CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-1999-1298

    Last Modified: 16 Apr 2026

    Sysinstall in FreeBSD 2.2.1 and earlier, when configuring anonymous FTP, creates the ftp user without a password and with /bin/date as the shell, which could allow attackers to gain access to certain system resources.

    Published: 7 Apr 1997
    5
    Medium

    CVE-1999-1387

    Last Modified: 16 Apr 2026

    Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.

    Published: 2 Apr 1997
    7.2
    High

    CVE-1999-0315

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris fdformat command gives root access to local users.

    Published: 1 Apr 1997
    7.5
    High

    CVE-1999-0280

    Last Modified: 16 Apr 2026

    Remote command execution in Microsoft Internet Explorer using .lnk and .url files.

    Published: 1 Apr 1997
    5
    Medium

    CVE-1999-0292

    Last Modified: 16 Apr 2026

    Denial of service through Winpopup using large user names.

    Published: 1 Apr 1997
    5.1
    Medium

    CVE-1999-1525

    Last Modified: 16 Apr 2026

    Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.

    Published: 14 Mar 1997
    2.1
    Low

    CVE-1999-1408

    Last Modified: 16 Apr 2026

    Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

    Published: 5 Mar 1997
    9.3
    Critical

    CVE-1999-0299

    Last Modified: 16 Apr 2026

    Buffer overflow in FreeBSD lpd through long DNS hostnames.

    Published: 5 Mar 1997
    7.2
    High

    CVE-1999-1489

    Last Modified: 16 Apr 2026

    Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.

    Published: 4 Mar 1997
    2.1
    Low

    CVE-1999-0106

    Last Modified: 16 Apr 2026

    Finger redirection allows finger bombs.

    Published: 1 Mar 1997
    0
    Low

    CVE-1999-0612

    Last Modified: 16 Apr 2026

    A version of finger is running that exposes valid user information to any entity on the network.

    Published: 1 Mar 1997
    10
    Critical

    CVE-1999-0165

    Last Modified: 16 Apr 2026

    NFS cache poisoning.

    Published: 1 Mar 1997
    5.1
    Medium

    CVE-1999-1128

    Last Modified: 16 Apr 2026

    Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.

    Published: 1 Mar 1997
    7.2
    High

    CVE-1999-0318

    Last Modified: 16 Apr 2026

    Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.

    Published: 1 Mar 1997
    2.1
    Low

    CVE-1999-0105

    Last Modified: 16 Apr 2026

    finger allows recursive searches by using a long string of @ symbols.

    Published: 1 Mar 1997
    7.2
    High

    CVE-1999-0868

    Last Modified: 16 Apr 2026

    ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.

    Published: 20 Feb 1997
    7.5
    High

    CVE-1999-0041

    Last Modified: 16 Apr 2026

    Buffer overflow in NLS (Natural Language Service).

    Published: 13 Feb 1997
    7.2
    High

    CVE-1999-0109

    Last Modified: 16 Apr 2026

    Buffer overflow in ffbconfig in Solaris 2.5.1.

    Published: 10 Feb 1997
    5
    Medium

    CVE-1999-0228

    Last Modified: 16 Apr 2026

    Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.

    Published: 7 Feb 1997
    10
    Critical

    CVE-1999-0046

    Last Modified: 16 Apr 2026

    Buffer overflow of rlogin program using TERM environmental variable.

    Published: 6 Feb 1997
    7.5
    High

    CVE-1999-0298

    Last Modified: 16 Apr 2026

    ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.

    Published: 5 Feb 1997
    10
    Critical

    CVE-1999-1299

    Last Modified: 16 Apr 2026

    rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.

    Published: 3 Feb 1997
    10
    Critical

    CVE-1999-1160

    Last Modified: 16 Apr 2026

    Vulnerability in ftpd/kftpd in HP-UX 10.x and 9.x allows local and possibly remote users to gain root privileges.

    Published: 2 Feb 1997
    7.2
    High

    CVE-1999-0369

    Last Modified: 16 Apr 2026

    The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.

    Published: 1 Feb 1997
    7.2
    High

    CVE-1999-0959

    Last Modified: 16 Apr 2026

    IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.

    Published: 1 Feb 1997
    7.2
    High

    CVE-1999-0309

    Last Modified: 16 Apr 2026

    HP-UX vgdisplay program gives root access to local users.

    Published: 1 Feb 1997
    6.4
    Medium

    CVE-1999-0174

    Last Modified: 16 Apr 2026

    The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.

    Published: 1 Feb 1997
    7.2
    High

    CVE-1999-1144

    Last Modified: 16 Apr 2026

    Certain files in MPower in HP-UX 10.x are installed with insecure permissions, which allows local users to gain privileges.

    Published: 30 Jan 1997
    10
    Critical

    CVE-1999-0047

    Last Modified: 16 Apr 2026

    MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.

    Published: 28 Jan 1997
    10
    Critical

    CVE-1999-0048

    Last Modified: 16 Apr 2026

    Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.

    Published: 27 Jan 1997
    7.2
    High

    CVE-1999-0966

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0].

    Published: 27 Jan 1997
    5
    Medium

    CVE-1999-0081

    Last Modified: 16 Apr 2026

    wu-ftp allows files to be overwritten via the rnfr command.

    Published: 11 Jan 1997
    7.2
    High

    CVE-1999-1088

    Last Modified: 16 Apr 2026

    Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.

    Published: 9 Jan 1997
    7.2
    High

    CVE-1999-0049

    Last Modified: 16 Apr 2026

    Csetup under IRIX allows arbitrary file creation or overwriting.

    Published: 8 Jan 1997
    4.6
    Medium

    CVE-1999-1311

    Last Modified: 16 Apr 2026

    Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.

    Published: 7 Jan 1997
    7.2
    High

    CVE-1999-1145

    Last Modified: 16 Apr 2026

    Vulnerability in Glance programs in GlancePlus for HP-UX 10.20 and earlier allows local users to access arbitrary files and gain privileges.

    Published: 7 Jan 1997
    7.2
    High

    CVE-1999-0051

    Last Modified: 16 Apr 2026

    Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.

    Published: 6 Jan 1997
    4.6
    Medium

    CVE-1999-1249

    Last Modified: 16 Apr 2026

    movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges.

    Published: 6 Jan 1997
    4.6
    Medium

    CVE-1999-1120

    Last Modified: 16 Apr 2026

    netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.

    Published: 4 Jan 1997
    5.9
    Medium

    CVE-1999-0517

    Last Modified: 28 May 2026

    An SNMP community name is the default (e.g. public), null, or missing.

    Published: 1 Jan 1997
    5
    Medium

    CVE-1999-0345

    Last Modified: 16 Apr 2026

    Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.

    Published: 1 Jan 1997
    10
    Critical

    CVE-1999-0100

    Last Modified: 16 Apr 2026

    Remote access in AIX innd 1.5.1, using control messages.

    Published: 1 Jan 1997
    5
    Medium

    CVE-1999-0166

    Last Modified: 16 Apr 2026

    NFS allows users to use a "cd .." command to access other directories besides the exported file system.

    Published: 1 Jan 1997
    7.2
    High

    CVE-1999-0163

    Last Modified: 16 Apr 2026

    In older versions of Sendmail, an attacker could use a pipe character to execute root commands.

    Published: 1 Jan 1997
    5
    Medium

    CVE-1999-0173

    Last Modified: 16 Apr 2026

    FormMail CGI program can be used by web servers other than the host server that the program resides on.

    Published: 1 Jan 1997
    7.5
    High

    CVE-1999-0504

    Last Modified: 16 Apr 2026

    A Windows NT local user or administrator account has a default, null, blank, or missing password.

    Published: 1 Jan 1997
    7.5
    High

    CVE-1999-0499

    Last Modified: 16 Apr 2026

    NETBIOS share information may be published through SNMP registry keys in NT.

    Published: 1 Jan 1997
    0
    Low

    CVE-1999-0525

    Last Modified: 16 Apr 2026

    IP traceroute is allowed from arbitrary hosts.

    Published: 1 Jan 1997
    10
    Critical

    CVE-1999-0535

    Last Modified: 16 Apr 2026

    A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.

    Published: 1 Jan 1997
    7.5
    High

    CVE-1999-0550

    Last Modified: 16 Apr 2026

    A router's routing tables can be obtained from arbitrary hosts.

    Published: 1 Jan 1997