CVE-1999-0880
Last Modified: 16 Apr 2026Denial of service in WU-FTPD via the SITE NEWER command, which does not free memory properly.
CVE-1999-0933
Last Modified: 16 Apr 2026TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-1999-1500
Last Modified: 16 Apr 2026Internet Anywhere POP3 Mail Server 2.3.1 allows remote attackers to cause a denial of service (crash) via (1) LIST, (2) TOP, or (3) UIDL commands using letters as arguments.
CVE-1999-1236
Last Modified: 16 Apr 2026Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf.
CVE-2000-0016
Last Modified: 16 Apr 2026Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username.
CVE-2000-0047
Last Modified: 16 Apr 2026Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message.
CVE-1999-0877
Last Modified: 16 Apr 2026Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.
CVE-1999-0879
Last Modified: 16 Apr 2026Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.
CVE-1999-1583
Last Modified: 16 Apr 2026Buffer overflow in nslookup for AIX 4.3 allows local users to execute arbitrary code via a long hostname command line argument.
CVE-1999-1469
Last Modified: 16 Apr 2026Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header.
CVE-1999-0932
Last Modified: 16 Apr 2026Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.
CVE-1999-0931
Last Modified: 16 Apr 2026Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.
CVE-1999-0289
Last Modified: 16 Apr 2026The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.
CVE-1999-1350
Last Modified: 16 Apr 2026ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse.
CVE-1999-0789
Last Modified: 16 Apr 2026Buffer overflow in AIX ftpd in the libc library.
CVE-1999-1352
Last Modified: 16 Apr 2026mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.
CVE-1999-1576
Last Modified: 16 Apr 2026Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary code via the pdf.setview method.
CVE-1999-0940
Last Modified: 16 Apr 2026Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.
CVE-1999-0788
Last Modified: 16 Apr 2026Arkiea nlservd allows remote attackers to conduct a denial of service.
CVE-1999-1351
Last Modified: 16 Apr 2026Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick <soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.
CVE-1999-1578
Last Modified: 16 Apr 2026Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.
CVE-1999-1484
Last Modified: 16 Apr 2026Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.
CVE-1999-0908
Last Modified: 16 Apr 2026Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.
CVE-1999-0777
Last Modified: 16 Apr 2026IIS FTP servers may allow a remote attacker to read or delete files on the server, even if they have "No Access" permissions.
CVE-1999-1534
Last Modified: 16 Apr 2026Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.
CVE-1999-0906
Last Modified: 16 Apr 2026Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.
CVE-1999-1013
Last Modified: 16 Apr 2026named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.
CVE-1999-1477
Last Modified: 16 Apr 2026Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.
CVE-1999-0786
Last Modified: 16 Apr 2026The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
CVE-1999-0912
Last Modified: 16 Apr 2026FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.
CVE-1999-0708
Last Modified: 16 Apr 2026Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.
CVE-1999-0909
Last Modified: 16 Apr 2026Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.
CVE-1999-0886
Last Modified: 16 Apr 2026The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
CVE-1999-0787
Last Modified: 16 Apr 2026The SSH authentication agent follows symlinks via a UNIX domain socket.
CVE-2000-0824
Last Modified: 16 Apr 2026The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.
CVE-1999-0704
Last Modified: 16 Apr 2026Buffer overflow in Berkeley automounter daemon (amd) logging facility provided in the Linux am-utils package and others.
CVE-1999-0907
Last Modified: 16 Apr 2026sccw allows local users to read arbitrary files.
CVE-1999-0953
Last Modified: 16 Apr 2026WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.
CVE-1999-0954
Last Modified: 16 Apr 2026WWWBoard has a default username and default password.
CVE-1999-0890
Last Modified: 16 Apr 2026iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.
CVE-1999-0817
Last Modified: 16 Apr 2026Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.
CVE-1999-1053
Last Modified: 16 Apr 2026guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
CVE-1999-0689
Last Modified: 16 Apr 2026The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
CVE-1999-0750
Last Modified: 16 Apr 2026Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.
CVE-1999-0751
Last Modified: 16 Apr 2026Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.
CVE-1999-0759
Last Modified: 16 Apr 2026Buffer overflow in FuseMAIL POP service via long USER and PASS commands.
CVE-1999-1014
Last Modified: 16 Apr 2026Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.
CVE-1999-0687
Last Modified: 16 Apr 2026The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
CVE-1999-0691
Last Modified: 16 Apr 2026Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.
CVE-1999-1521
Last Modified: 16 Apr 2026Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server.
