CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-1999-0196

    Last Modified: 16 Apr 2026

    websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).

    Published: 8 Jul 1997
    5
    Medium

    CVE-1999-1326

    Last Modified: 16 Apr 2026

    wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.

    Published: 4 Jul 1997
    10
    Critical

    CVE-1999-0169

    Last Modified: 16 Apr 2026

    NFS allows attackers to read and write any file on the system by specifying a false UID.

    Published: 1 Jul 1997
    10
    Critical

    CVE-1999-0250

    Last Modified: 16 Apr 2026

    Denial of service in Qmail through long SMTP commands.

    Published: 1 Jul 1997
    5
    Medium

    CVE-1999-0195

    Last Modified: 16 Apr 2026

    Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.

    Published: 1 Jul 1997
    5
    Medium

    CVE-1999-0153

    Last Modified: 16 Apr 2026

    Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.

    Published: 1 Jul 1997
    6.4
    Medium

    CVE-1999-0074

    Last Modified: 16 Apr 2026

    Listening TCP ports are sequentially allocated, allowing spoofing attacks.

    Published: 1 Jul 1997
    7.5
    High

    CVE-1999-0541

    Last Modified: 16 Apr 2026

    A password for accessing a WWW URL is guessable.

    Published: 1 Jul 1997
    0
    Low

    CVE-1999-0532

    Last Modified: 16 Apr 2026

    A DNS server allows zone transfers.

    Published: 1 Jul 1997
    10
    Critical

    CVE-1999-0526

    Last Modified: 16 Apr 2026

    An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.

    Published: 1 Jul 1997
    5
    Medium

    CVE-1999-0111

    Last Modified: 16 Apr 2026

    RIP v1 is susceptible to spoofing.

    Published: 1 Jul 1997
    7.5
    High

    CVE-1999-0147

    Last Modified: 16 Apr 2026

    The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.

    Published: 1 Jul 1997
    4.6
    Medium

    CVE-1999-0156

    Last Modified: 16 Apr 2026

    wu-ftpd FTP daemon allows any user and password combination.

    Published: 1 Jul 1997
    6.4
    Medium

    CVE-1999-0184

    Last Modified: 16 Apr 2026

    When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.

    Published: 1 Jul 1997
    7.5
    High

    CVE-1999-0533

    Last Modified: 16 Apr 2026

    A DNS server allows inverse queries.

    Published: 1 Jul 1997
    5
    Medium

    CVE-1999-0628

    Last Modified: 16 Apr 2026

    The rwho/rwhod service is running, which exposes machine status and user information.

    Published: 1 Jul 1997
    5
    Medium

    CVE-1999-0076

    Last Modified: 16 Apr 2026

    Buffer overflow in wu-ftp from PASV command causes a core dump.

    Published: 1 Jul 1997
    7.5
    High

    CVE-1999-0150

    Last Modified: 16 Apr 2026

    The Perl fingerd program allows arbitrary command execution from remote users.

    Published: 1 Jul 1997
    7.8
    High

    CVE-1999-0219

    Last Modified: 16 Apr 2026

    Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.

    Published: 1 Jul 1997
    2.1
    Low

    CVE-1999-1423

    Last Modified: 16 Apr 2026

    ping in Solaris 2.3 through 2.6 allows local users to cause a denial of service (crash) via a ping request to a multicast address through the loopback interface, e.g. via ping -i.

    Published: 26 Jun 1997
    7.2
    High

    CVE-1999-1192

    Last Modified: 16 Apr 2026

    Buffer overflow in eeprom in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.

    Published: 24 Jun 1997
    4.6
    Medium

    CVE-1999-1483

    Last Modified: 16 Apr 2026

    Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.

    Published: 19 Jun 1997
    2.1
    Low

    CVE-1999-0957

    Last Modified: 16 Apr 2026

    MajorCool mj_key_cache program allows local users to modify files via a symlink attack.

    Published: 18 Jun 1997
    5
    Medium

    CVE-1999-1266

    Last Modified: 16 Apr 2026

    rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.

    Published: 13 Jun 1997
    7.2
    High

    CVE-1999-0033

    Last Modified: 16 Apr 2026

    Command execution in Sun systems via buffer overflow in the at program.

    Published: 12 Jun 1997
    5
    Medium

    CVE-1999-0083

    Last Modified: 16 Apr 2026

    getcwd() file descriptor leak in FTP.

    Published: 11 Jun 1997
    5
    Medium

    CVE-1999-0275

    Last Modified: 16 Apr 2026

    Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.

    Published: 10 Jun 1997
    7.5
    High

    CVE-1999-0189

    Last Modified: 16 Apr 2026

    Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.

    Published: 4 Jun 1997
    5
    Medium

    CVE-1999-0227

    Last Modified: 16 Apr 2026

    Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.

    Published: 1 Jun 1997
    10
    Critical

    CVE-1999-0799

    Last Modified: 16 Apr 2026

    Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.

    Published: 1 Jun 1997
    5
    Medium

    CVE-1999-0281

    Last Modified: 16 Apr 2026

    Denial of service in IIS using long URLs.

    Published: 1 Jun 1997
    2.1
    Low

    CVE-1999-0144

    Last Modified: 16 Apr 2026

    Denial of service in Qmail by specifying a large number of recipients with the RCPT command.

    Published: 1 Jun 1997
    7.2
    High

    CVE-1999-0034

    Last Modified: 16 Apr 2026

    Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.

    Published: 29 May 1997
    5.4
    Medium

    CVE-1999-0035

    Last Modified: 16 Apr 2026

    Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.

    Published: 29 May 1997
    7.2
    High

    CVE-1999-1143

    Last Modified: 16 Apr 2026

    Vulnerability in runtime linker program rld in SGI IRIX 6.x and earlier allows local users to gain privileges via setuid and setgid programs.

    Published: 28 May 1997
    7.2
    High

    CVE-1999-0064

    Last Modified: 16 Apr 2026

    Buffer overflow in AIX lquerylv program gives root access to local users.

    Published: 26 May 1997
    8.4
    High

    CVE-1999-0036

    Last Modified: 16 Apr 2026

    IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.

    Published: 26 May 1997
    5
    Medium

    CVE-1999-0259

    Last Modified: 16 Apr 2026

    cfingerd lists all users on a system via search.**@target.

    Published: 23 May 1997
    7.5
    High

    CVE-1999-0037

    Last Modified: 16 Apr 2026

    Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.

    Published: 21 May 1997
    7.2
    High

    CVE-1999-1191

    Last Modified: 16 Apr 2026

    Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.

    Published: 19 May 1997
    2.1
    Low

    CVE-1999-1449

    Last Modified: 16 Apr 2026

    SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.

    Published: 19 May 1997
    2.1
    Low

    CVE-1999-1402

    Last Modified: 16 Apr 2026

    The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.

    Published: 17 May 1997
    7.2
    High

    CVE-1999-1232

    Last Modified: 16 Apr 2026

    Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.

    Published: 16 May 1997
    7.5
    High

    CVE-1999-1141

    Last Modified: 16 Apr 2026

    Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.

    Published: 15 May 1997
    7.2
    High

    CVE-1999-0962

    Last Modified: 16 Apr 2026

    Buffer overflow in HPUX passwd command allows local users to gain root privileges via a command line option.

    Published: 14 May 1997
    7.2
    High

    CVE-1999-1158

    Last Modified: 16 Apr 2026

    Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.

    Published: 13 May 1997
    4.6
    Medium

    CVE-1999-1184

    Last Modified: 16 Apr 2026

    Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.

    Published: 13 May 1997
    6.2
    Medium

    CVE-1999-1410

    Last Modified: 16 Apr 2026

    addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.

    Published: 9 May 1997
    7.2
    High

    CVE-1999-1286

    Last Modified: 16 Apr 2026

    addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.

    Published: 9 May 1997
    6.2
    Medium

    CVE-1999-1398

    Last Modified: 16 Apr 2026

    Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.

    Published: 7 May 1997