CVE-1999-0321
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
CVE-1999-0315
Buffer overflow in Solaris fdformat command gives root access to local users.
CVE-1999-0314
ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.
CVE-1999-0294
All records in a WINS database can be deleted through SNMP for a denial of service.
CVE-1999-0288
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.
CVE-1999-0284
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
CVE-1999-0283
The Java Web Server would allow remote users to obtain the source code for CGI programs.
CVE-1999-0278
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
CVE-1999-0269
Netscape Enterprise servers may list files through the PageServices query.
CVE-1999-0268
MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
CVE-1999-0267
Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.
CVE-1999-0266
The info2www CGI script allows remote file access or remote command execution.
CVE-1999-0262
Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
CVE-1999-0256
Buffer overflow in War FTP allows remote execution of commands.
CVE-1999-0239
Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.
CVE-1999-0236
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
CVE-1999-0235
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
CVE-1999-0233
IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
CVE-1999-0224
Denial of service in Windows NT messenger service through a long username.
CVE-1999-0219
Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.
CVE-1999-0210
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
CVE-1999-0209
The SunView (SunTools) selection_svc facility allows remote users to read files.
CVE-1999-0208
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
CVE-1999-0207
Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.
CVE-1999-0204
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
CVE-1999-0196
websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).
CVE-1999-0193
Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.
CVE-1999-0192
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
CVE-1999-0191
IIS newdsn.exe CGI script allows remote users to overwrite files.
CVE-1999-0182
Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.
CVE-1999-0178
Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.
CVE-1999-0176
The Webgais program allows a remote user to execute arbitrary commands.
CVE-1999-0175
The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.
CVE-1999-0174
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
CVE-1999-0173
FormMail CGI program can be used by web servers other than the host server that the program resides on.
CVE-1999-0154
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.
CVE-1999-0153
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
CVE-1999-0149
The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.
CVE-1999-0148
The handler CGI program in IRIX allows arbitrary command execution.
CVE-1999-0147
The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.
CVE-1999-0146
The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.
CVE-1999-0144
Denial of service in Qmail by specifying a large number of recipients with the RCPT command.
