CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-1999-1067

    Last Modified: 16 Apr 2026

    SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.

    Published: 7 May 1997
    7.2
    High

    CVE-1999-1461

    Last Modified: 16 Apr 2026

    inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.

    Published: 7 May 1997
    7.3
    High

    CVE-1999-0039

    Last Modified: 16 Apr 2026

    webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.

    Published: 6 May 1997
    5
    Medium

    CVE-1999-1267

    Last Modified: 16 Apr 2026

    KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.

    Published: 5 May 1997
    5.1
    Medium

    CVE-1999-1380

    Last Modified: 16 Apr 2026

    Symantec Norton Utilities 2.0 for Windows 95 marks the TUNEOCX.OCX ActiveX control as safe for scripting, which allows remote attackers to execute arbitrary commands via the run option through malicious web pages that are accessed by browsers such as Internet Explorer 3.0.

    Published: 4 May 1997
    7.2
    High

    CVE-1999-1116

    Last Modified: 16 Apr 2026

    Vulnerability in runpriv in Indigo Magic System Administration subsystem of SGI IRIX 6.3 and 6.4 allows local users to gain root privileges.

    Published: 3 May 1997
    7.2
    High

    CVE-1999-0112

    Last Modified: 16 Apr 2026

    Buffer overflow in AIX dtterm program for the CDE.

    Published: 1 May 1997
    7.2
    High

    CVE-1999-0040

    Last Modified: 16 Apr 2026

    Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.

    Published: 1 May 1997
    7.2
    High

    CVE-1999-1296

    Last Modified: 16 Apr 2026

    Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.

    Published: 29 Apr 1997
    8.4
    High

    CVE-1999-0038

    Last Modified: 16 Apr 2026

    Buffer overflow in xlock program allows local users to execute commands as root.

    Published: 26 Apr 1997
    7.5
    High

    CVE-1999-0149

    Last Modified: 16 Apr 2026

    The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.

    Published: 19 Apr 1997
    7.5
    High

    CVE-1999-0058

    Last Modified: 16 Apr 2026

    Buffer overflow in PHP cgi program, php.cgi allows shell access.

    Published: 17 Apr 1997
    10
    Critical

    CVE-1999-0042

    Last Modified: 16 Apr 2026

    Buffer overflow in University of Washington's implementation of IMAP and POP servers.

    Published: 7 Apr 1997
    7.5
    High

    CVE-1999-1298

    Last Modified: 16 Apr 2026

    Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.

    Published: 7 Apr 1997
    5
    Medium

    CVE-1999-1387

    Last Modified: 16 Apr 2026

    Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.

    Published: 2 Apr 1997
    7.2
    High

    CVE-1999-0315

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris fdformat command gives root access to local users.

    Published: 1 Apr 1997
    7.5
    High

    CVE-1999-0280

    Last Modified: 16 Apr 2026

    Remote command execution in Microsoft Internet Explorer using .lnk and .url files.

    Published: 1 Apr 1997
    5
    Medium

    CVE-1999-0292

    Last Modified: 16 Apr 2026

    Denial of service through Winpopup using large user names.

    Published: 1 Apr 1997
    5.1
    Medium

    CVE-1999-1525

    Last Modified: 16 Apr 2026

    Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.

    Published: 14 Mar 1997
    2.1
    Low

    CVE-1999-1408

    Last Modified: 16 Apr 2026

    Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

    Published: 5 Mar 1997
    9.3
    Critical

    CVE-1999-0299

    Last Modified: 16 Apr 2026

    Buffer overflow in FreeBSD lpd through long DNS hostnames.

    Published: 5 Mar 1997
    7.2
    High

    CVE-1999-1489

    Last Modified: 16 Apr 2026

    Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.

    Published: 4 Mar 1997
    2.1
    Low

    CVE-1999-0106

    Last Modified: 16 Apr 2026

    Finger redirection allows finger bombs.

    Published: 1 Mar 1997
    0
    Low

    CVE-1999-0612

    Last Modified: 16 Apr 2026

    A version of finger is running that exposes valid user information to any entity on the network.

    Published: 1 Mar 1997
    10
    Critical

    CVE-1999-0165

    Last Modified: 16 Apr 2026

    NFS cache poisoning.

    Published: 1 Mar 1997
    5.1
    Medium

    CVE-1999-1128

    Last Modified: 16 Apr 2026

    Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.

    Published: 1 Mar 1997
    7.2
    High

    CVE-1999-0318

    Last Modified: 16 Apr 2026

    Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.

    Published: 1 Mar 1997
    2.1
    Low

    CVE-1999-0105

    Last Modified: 16 Apr 2026

    finger allows recursive searches by using a long string of @ symbols.

    Published: 1 Mar 1997
    7.2
    High

    CVE-1999-0868

    Last Modified: 16 Apr 2026

    ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.

    Published: 20 Feb 1997
    7.5
    High

    CVE-1999-0041

    Last Modified: 16 Apr 2026

    Buffer overflow in NLS (Natural Language Service).

    Published: 13 Feb 1997
    7.2
    High

    CVE-1999-0109

    Last Modified: 16 Apr 2026

    Buffer overflow in ffbconfig in Solaris 2.5.1.

    Published: 10 Feb 1997
    5
    Medium

    CVE-1999-0228

    Last Modified: 16 Apr 2026

    Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.

    Published: 7 Feb 1997
    10
    Critical

    CVE-1999-0046

    Last Modified: 16 Apr 2026

    Buffer overflow of rlogin program using TERM environmental variable.

    Published: 6 Feb 1997
    7.5
    High

    CVE-1999-0298

    Last Modified: 16 Apr 2026

    ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.

    Published: 5 Feb 1997
    10
    Critical

    CVE-1999-1299

    Last Modified: 16 Apr 2026

    rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.

    Published: 3 Feb 1997
    10
    Critical

    CVE-1999-1160

    Last Modified: 16 Apr 2026

    Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.

    Published: 2 Feb 1997
    7.2
    High

    CVE-1999-0369

    Last Modified: 16 Apr 2026

    The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.

    Published: 1 Feb 1997
    7.2
    High

    CVE-1999-0959

    Last Modified: 16 Apr 2026

    IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.

    Published: 1 Feb 1997
    7.2
    High

    CVE-1999-0309

    Last Modified: 16 Apr 2026

    HP-UX vgdisplay program gives root access to local users.

    Published: 1 Feb 1997
    6.4
    Medium

    CVE-1999-0174

    Last Modified: 16 Apr 2026

    The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Published: 1 Feb 1997
    7.2
    High

    CVE-1999-1144

    Last Modified: 16 Apr 2026

    Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.

    Published: 30 Jan 1997
    10
    Critical

    CVE-1999-0047

    Last Modified: 16 Apr 2026

    MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.

    Published: 28 Jan 1997
    10
    Critical

    CVE-1999-0048

    Last Modified: 16 Apr 2026

    Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.

    Published: 27 Jan 1997
    7.2
    High

    CVE-1999-0966

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].

    Published: 27 Jan 1997
    5
    Medium

    CVE-1999-0081

    Last Modified: 16 Apr 2026

    wu-ftp allows files to be overwritten via the rnfr command.

    Published: 11 Jan 1997
    7.2
    High

    CVE-1999-1088

    Last Modified: 16 Apr 2026

    Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.

    Published: 9 Jan 1997
    7.2
    High

    CVE-1999-0049

    Last Modified: 16 Apr 2026

    Csetup under IRIX allows arbitrary file creation or overwriting.

    Published: 8 Jan 1997
    4.6
    Medium

    CVE-1999-1311

    Last Modified: 16 Apr 2026

    Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.

    Published: 7 Jan 1997
    7.2
    High

    CVE-1999-1145

    Last Modified: 16 Apr 2026

    Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.

    Published: 7 Jan 1997
    7.2
    High

    CVE-1999-0051

    Last Modified: 16 Apr 2026

    Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.

    Published: 6 Jan 1997