CVE-1999-0297
Last Modified: 16 Apr 2026Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.
CVE-1999-0045
Last Modified: 16 Apr 2026List of arbitrary files on Web host via nph-test-cgi script.
CVE-1999-0096
Last Modified: 16 Apr 2026Sendmail decode alias can be used to overwrite sensitive files.
CVE-1999-0101
Last Modified: 16 Apr 2026Buffer overflow in AIX and Solaris "gethostbyname" library call allows root access through corrupt DNS host names.
CVE-1999-1401
Last Modified: 16 Apr 2026Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).
CVE-1999-0043
Last Modified: 16 Apr 2026Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
CVE-1999-0044
Last Modified: 16 Apr 2026fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.
CVE-1999-0129
Last Modified: 16 Apr 2026Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
CVE-1999-0050
Last Modified: 16 Apr 2026Buffer overflow in HP-UX newgrp program.
CVE-1999-1240
Last Modified: 16 Apr 2026Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.
CVE-1999-1099
Last Modified: 16 Apr 2026Kerberos 4 allows remote attackers to obtain sensitive information via a malformed UDP packet that generates an error string that inadvertently includes the realm name and the last user.
CVE-1999-1221
Last Modified: 16 Apr 2026dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.
CVE-1999-0130
Last Modified: 16 Apr 2026Local users can start Sendmail in daemon mode and gain root privileges.
CVE-1999-1161
Last Modified: 16 Apr 2026Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.
CVE-1999-0311
Last Modified: 16 Apr 2026fpkg2swpk in HP-UX allows local users to gain root access.
CVE-1999-0336
Last Modified: 16 Apr 2026Buffer overflow in mstm in HP-UX allows local users to gain root access.
CVE-1999-1384
Last Modified: 16 Apr 2026Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.
CVE-1999-0277
Last Modified: 16 Apr 2026The WorkMan program can be used to overwrite any file to get root access.
CVE-1999-0032
Last Modified: 16 Apr 2026Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.
CVE-1999-0075
Last Modified: 16 Apr 2026PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.
CVE-1999-0234
Last Modified: 16 Apr 2026Bash treats any character with a value of 255 as a command separator.
CVE-1999-0308
Last Modified: 16 Apr 2026HP-UX gwind program allows users to modify arbitrary files.
CVE-1999-0319
Last Modified: 16 Apr 2026Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.
CVE-1999-0206
Last Modified: 16 Apr 2026MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.
CVE-1999-0246
Last Modified: 16 Apr 2026HP Remote Watch allows a remote user to gain root access.
CVE-1999-0961
Last Modified: 16 Apr 2026HPUX sysdiag allows local users to gain root privileges via a symlink attack during log file creation.
CVE-1999-0116
Last Modified: 16 Apr 2026Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.
CVE-1999-1295
Last Modified: 16 Apr 2026Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.
CVE-1999-1383
Last Modified: 16 Apr 2026(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.
CVE-1999-0131
Last Modified: 16 Apr 2026Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
CVE-1999-1252
Last Modified: 16 Apr 2026Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.
CVE-1999-0324
Last Modified: 16 Apr 2026ppl program in HP-UX allows local users to create root files through symlinks.
CVE-1999-1309
Last Modified: 16 Apr 2026Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
CVE-1999-1187
Last Modified: 16 Apr 2026Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.
CVE-1999-0085
Last Modified: 16 Apr 2026Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.
CVE-1999-0132
Last Modified: 16 Apr 2026Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.
CVE-1999-0133
Last Modified: 16 Apr 2026fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.
CVE-1999-0134
Last Modified: 16 Apr 2026vold in Solaris 2.x allows local users to gain root access.
CVE-1999-1413
Last Modified: 16 Apr 2026Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
CVE-1999-0335
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-1999-0136
Last Modified: 16 Apr 2026Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.
CVE-1999-0135
Last Modified: 16 Apr 2026admintool in Solaris allows a local user to write to arbitrary files and gain root access.
CVE-1999-0023
Last Modified: 16 Apr 2026Local user gains root privileges via buffer overflow in rdist, via lookup() function.
CVE-1999-1301
Last Modified: 16 Apr 2026A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.
CVE-1999-1572
Last Modified: 16 Apr 2026cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.
CVE-1999-0137
Last Modified: 16 Apr 2026The dip program on many Linux systems allows local users to gain root access via a buffer overflow.
CVE-1999-0022
Last Modified: 16 Apr 2026Local user gains root privileges via buffer overflow in rdist, via expstr() function.
CVE-1999-0175
Last Modified: 16 Apr 2026The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.
CVE-1999-0138
Last Modified: 16 Apr 2026The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
CVE-1999-1205
Last Modified: 16 Apr 2026nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.
