CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-1999-1572

    Last Modified: 16 Apr 2026

    cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.

    Published: 16 Jul 1996
    7.2
    High

    CVE-1999-0137

    Last Modified: 16 Apr 2026

    The dip program on many Linux systems allows local users to gain root access via a buffer overflow.

    Published: 9 Jul 1996
    7.8
    High

    CVE-1999-0022

    Last Modified: 16 Apr 2026

    Local user gains root privileges via buffer overflow in rdist, via expstr() function.

    Published: 3 Jul 1996
    5
    Medium

    CVE-1999-0175

    Last Modified: 16 Apr 2026

    The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.

    Published: 1 Jul 1996
    7.2
    High

    CVE-1999-0138

    Last Modified: 16 Apr 2026

    The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.

    Published: 26 Jun 1996
    2.1
    Low

    CVE-1999-1205

    Last Modified: 16 Apr 2026

    nettune in HP-UX 10.01 and 10.00 is installed setuid root, which allows local users to cause a denial of service by modifying critical networking configuration information.

    Published: 7 Jun 1996
    7.2
    High

    CVE-1999-1253

    Last Modified: 16 Apr 2026

    Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.

    Published: 7 Jun 1996
    10
    Critical

    CVE-1999-0509

    Last Modified: 16 Apr 2026

    Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.

    Published: 29 May 1996
    7.2
    High

    CVE-1999-0522

    Last Modified: 16 Apr 2026

    The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.

    Published: 28 May 1996
    4.6
    Medium

    CVE-1999-1313

    Last Modified: 16 Apr 2026

    Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.

    Published: 23 May 1996
    2.1
    Low

    CVE-1999-1314

    Last Modified: 16 Apr 2026

    Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.

    Published: 17 May 1996
    5
    Medium

    CVE-1999-0019

    Last Modified: 16 Apr 2026

    Delete or create a file via rpc.statd, due to invalid information.

    Published: 24 Apr 1996
    1.9
    Low

    CVE-1999-0078

    Last Modified: 16 Apr 2026

    pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

    Published: 18 Apr 1996
    4.6
    Medium

    CVE-1999-1103

    Last Modified: 16 Apr 2026

    dxconsole in DEC OSF/1 3.2C and earlier allows local users to read arbitrary files by specifying the file with the -file parameter.

    Published: 3 Apr 1996
    5
    Medium

    CVE-1999-0070

    Last Modified: 16 Apr 2026

    test-cgi program allows an attacker to list files on the server.

    Published: 1 Apr 1996
    3.7
    Low

    CVE-1999-0141

    Last Modified: 16 Apr 2026

    Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.

    Published: 29 Mar 1996
    10
    Critical

    CVE-1999-0067

    Last Modified: 16 Apr 2026

    phf CGI program allows remote command execution through shell metacharacters.

    Published: 20 Mar 1996
    7.5
    High

    CVE-1999-0142

    Last Modified: 16 Apr 2026

    The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.

    Published: 1 Mar 1996
    10
    Critical

    CVE-1999-0233

    Last Modified: 16 Apr 2026

    IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.

    Published: 25 Feb 1996
    4.6
    Medium

    CVE-1999-0143

    Last Modified: 16 Apr 2026

    Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.

    Published: 21 Feb 1996
    5
    Medium

    CVE-1999-0103

    Last Modified: 16 Apr 2026

    Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.

    Published: 8 Feb 1996
    7.2
    High

    CVE-1999-1491

    Last Modified: 16 Apr 2026

    abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.

    Published: 2 Feb 1996
    10
    Critical

    CVE-1999-1319

    Last Modified: 16 Apr 2026

    Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.

    Published: 3 Jan 1996
    7.2
    High

    CVE-1999-1186

    Last Modified: 16 Apr 2026

    rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.

    Published: 2 Jan 1996
    10
    Critical

    CVE-1999-0208

    Last Modified: 16 Apr 2026

    rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

    Published: 12 Dec 1995
    3.7
    Low

    CVE-1999-0123

    Last Modified: 16 Apr 2026

    Race condition in Linux mailx command allows local users to read user files.

    Published: 1 Dec 1995
    7.2
    High

    CVE-1999-0316

    Last Modified: 16 Apr 2026

    Buffer overflow in Linux splitvt command gives root access to local users.

    Published: 1 Dec 1995
    7.2
    High

    CVE-1999-0325

    Last Modified: 16 Apr 2026

    vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.

    Published: 1 Dec 1995
    10
    Critical

    CVE-1999-0080

    Last Modified: 16 Apr 2026

    Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.

    Published: 30 Nov 1995
    10
    Critical

    CVE-1999-0241

    Last Modified: 16 Apr 2026

    Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.

    Published: 1 Nov 1995
    10
    Critical

    CVE-1999-0099

    Last Modified: 16 Apr 2026

    Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.

    Published: 19 Oct 1995
    10
    Critical

    CVE-1999-0073

    Last Modified: 16 Apr 2026

    Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.

    Published: 13 Oct 1995
    5
    Medium

    CVE-1999-0218

    Last Modified: 16 Apr 2026

    Livingston portmaster machines could be rebooted via a series of commands.

    Published: 1 Oct 1995
    4.6
    Medium

    CVE-1999-0245

    Last Modified: 16 Apr 2026

    Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".

    Published: 7 Sept 1995
    7.5
    High

    CVE-1999-0155

    Last Modified: 16 Apr 2026

    The ghostscript command with the -dSAFER option allows remote attackers to execute commands.

    Published: 31 Aug 1995
    6.2
    Medium

    CVE-1999-0164

    Last Modified: 16 Apr 2026

    A race condition in the Solaris ps command allows an attacker to overwrite critical files.

    Published: 29 Aug 1995
    7.2
    High

    CVE-1999-1580

    Last Modified: 16 Apr 2026

    SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option.

    Published: 23 Aug 1995
    10
    Critical

    CVE-1999-0203

    Last Modified: 16 Apr 2026

    In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.

    Published: 17 Aug 1995
    7.5
    High

    CVE-1999-0172

    Last Modified: 16 Apr 2026

    FormMail CGI program allows remote execution of commands.

    Published: 2 Aug 1995
    7.5
    High

    CVE-1999-0161

    Last Modified: 16 Apr 2026

    In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.

    Published: 31 Jul 1995
    9.8
    Critical

    CVE-1999-0066

    Last Modified: 16 Apr 2026

    AnyForm CGI remote execution.

    Published: 31 Jul 1995
    7.2
    High

    CVE-1999-1080

    Last Modified: 16 Apr 2026

    rmmount in SunOS 5.7 may mount file systems without the nosuid flag set, contrary to the documentation and its use in previous versions of SunOS, which could allow local users with physical access to gain root privileges by mounting a floppy or CD-ROM that contains a setuid program and running volcheck, when the file systems do not have the nosuid option specified in rmmount.conf.

    Published: 10 May 1995
    7.6
    High

    CVE-1999-0151

    Last Modified: 16 Apr 2026

    The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.

    Published: 3 Apr 1995
    5
    Medium

    CVE-1999-1098

    Last Modified: 16 Apr 2026

    Vulnerability in BSD Telnet client with encryption and Kerberos 4 authentication allows remote attackers to decrypt the session via sniffing.

    Published: 3 Mar 1995
    4.6
    Medium

    CVE-1999-1243

    Last Modified: 16 Apr 2026

    SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.

    Published: 3 Mar 1995
    7.5
    High

    CVE-1999-0242

    Last Modified: 16 Apr 2026

    Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.

    Published: 1 Mar 1995
    10
    Critical

    CVE-1999-0235

    Last Modified: 16 Apr 2026

    Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.

    Published: 17 Feb 1995
    10
    Critical

    CVE-1999-0232

    Last Modified: 16 Apr 2026

    Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.

    Published: 1 Feb 1995
    5
    Medium

    CVE-1999-0077

    Last Modified: 16 Apr 2026

    Predictable TCP sequence numbers allow spoofing.

    Published: 1 Jan 1995
    5
    Medium

    CVE-2000-0508

    Last Modified: 16 Apr 2026

    rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.

    Published: 19 Dec 1994