CVE-1999-0950
Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
CVE-1999-0949
Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.
CVE-1999-0948
Buffer overflow in uum program for Canna input system allows local users to gain root privileges.
CVE-1999-0947
AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via shell metacharacters.
CVE-1999-0946
Buffer overflow in Yamaha MidiPlug via a Text variable in an EMBED tag.
CVE-1999-0944
IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.
CVE-1999-0943
Buffer overflow in OpenLink 3.2 allows remote attackers to gain privileges via a long GET request to the web configurator.
CVE-1999-0935
classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.
CVE-1999-0934
classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.
CVE-1999-0933
TeamTrack web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-1999-0931
Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.
CVE-1999-0928
Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.
CVE-1999-0927
NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-1999-0926
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
CVE-1999-0925
UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.
CVE-1999-0920
Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.
CVE-1999-0918
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
CVE-1999-0915
URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-1999-0914
Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
CVE-1999-0913
dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.
CVE-1999-0912
FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.
CVE-1999-0911
Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
CVE-1999-0908
Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result of recursive calls to mutex_enter.
CVE-1999-0906
Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.
CVE-1999-0905
Denial of service in Axent Raptor firewall via malformed zero-length IP options.
CVE-1999-0904
Buffer overflow in BFTelnet allows remote attackers to cause a denial of service via a long username.
CVE-1999-0899
The Windows NT 4.0 print spooler allows a local user to execute arbitrary commands due to inappropriate permissions that allow the user to specify an alternate print provider.
CVE-1999-0896
Buffer overflow in RealNetworks RealServer administration utility allows remote attackers to execute arbitrary commands via a long username and password.
CVE-1999-0893
userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.
CVE-1999-0891
The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.
CVE-1999-0888
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
CVE-1999-0887
FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.
CVE-1999-0886
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
CVE-1999-0885
Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.
CVE-1999-0879
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via macro variables in a message file.
CVE-1999-0877
Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.
CVE-1999-0875
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
CVE-1999-0874
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.
CVE-1999-0869
Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.
CVE-1999-0867
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
CVE-1999-0866
Buffer overflow in UnixWare xauto program allows local users to gain root privilege.
CVE-1999-0864
UnixWare programs that dump core allow a local user to modify files via a symlink attack on the ./core.pid file.
CVE-1999-0860
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
CVE-1999-0859
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
CVE-1999-0857
FreeBSD gdc program allows local users to modify files via a symlink attack.
CVE-1999-0848
Denial of service in BIND named via consuming more than "fdmax" file descriptors.
CVE-1999-0845
Buffer overflow in SCO su program allows local users to gain root access via a long username.
CVE-1999-0844
Denial of service in MDaemon WorldClient and WebConfig services via a long URL.
