Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 380 855

Количество 380 855

nvd логотип

CVE-1999-1074

больше 26 лет назад

Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1073

больше 27 лет назад

Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1072

больше 27 лет назад

Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1071

больше 27 лет назад

Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1070

около 28 лет назад

Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1069

почти 29 лет назад

Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1068

около 29 лет назад

Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1067

больше 29 лет назад

SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1066

больше 26 лет назад

Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1065

почти 27 лет назад

Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1064

почти 27 лет назад

Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-1999-1063

около 27 лет назад

CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-1999-1062

почти 29 лет назад

HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1061

почти 29 лет назад

HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1060

больше 27 лет назад

Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1059

больше 34 лет назад

Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-1999-1058

больше 26 лет назад

Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1057

почти 36 лет назад

VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1056

больше 33 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1395. Reason: This candidate is a duplicate of CVE-1999-1395. Notes: All CVE users should reference CVE-1999-1395 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-1999-1055

больше 26 лет назад

Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-1999-1074

Webmin before 0.5 does not restrict the number of invalid passwords that are entered for a valid username, which could allow remote attackers to gain privileges via brute force password cracking.

CVSS2: 7.5
2%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1073

Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.

CVSS2: 7.2
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1072

Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.

CVSS2: 7.2
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1071

Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.

CVSS2: 7.2
0%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1070

Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.

CVSS2: 5
1%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1069

Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.

CVSS2: 5
8%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1068

Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.

CVSS2: 5
2%
Низкий
около 29 лет назад
nvd логотип
CVE-1999-1067

SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.

CVSS2: 5
1%
Низкий
больше 29 лет назад
nvd логотип
CVE-1999-1066

Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.

CVSS2: 5
1%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1065

Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.

CVSS2: 7.5
2%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1064

Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).

CVSS2: 10
3%
Низкий
почти 27 лет назад
nvd логотип
CVE-1999-1063

CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.

CVSS2: 10
13%
Средний
около 27 лет назад
nvd логотип
CVE-1999-1062

HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.

CVSS2: 7.5
2%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1061

HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.

CVSS2: 7.5
4%
Низкий
почти 29 лет назад
nvd логотип
CVE-1999-1060

Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.

CVSS2: 5
2%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1059

Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.

CVSS2: 10
4%
Низкий
больше 34 лет назад
nvd логотип
CVE-1999-1058

Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands.

CVSS2: 7.5
2%
Низкий
больше 26 лет назад
nvd логотип
CVE-1999-1057

VMS 4.0 through 5.3 allows local users to gain privileges via the ANALYZE/PROCESS_DUMP dcl command.

CVSS2: 4.6
0%
Низкий
почти 36 лет назад
nvd логотип
CVE-1999-1056

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-1395. Reason: This candidate is a duplicate of CVE-1999-1395. Notes: All CVE users should reference CVE-1999-1395 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 33 лет назад
nvd логотип
CVE-1999-1055

Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."

CVSS2: 7.5
7%
Низкий
больше 26 лет назад

Уязвимостей на страницу