Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 393 962

Количество 393 962

nvd логотип

CVE-1999-1421

около 28 лет назад

NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-1999-1420

около 28 лет назад

NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-1999-1419

около 29 лет назад

Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1418

больше 27 лет назад

ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1417

около 28 лет назад

Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1416

около 28 лет назад

AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1415

около 35 лет назад

Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1414

больше 27 лет назад

IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1413

около 30 лет назад

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-1999-1412

больше 27 лет назад

A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-1999-1411

почти 28 лет назад

The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-1999-1410

больше 29 лет назад

addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.

CVSS2: 6.2
EPSS: Низкий
nvd логотип

CVE-1999-1409

около 28 лет назад

The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1408

больше 29 лет назад

Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1407

больше 28 лет назад

ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1406

около 28 лет назад

dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-1999-1405

больше 27 лет назад

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-1999-1404

почти 28 лет назад

IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-1999-1403

почти 28 лет назад

IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-1999-1402

больше 29 лет назад

The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-1999-1421

NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.

CVSS2: 6.4
2%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1420

NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.

CVSS2: 10
3%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1419

Buffer overflow in nss_nisplus.so.1 library in NIS+ in Solaris 2.3 and 2.4 allows local users to gain root privileges.

CVSS2: 7.2
0%
Низкий
около 29 лет назад
nvd логотип
CVE-1999-1418

ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").

CVSS2: 5
1%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1417

Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.

CVSS2: 7.5
2%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1416

AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.

CVSS2: 5
1%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1415

Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
около 35 лет назад
nvd логотип
CVE-1999-1414

IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

CVSS2: 7.2
1%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1413

Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

CVSS2: 4.6
1%
Низкий
около 30 лет назад
nvd логотип
CVE-1999-1412

A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

CVSS2: 5
36%
Средний
больше 27 лет назад
nvd логотип
CVE-1999-1411

The installation of the fsp package 2.71-10 in Debian GNU/Linux 2.0 adds the anonymous FTP user without notifying the administrator, which could automatically enable anonymous FTP on some servers such as wu-ftp.

CVSS2: 7.5
2%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1410

addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.

CVSS2: 6.2
1%
Низкий
больше 29 лет назад
nvd логотип
CVE-1999-1409

The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.

CVSS2: 2.1
1%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1408

Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

CVSS2: 2.1
1%
Низкий
больше 29 лет назад
nvd логотип
CVE-1999-1407

ifdhcpc-done script for configuring DHCP on Red Hat Linux 5 allows local users to append text to arbitrary files via a symlink attack on the dhcplog file.

CVSS2: 2.1
0%
Низкий
больше 28 лет назад
nvd логотип
CVE-1999-1406

dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.

CVSS2: 2.1
0%
Низкий
около 28 лет назад
nvd логотип
CVE-1999-1405

snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

CVSS2: 10
3%
Низкий
больше 27 лет назад
nvd логотип
CVE-1999-1404

IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.

CVSS2: 5
1%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1403

IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.

CVSS2: 7.2
0%
Низкий
почти 28 лет назад
nvd логотип
CVE-1999-1402

The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.

CVSS2: 2.1
1%
Низкий
больше 29 лет назад

Уязвимостей на страницу