CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-1999-0131

    Last Modified: 16 Apr 2026

    Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.

    Published: 11 Sept 1996
    7.2
    High

    CVE-1999-1252

    Last Modified: 16 Apr 2026

    Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.

    Published: 4 Sept 1996
    7.2
    High

    CVE-1999-0324

    Last Modified: 16 Apr 2026

    ppl program in HP-UX allows local users to create root files through symlinks.

    Published: 1 Sept 1996
    7.2
    High

    CVE-1999-1309

    Last Modified: 16 Apr 2026

    Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.

    Published: 30 Aug 1996
    4.6
    Medium

    CVE-1999-1187

    Last Modified: 16 Apr 2026

    Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.

    Published: 26 Aug 1996
    7.5
    High

    CVE-1999-0085

    Last Modified: 16 Apr 2026

    Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.

    Published: 21 Aug 1996
    2.1
    Low

    CVE-1999-0132

    Last Modified: 16 Apr 2026

    Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.

    Published: 15 Aug 1996
    2.1
    Low

    CVE-1999-0133

    Last Modified: 16 Apr 2026

    fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.

    Published: 14 Aug 1996
    7.2
    High

    CVE-1999-0134

    Last Modified: 16 Apr 2026

    vold in Solaris 2.x allows local users to gain root access.

    Published: 6 Aug 1996
    4.6
    Medium

    CVE-1999-1413

    Last Modified: 16 Apr 2026

    Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

    Published: 3 Aug 1996
    Unknown

    CVE-1999-0335

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Aug 1996
    7.2
    High

    CVE-1999-0136

    Last Modified: 16 Apr 2026

    Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.

    Published: 31 Jul 1996
    7.2
    High

    CVE-1999-0135

    Last Modified: 16 Apr 2026

    admintool in Solaris allows a local user to write to arbitrary files and gain root access.

    Published: 25 Jul 1996
    7.2
    High

    CVE-1999-0023

    Last Modified: 16 Apr 2026

    Local user gains root privileges via buffer overflow in rdist, via lookup() function.

    Published: 24 Jul 1996
    7.5
    High

    CVE-1999-1301

    Last Modified: 16 Apr 2026

    A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.

    Published: 16 Jul 1996
    2.1
    Low

    CVE-1999-1572

    Last Modified: 16 Apr 2026

    cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.

    Published: 16 Jul 1996
    7.2
    High

    CVE-1999-0137

    Last Modified: 16 Apr 2026

    The dip program on many Linux systems allows local users to gain root access via a buffer overflow.

    Published: 9 Jul 1996
    7.8
    High

    CVE-1999-0022

    Last Modified: 16 Apr 2026

    Local user gains root privileges via buffer overflow in rdist, via expstr() function.

    Published: 3 Jul 1996
    5
    Medium

    CVE-1999-0175

    Last Modified: 16 Apr 2026

    The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.

    Published: 1 Jul 1996
    7.2
    High

    CVE-1999-0138

    Last Modified: 16 Apr 2026

    The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.

    Published: 26 Jun 1996
    2.1
    Low

    CVE-1999-1205

    Last Modified: 16 Apr 2026

    nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.

    Published: 7 Jun 1996
    7.2
    High

    CVE-1999-1253

    Last Modified: 16 Apr 2026

    Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.

    Published: 7 Jun 1996
    10
    Critical

    CVE-1999-0509

    Last Modified: 16 Apr 2026

    Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.

    Published: 29 May 1996
    7.2
    High

    CVE-1999-0522

    Last Modified: 16 Apr 2026

    The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.

    Published: 28 May 1996
    4.6
    Medium

    CVE-1999-1313

    Last Modified: 16 Apr 2026

    Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.

    Published: 23 May 1996
    2.1
    Low

    CVE-1999-1314

    Last Modified: 16 Apr 2026

    Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.

    Published: 17 May 1996
    5
    Medium

    CVE-1999-0019

    Last Modified: 16 Apr 2026

    Delete or create a file via rpc.statd, due to invalid information.

    Published: 24 Apr 1996
    1.9
    Low

    CVE-1999-0078

    Last Modified: 16 Apr 2026

    pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

    Published: 18 Apr 1996
    4.6
    Medium

    CVE-1999-1103

    Last Modified: 16 Apr 2026

    dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.

    Published: 3 Apr 1996
    5
    Medium

    CVE-1999-0070

    Last Modified: 16 Apr 2026

    test-cgi program allows an attacker to list files on the server.

    Published: 1 Apr 1996
    3.7
    Low

    CVE-1999-0141

    Last Modified: 16 Apr 2026

    Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.

    Published: 29 Mar 1996
    10
    Critical

    CVE-1999-0067

    Last Modified: 16 Apr 2026

    phf CGI program allows remote command execution through shell metacharacters.

    Published: 20 Mar 1996
    7.5
    High

    CVE-1999-0142

    Last Modified: 16 Apr 2026

    The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.

    Published: 1 Mar 1996
    10
    Critical

    CVE-1999-0233

    Last Modified: 16 Apr 2026

    IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.

    Published: 25 Feb 1996
    4.6
    Medium

    CVE-1999-0143

    Last Modified: 16 Apr 2026

    Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.

    Published: 21 Feb 1996
    5
    Medium

    CVE-1999-0103

    Last Modified: 16 Apr 2026

    Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.

    Published: 8 Feb 1996
    7.2
    High

    CVE-1999-1491

    Last Modified: 16 Apr 2026

    abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.

    Published: 2 Feb 1996
    10
    Critical

    CVE-1999-1319

    Last Modified: 16 Apr 2026

    Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.

    Published: 3 Jan 1996
    7.2
    High

    CVE-1999-1186

    Last Modified: 16 Apr 2026

    rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.

    Published: 2 Jan 1996
    10
    Critical

    CVE-1999-0208

    Last Modified: 16 Apr 2026

    rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

    Published: 12 Dec 1995
    3.7
    Low

    CVE-1999-0123

    Last Modified: 16 Apr 2026

    Race condition in Linux mailx command allows local users to read user files.

    Published: 1 Dec 1995
    7.2
    High

    CVE-1999-0316

    Last Modified: 16 Apr 2026

    Buffer overflow in Linux splitvt command gives root access to local users.

    Published: 1 Dec 1995
    7.2
    High

    CVE-1999-0325

    Last Modified: 16 Apr 2026

    vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.

    Published: 1 Dec 1995
    10
    Critical

    CVE-1999-0080

    Last Modified: 16 Apr 2026

    Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.

    Published: 30 Nov 1995
    10
    Critical

    CVE-1999-0241

    Last Modified: 16 Apr 2026

    Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.

    Published: 1 Nov 1995
    10
    Critical

    CVE-1999-0099

    Last Modified: 16 Apr 2026

    Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.

    Published: 19 Oct 1995
    10
    Critical

    CVE-1999-0073

    Last Modified: 16 Apr 2026

    Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.

    Published: 13 Oct 1995
    5
    Medium

    CVE-1999-0218

    Last Modified: 16 Apr 2026

    Livingston portmaster machines could be rebooted via a series of commands.

    Published: 1 Oct 1995
    4.6
    Medium

    CVE-1999-0245

    Last Modified: 16 Apr 2026

    Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".

    Published: 7 Sept 1995
    7.5
    High

    CVE-1999-0155

    Last Modified: 16 Apr 2026

    The ghostscript command with the -dSAFER option allows remote attackers to execute commands.

    Published: 31 Aug 1995