CVE-1999-0131
Last Modified: 16 Apr 2026Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
CVE-1999-1252
Last Modified: 16 Apr 2026Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.
CVE-1999-0324
Last Modified: 16 Apr 2026ppl program in HP-UX allows local users to create root files through symlinks.
CVE-1999-1309
Last Modified: 16 Apr 2026Sendmail before 8.6.7 allows local users to gain root access via a large value in the debug (-d) command line option.
CVE-1999-1187
Last Modified: 16 Apr 2026Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.
CVE-1999-0085
Last Modified: 16 Apr 2026Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.
CVE-1999-0132
Last Modified: 16 Apr 2026Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.
CVE-1999-0133
Last Modified: 16 Apr 2026fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.
CVE-1999-0134
Last Modified: 16 Apr 2026vold in Solaris 2.x allows local users to gain root access.
CVE-1999-1413
Last Modified: 16 Apr 2026Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
CVE-1999-0335
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-1999-0136
Last Modified: 16 Apr 2026Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.
CVE-1999-0135
Last Modified: 16 Apr 2026admintool in Solaris allows a local user to write to arbitrary files and gain root access.
CVE-1999-0023
Last Modified: 16 Apr 2026Local user gains root privileges via buffer overflow in rdist, via lookup() function.
CVE-1999-1301
Last Modified: 16 Apr 2026A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.
CVE-1999-1572
Last Modified: 16 Apr 2026cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.
CVE-1999-0137
Last Modified: 16 Apr 2026The dip program on many Linux systems allows local users to gain root access via a buffer overflow.
CVE-1999-0022
Last Modified: 16 Apr 2026Local user gains root privileges via buffer overflow in rdist, via expstr() function.
CVE-1999-0175
Last Modified: 16 Apr 2026The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.
CVE-1999-0138
Last Modified: 16 Apr 2026The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
CVE-1999-1205
Last Modified: 16 Apr 2026nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.
CVE-1999-1253
Last Modified: 16 Apr 2026Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.
CVE-1999-0509
Last Modified: 16 Apr 2026Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.
CVE-1999-0522
Last Modified: 16 Apr 2026The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.
CVE-1999-1313
Last Modified: 16 Apr 2026Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.
CVE-1999-1314
Last Modified: 16 Apr 2026Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.
CVE-1999-0019
Last Modified: 16 Apr 2026Delete or create a file via rpc.statd, due to invalid information.
CVE-1999-0078
Last Modified: 16 Apr 2026pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.
CVE-1999-1103
Last Modified: 16 Apr 2026dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.
CVE-1999-0070
Last Modified: 16 Apr 2026test-cgi program allows an attacker to list files on the server.
CVE-1999-0141
Last Modified: 16 Apr 2026Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.
CVE-1999-0067
Last Modified: 16 Apr 2026phf CGI program allows remote command execution through shell metacharacters.
CVE-1999-0142
Last Modified: 16 Apr 2026The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.
CVE-1999-0233
Last Modified: 16 Apr 2026IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
CVE-1999-0143
Last Modified: 16 Apr 2026Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.
CVE-1999-0103
Last Modified: 16 Apr 2026Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.
CVE-1999-1491
Last Modified: 16 Apr 2026abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.
CVE-1999-1319
Last Modified: 16 Apr 2026Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.
CVE-1999-1186
Last Modified: 16 Apr 2026rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.
CVE-1999-0208
Last Modified: 16 Apr 2026rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
CVE-1999-0123
Last Modified: 16 Apr 2026Race condition in Linux mailx command allows local users to read user files.
CVE-1999-0316
Last Modified: 16 Apr 2026Buffer overflow in Linux splitvt command gives root access to local users.
CVE-1999-0325
Last Modified: 16 Apr 2026vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.
CVE-1999-0080
Last Modified: 16 Apr 2026Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.
CVE-1999-0241
Last Modified: 16 Apr 2026Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.
CVE-1999-0099
Last Modified: 16 Apr 2026Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
CVE-1999-0073
Last Modified: 16 Apr 2026Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.
CVE-1999-0218
Last Modified: 16 Apr 2026Livingston portmaster machines could be rebooted via a series of commands.
CVE-1999-0245
Last Modified: 16 Apr 2026Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".
CVE-1999-0155
Last Modified: 16 Apr 2026The ghostscript command with the -dSAFER option allows remote attackers to execute commands.
