10
    Critical

    CVE-2000-0002

    Last Modified: 16 Jul 2012

    Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.

    Source:Ussr Labs
    Published:22 Dec 1999
    5
    Medium

    CVE-2000-0001

    Last Modified: 8 Jul 2012

    RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.

    Source:bow
    Published:23 Dec 1999
    9.8
    Critical

    CVE-1999-1588

    Last Modified: 18 Aug 2012

    Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.

    Source:Last Stage of Delirium
    Published:31 Dec 1999
    2.1
    Low

    CVE-1999-1587

    Last Modified: 14 Nov 2016

    /usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.

    Source:Marco Ivaldi
    Published:31 Dec 1999
    5.1
    Medium

    CVE-1999-1578

    Last Modified: 2 Jul 2012

    Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands.

    Source:Shane Hird
    Published:24 Sept 1999
    5.1
    Medium

    CVE-1999-1577

    Last Modified: 1 Jul 2012

    Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method.

    Source:Shane Hird
    Published:31 Oct 1999
    7.5
    High

    CVE-1999-1576

    Last Modified: 1 Jul 2012

    Buffer overflow in Adobe Acrobat ActiveX control (pdf.ocx, PDF.PdfCtrl.1) 1.3.188 for Acrobat Reader 4.0 allows remote attackers to execute arbitrary code via the pdf.setview method.

    Source:Shane Hird
    Published:27 Sept 1999
    5.1
    Medium

    CVE-1999-1575

    Last Modified: 2 Jul 2012

    The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet Explorer (IE) 4.01 and 5.0 are marked as "Safe for Scripting," which allows remote attackers to create and modify files and execute arbitrary commands.

    Source:Shane Hird
    Published:10 Sept 1999
    5
    Medium

    CVE-1999-1569

    Last Modified: 2 Sept 2012

    Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's player limit.

    Source:Andy Gavin
    Published:17 Jul 2001
    5
    Medium

    CVE-1999-1566

    Last Modified: 25 Oct 2012

    Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters.

    Source:wh00t
    Published:8 May 1999
    5
    Medium

    CVE-1999-1557

    Last Modified: 23 Jun 2012

    Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.

    Source:Marc of eEye
    Published:12 Sept 2001
    7.2
    High

    CVE-1999-1555

    Last Modified: 11 Jun 2012

    Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FULL CONTROL" permissions, which allows local users to cause Inoculan's antivirus update feature to install a Trojan horse dll.

    Source:Paul Boyer
    Published:11 Jun 1998
    10
    Critical

    CVE-1999-1553

    Last Modified: 15 Nov 2017

    Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.

    Source:Arthur
    Published:1 May 1999
    5
    Medium

    CVE-1999-1551

    Last Modified: 23 Jun 2012

    Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.

    Source:Marc of eEye
    Published:2 Mar 1999
    4.6
    Medium

    CVE-1999-1543

    Last Modified: 27 Jun 2012

    MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.

    Source:Dawid adix Adamski
    Published:10 Jul 1999
    7.5
    High

    CVE-1999-1539

    Last Modified: 7 Jul 2012

    Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.

    Source:Ussr Labs
    Published:10 Nov 1999
    2.1
    Low

    CVE-1999-1538

    Last Modified: 31 Mar 2017

    When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.

    Source:Mnemonix
    Published:14 Jan 1999
    7.2
    High

    CVE-1999-1534

    Last Modified: 23 Jul 2018

    Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.

    Source:Brock Tellier
    Published:23 Sept 1999
    7.5
    High

    CVE-1999-1533

    Last Modified: 1 Jul 2012

    Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service.

    Source:Bjorn Stickler
    Published:7 Nov 1999
    5
    Medium

    CVE-1999-1532

    Last Modified: 28 Oct 2017

    Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.

    Source:Nobuo Miwa
    Published:29 Oct 1999
    7.5
    High

    CVE-1999-1531

    Last Modified: 4 Jul 2012

    Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag.

    Source:UNYUN
    Published:2 Nov 1999
    7.5
    High

    CVE-1999-1529

    Last Modified: 5 Jul 2012

    A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code.

    Source:Alain Thivillon & Stephane Aubert
    Published:7 Nov 1999
    10
    Critical

    CVE-1999-1521

    Last Modified: 30 Jun 2012

    Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server.

    Source:UNYUN
    Published:12 Sept 1999
    5
    Medium

    CVE-1999-1520

    Last Modified: 16 Jun 2012

    A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.

    Source:Andrey Kruchkov
    Published:11 May 1999
    5
    Medium

    CVE-1999-1519

    Last Modified: 7 Jul 2012

    Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password.

    Source:Ussr Labs
    Published:17 Nov 1999
    5
    Medium

    CVE-1999-1518

    Last Modified: 21 Sept 2016

    Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.

    Source:Mike Perry
    Published:15 Jul 1999
    5
    Medium

    CVE-1999-1515

    Last Modified: 30 Jun 2012

    A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds.

    Source:anonymous
    Published:31 Aug 1999
    7.5
    High

    CVE-1999-1510

    Last Modified: 16 Jun 2012

    Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.

    Source:Arne Vidstrom
    Published:17 May 1999
    5
    Medium

    CVE-1999-1509

    Last Modified: 5 Jul 2012

    Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.

    Source:Ussr Labs
    Published:4 Nov 1999
    10
    Critical

    CVE-1999-1508

    Last Modified: 6 Jul 2012

    Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.

    Source:Dennis W. Mattison
    Published:16 Nov 1999
    5
    Medium

    CVE-1999-1504

    Last Modified: 2 Jan 2014

    Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.

    Source:David Luyer
    Published:8 Apr 1998
    2.1
    Low

    CVE-1999-1499

    Last Modified: 11 Jun 2012

    named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.

    Source:Joe H
    Published:10 Apr 1998
    3.6
    Low

    CVE-1999-1498

    Last Modified: 11 Jun 2012

    Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.

    Source:neonhaze
    Published:6 Apr 1998
    7.2
    High

    CVE-1999-1497

    Last Modified: 27 Oct 2016

    Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.

    Source:Mike Davis
    Published:21 Dec 1999
    2.1
    Low

    CVE-1999-1494

    Last Modified: 22 Nov 2017

    colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.

    Source:Dave Sill
    Published:9 Aug 1994
    7.2
    High

    CVE-1999-1491

    Last Modified: 18 Jun 2012

    abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.

    Source:David J Meltzer
    Published:2 Feb 1996
    7.2
    High

    CVE-1999-1490

    Last Modified: 18 Jun 2012

    xosview 1.5.1 in Red Hat 5.1 allows local users to gain root access via a long HOME environmental variable.

    Source:Chris Evans
    Published:28 May 1998
    7.2
    High

    CVE-1999-1489

    Last Modified: 15 Nov 2017

    Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.

    Source:Solar
    Published:4 Mar 1997
    5
    Medium

    CVE-1999-1488

    Last Modified: 15 Nov 2017

    sdrd daemon in IBM SP2 System Data Repository (SDR) allows remote attackers to read files without authentication.

    Source:Chuck Athey & Jim Garlick
    Published:31 Dec 1999
    6.4
    Medium

    CVE-1999-1485

    Last Modified: 16 Nov 2017

    nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system.

    Source:Jefferson Ogata
    Published:31 May 1999
    7.5
    High

    CVE-1999-1484

    Last Modified: 1 Jul 2012

    Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.

    Source:Shane Hird
    Published:24 Sept 1999
    4.6
    Medium

    CVE-1999-1483

    Last Modified: 30 Aug 2016

    Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.

    Source:BeastMaster V
    Published:19 Jun 1997
    5
    Medium

    CVE-1999-1481

    Last Modified: 3 Jul 2012

    Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.

    Source:Oezguer Kesim
    Published:31 Dec 1999
    10
    Critical

    CVE-1999-1479

    Last Modified: 17 Aug 2012

    The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.

    Source:Doru Petrescu
    Published:24 Jun 1998
    7.2
    High

    CVE-1999-1477

    Last Modified: 1 Jul 2012

    Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.

    Source:Brock Tellier
    Published:23 Sept 1999
    7.2
    High

    CVE-1999-1461

    Last Modified: 20 Jun 2012

    inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.

    Source:Yuri Volobuev
    Published:7 May 1997
    7.2
    High

    CVE-1999-1460

    Last Modified: 27 Jun 2012

    BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.

    Source:Andrew Alness
    Published:13 Jul 1999
    2.6
    Low

    CVE-1999-1453

    Last Modified: 14 Jun 2012

    Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.

    Source:Juan Carlos Garcia Cuartango
    Published:2 Feb 1999
    7.2
    High

    CVE-1999-1442

    Last Modified: 11 Jun 2012

    Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments.

    Source:Poulot-Cazajous
    Published:22 Jun 1998
    2.1
    Low

    CVE-1999-1441

    Last Modified: 11 Jun 2012

    Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it.

    Source:David Luyer
    Published:30 Jun 1998