CVE-1999-0860
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.
CVE-1999-0859
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.
CVE-1999-0857
FreeBSD gdc program allows local users to modify files via a symlink attack.
CVE-1999-0848
Denial of service in BIND named via consuming more than "fdmax" file descriptors.
CVE-1999-0845
Buffer overflow in SCO su program allows local users to gain root access via a long username.
CVE-1999-0844
Denial of service in MDaemon WorldClient and WebConfig services via a long URL.
CVE-1999-0842
Symantec Mail-Gear 1.0 web interface server allows remote users to read arbitrary files via a .. (dot dot) attack.
CVE-1999-0841
Buffer overflow in CDE mailtool allows local users to gain root privileges via a long MIME Content-Type.
CVE-1999-0838
Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command.
CVE-1999-0836
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
CVE-1999-0834
Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.
CVE-1999-0830
Buffer overflow in SCO UnixWare Xsco command via a long argument.
CVE-1999-0828
UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.
CVE-1999-0826
Buffer overflow in FreeBSD angband allows local users to gain privileges.
CVE-1999-0825
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.
CVE-1999-0823
Buffer overflow in FreeBSD xmindpath allows local users to gain privileges via -f argument.
CVE-1999-0822
Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.
CVE-1999-0821
FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.
CVE-1999-0820
FreeBSD seyon allows users to gain privileges via a modified PATH variable for finding the xterm and seyon-emu commands.
CVE-1999-0819
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
CVE-1999-0818
Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.
CVE-1999-0811
Buffer overflow in Samba smbd program via a malformed message command.
CVE-1999-0804
Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.
CVE-1999-0803
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.
CVE-1999-0800
The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.
CVE-1999-0793
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
CVE-1999-0791
Hybrid Network cable modems do not include an authentication mechanism for administration, allowing remote attackers to compromise the system through the HSMP protocol.
CVE-1999-0787
The SSH authentication agent follows symlinks via a UNIX domain socket.
CVE-1999-0786
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable and a symlink attack.
CVE-1999-0778
Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query parameter.
CVE-1999-0774
Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.
CVE-1999-0773
Buffer overflow in Solaris lpset program allows local users to gain root access.
CVE-1999-0771
The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.
CVE-1999-0770
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.
CVE-1999-0769
Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
CVE-1999-0768
Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
CVE-1999-0767
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.
CVE-1999-0765
SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.
CVE-1999-0759
Buffer overflow in FuseMAIL POP service via long USER and PASS commands.
CVE-1999-0757
The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.
CVE-1999-0755
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
CVE-1999-0753
The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.
CVE-1999-0752
Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.
CVE-1999-0751
Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.
CVE-1999-0750
Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.
CVE-1999-0749
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
CVE-1999-0746
A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.
