7.2
    High

    CVE-1999-1414

    Last Modified: 15 Nov 2017

    IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.

    Source:Thomas Krug
    Published:25 May 1999
    4.6
    Medium

    CVE-1999-1413

    Last Modified: 15 Nov 2017

    Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

    Source:Jungseok Roh
    Published:3 Aug 1996
    5
    Medium

    CVE-1999-1412

    Last Modified: 17 Jun 2012

    A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

    Source:Juergen Schmidt
    Published:3 Jun 1999
    6.2
    Medium

    CVE-1999-1410

    Last Modified: 17 Jun 2012

    addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.

    Source:Jaechul Choe
    Published:9 May 1997
    2.1
    Low

    CVE-1999-1409

    Last Modified: 22 Nov 2017

    The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.

    Source:Gutierrez
    Published:3 Jul 1998
    2.1
    Low

    CVE-1999-1408

    Last Modified: 18 Jun 2012

    Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

    Source:Cahya Wirawan
    Published:5 Mar 1997
    10
    Critical

    CVE-1999-1405

    Last Modified: 20 Jun 2012

    snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

    Source:Larry W. Cashdollar
    Published:17 Feb 1999
    2.1
    Low

    CVE-1999-1402

    Last Modified: 22 Jun 2012

    The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket.

    Source:Thamer Al-Herbish
    Published:17 May 1997
    7.2
    High

    CVE-1999-1399

    Last Modified: 22 Jun 2012

    spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.

    Source:J.A. Guitierrez
    Published:20 Aug 1997
    6.2
    Medium

    CVE-1999-1398

    Last Modified: 16 Nov 2017

    Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.

    Source:Yuri Volobuev
    Published:7 May 1997
    2.1
    Low

    CVE-1999-1394

    Last Modified: 27 Jun 2012

    BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a device.

    Source:Stealth
    Published:2 Jul 1999
    7.2
    High

    CVE-1999-1390

    Last Modified: 15 Nov 2017

    suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.

    Source:Thomas Roessler
    Published:28 Apr 1998
    7.2
    High

    CVE-1999-1384

    Last Modified: 30 Oct 2017

    Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.

    Source:Tun-Hui Hu
    Published:30 Oct 1996
    5
    Medium

    CVE-1999-1375

    Last Modified: 16 Jun 2012

    FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

    Source:Gary Geisbert
    Published:11 Feb 1999
    7.2
    High

    CVE-1999-1371

    Last Modified: 16 Apr 2026

    Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.

    Source:Pablo Sor
    Published:8 Mar 1999
    7.2
    High

    CVE-1999-1340

    Last Modified: 4 Jul 2012

    Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.

    Source:Brock Tellier
    Published:4 Nov 1999
    7.2
    High

    CVE-1999-1286

    Last Modified: 17 Jun 2012

    addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.

    Source:Jaechul Choe
    Published:9 May 1997
    4.6
    Medium

    CVE-1999-1243

    Last Modified: 5 Aug 2012

    SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges.

    Source:Larry Glaze
    Published:3 Mar 1995
    4.6
    Medium

    CVE-1999-1235

    Last Modified: 30 Jun 2012

    Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.

    Source:Makoto Shiotsuki
    Published:25 Aug 1999
    7.2
    High

    CVE-1999-1219

    Last Modified: 22 Nov 2017

    Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.

    Source:anonymous
    Published:11 Aug 1994
    7.2
    High

    CVE-1999-1208

    Last Modified: 20 Jun 2012

    Buffer overflow in ping in AIX 4.2 and earlier allows local users to gain root privileges via a long command line argument.

    Source:Bryan P. Self
    Published:21 Jul 1997
    7.2
    High

    CVE-1999-1194

    Last Modified: 16 Nov 2017

    chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.

    Source:anonymous
    Published:1 May 1991
    7.2
    High

    CVE-1999-1191

    Last Modified: 27 Oct 2016

    Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument.

    Source:Joe Zbiciak
    Published:19 May 1997
    10
    Critical

    CVE-1999-1190

    Last Modified: 5 Jul 2012

    Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.

    Source:UNYUN
    Published:15 Nov 1999
    7.2
    High

    CVE-1999-1185

    Last Modified: 16 Apr 2026

    Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.

    Source:K2
    Published:6 Oct 1998
    4.6
    Medium

    CVE-1999-1184

    Last Modified: 20 Nov 2012

    Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.

    Source:kokanin
    Published:13 May 1997
    4.6
    Medium

    CVE-1999-1171

    Last Modified: 27 Sept 2016

    IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

    Source:Marc
    Published:2 Feb 1999
    4.6
    Medium

    CVE-1999-1170

    Last Modified: 27 Sept 2016

    IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

    Source:Marc
    Published:2 Jan 1999
    7.2
    High

    CVE-1999-1166

    Last Modified: 27 Jun 2012

    Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.

    Source:Solar
    Published:11 Jul 1999
    7.2
    High

    CVE-1999-1158

    Last Modified: 27 Oct 2016

    Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.

    Source:Cristian Schipor
    Published:13 May 1997
    5
    Medium

    CVE-1999-1130

    Last Modified: 28 Jun 2012

    Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.

    Source:David Litchfield
    Published:30 Jul 1999
    7.2
    High

    CVE-1999-1123

    Last Modified: 16 Nov 2017

    The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.

    Source:anonymous
    Published:20 May 1991
    4.6
    Medium

    CVE-1999-1120

    Last Modified: 20 Jun 2012

    netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.

    Source:Yuri Volobuev
    Published:4 Jan 1997
    2.1
    Low

    CVE-1999-1117

    Last Modified: 15 Nov 2017

    lquerypv in AIX 4.1 and 4.2 allows local users to read arbitrary files by specifying the file in the -h command line parameter.

    Source:Aleph1
    Published:31 Dec 1999
    7.2
    High

    CVE-1999-1114

    Last Modified: 22 Jun 2012

    Buffer overflow in Korn Shell (ksh) suid_exec program on IRIX 6.x and earlier, and possibly other operating systems, allows local users to gain root privileges.

    Source:Yuri Volobuev
    Published:8 Apr 1998
    5
    Medium

    CVE-1999-1113

    Last Modified: 11 Jun 2012

    Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a long USER command to port 106.

    Source:Netstat Webmaster
    Published:14 Apr 1998
    7.5
    High

    CVE-1999-1112

    Last Modified: 31 Oct 2016

    Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.

    Source:UNYUN
    Published:9 Nov 1999
    5
    Medium

    CVE-1999-1110

    Last Modified: 5 Jul 2012

    Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.

    Source:Georgi Guninski
    Published:14 Nov 1999
    5
    Medium

    CVE-1999-1109

    Last Modified: 9 Jul 2012

    Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then disconnecting from the server, while Sendmail continues to process the commands after the connection has been terminated.

    Source:Michal Zalewski
    Published:22 Dec 1999
    4.6
    Medium

    CVE-1999-1084

    Last Modified: 13 Jul 2012

    The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

    Source:anonymous
    Published:31 Dec 1999
    5
    Medium

    CVE-1999-1083

    Last Modified: 9 Mar 2018

    Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.

    Source:Jason Lutz
    Published:8 Oct 1999
    5
    Medium

    CVE-1999-1082

    Last Modified: 9 Mar 2018

    Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.

    Source:Jason Lutz
    Published:8 Oct 1999
    5
    Medium

    CVE-1999-1081

    Last Modified: 13 Aug 2012

    Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.

    Source:anonymous
    Published:12 Sept 2001
    5
    Medium

    CVE-1999-1069

    Last Modified: 14 Aug 2012

    Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.

    Source:Mikael Johansson
    Published:8 Nov 1997
    10
    Critical

    CVE-1999-1063

    Last Modified: 17 Jun 2012

    CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.

    Source:Salvatore Sanfilippo -antirez-
    Published:1 Jun 1999
    7.5
    High

    CVE-1999-1053

    Last Modified: 27 Oct 2016

    guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".

    Source:Metasploit
    Published:13 Sept 1999
    5
    Medium

    CVE-1999-1050

    Last Modified: 5 Jul 2012

    Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.

    Source:m4rcyS
    Published:12 Nov 1999
    10
    Critical

    CVE-1999-1046

    Last Modified: 23 Jun 2012

    Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.

    Source:Marc of eEye
    Published:1 Mar 1999
    7.2
    High

    CVE-1999-1041

    Last Modified: 16 Apr 2026

    Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.

    Source:K2
    Published:27 Aug 1998
    5
    Medium

    CVE-1999-1033

    Last Modified: 16 Jun 2012

    Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.

    Source:Miquel van Smoorenburg
    Published:11 May 1999