2: 5
1%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1065

Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.

CVSS2: 7.5
2%
Низкий
почти 27 лет назад

Уязвимостей на страницу