7.2
    High

    CVE-1999-0381

    Last Modified: 15 Nov 2017

    super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.

    Source:c0nd0r
    Published:26 Feb 1999
    4.6
    Medium

    CVE-1999-0376

    Last Modified: 16 Jun 2012

    Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.

    Source:L0pht
    Published:20 Feb 1999
    2.1
    Low

    CVE-1999-0372

    Last Modified: 16 Jun 2012

    The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.

    Source:Russ Cooper
    Published:12 Feb 1999
    7.2
    High

    CVE-1999-0369

    Last Modified: 16 Nov 2017

    The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.

    Source:UNYUN
    Published:1 Feb 1997
    10
    Critical

    CVE-1999-0368

    Last Modified: 16 Nov 2017

    Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.

    Source:smiler & cossack
    Published:9 Feb 1999
    7.2
    High

    CVE-1999-0363

    Last Modified: 17 Jun 2012

    SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.

    Source:xnec
    Published:2 Feb 1999
    7.2
    High

    CVE-1999-0360

    Last Modified: 7 Aug 2012

    MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.

    Source:Mnemonix
    Published:30 Jan 1999
    6.2
    Medium

    CVE-1999-0350

    Last Modified: 27 Jun 2012

    Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.

    Source:Mudge
    Published:8 Feb 1999
    10
    Critical

    CVE-1999-0347

    Last Modified: 14 Jun 2012

    Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.

    Source:Georgi Guninski
    Published:26 Jan 1999
    Low

    CVE-1999-0335

    Last Modified: 15 Nov 2017

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Vadim Kolontsov
    Published:1 Aug 1996
    7.2
    High

    CVE-1999-0328

    Last Modified: 20 Jun 2012

    SGI permissions program allows local users to gain root privileges.

    Source:David Hedley
    Published:1 Nov 1997
    7.2
    High

    CVE-1999-0321

    Last Modified: 22 Jun 2012

    Buffer overflow in Solaris kcms_configure command allows local users to gain root access.

    Source:Cheez Whiz
    Published:1 Dec 1998
    7.2
    High

    CVE-1999-0315

    Last Modified: 16 Apr 2026

    Buffer overflow in Solaris fdformat command gives root access to local users.

    Source:Cristian Schipor
    Published:1 Apr 1997
    7.2
    High

    CVE-1999-0314

    Last Modified: 14 Jun 2012

    ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.

    Source:Loneguard
    Published:1 Jul 1998
    7.2
    High

    CVE-1999-0306

    Last Modified: 15 Nov 2017

    buffer overflow in HP xlock program.

    Source:BeastMaster
    Published:4 Nov 1997
    7.2
    High

    CVE-1999-0301

    Last Modified: 14 Jun 2012

    Buffer overflow in SunOS/Solaris ps command.

    Source:Joe Zbiciak
    Published:1 Aug 1997
    5
    Medium

    CVE-1999-0294

    Last Modified: 16 Aug 2012

    All records in a WINS database can be deleted through SNMP for a denial of service.

    Source:CRouland
    Published:1 Oct 1997
    5
    Medium

    CVE-1999-0288

    Last Modified: 17 Jun 2012

    The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.

    Source:Carl Byington
    Published:1 Aug 1998
    7.5
    High

    CVE-1999-0287

    Last Modified: 12 Aug 2012

    Vulnerability in the Wguest CGI program.

    Source:Mnemonix
    Published:9 Apr 1999
    7.5
    High

    CVE-1999-0284

    Last Modified: 4 Dec 2012

    Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.

    Source:Rootshell
    Published:1 Jan 1998
    10
    Critical

    CVE-1999-0283

    Last Modified: 9 Aug 2012

    The Java Web Server would allow remote users to obtain the source code for CGI programs.

    Source:Brian Krahmer
    Published:1 Jan 1999
    5
    Medium

    CVE-1999-0281

    Last Modified: 25 Aug 2012

    Denial of service in IIS using long URLs.

    Source:Andrea Arcangeli
    Published:1 Jun 1997
    5
    Medium

    CVE-1999-0278

    Last Modified: 13 Jun 2012

    In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.

    Source:Paul Ashton
    Published:1 Jun 1998
    5
    Medium

    CVE-1999-0269

    Last Modified: 10 Nov 2012

    Netscape Enterprise servers may list files through the PageServices query.

    Source:anonymous
    Published:1 Aug 1998
    10
    Critical

    CVE-1999-0268

    Last Modified: 15 Nov 2017

    MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.

    Source:Jeff Forristal
    Published:1 Jan 1999
    7.5
    High

    CVE-1999-0267

    Last Modified: 3 Sept 2012

    Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.

    Source:savage
    Published:23 Sept 1997
    7.5
    High

    CVE-1999-0266

    Last Modified: 11 Aug 2012

    The info2www CGI script allows remote file access or remote command execution.

    Source:Niall Smart
    Published:1 Mar 1998
    5
    Medium

    CVE-1999-0264

    Last Modified: 11 Aug 2012

    htmlscript CGI program allows remote read access to files.

    Source:Dennis Moore
    Published:27 Jan 1998
    7.5
    High

    CVE-1999-0262

    Last Modified: 12 Aug 2012

    Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.

    Source:Tom
    Published:4 Aug 1998
    7.5
    High

    CVE-1999-0256

    Last Modified: 9 Mar 2011

    Buffer overflow in War FTP allows remote execution of commands.

    Source:Metasploit
    Published:1 Feb 1998
    7.5
    High

    CVE-1999-0239

    Last Modified: 22 Jun 2012

    Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.

    Source:Jesús López de Aguileta
    Published:1 Jan 1998
    10
    Critical

    CVE-1999-0238

    Last Modified: 16 Aug 2012

    php.cgi allows attackers to read any file on the system.

    Source:Shamanski
    Published:1 Aug 1997
    7.5
    High

    CVE-1999-0236

    Last Modified: 17 Aug 2012

    ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.

    Source:anonymous
    Published:1 Jan 1997
    10
    Critical

    CVE-1999-0235

    Last Modified: 3 Sept 2012

    Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.

    Source:savage
    Published:17 Feb 1995
    10
    Critical

    CVE-1999-0233

    Last Modified: 12 Aug 2012

    IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.

    Source:anonymous
    Published:25 Feb 1996
    5
    Medium

    CVE-1999-0224

    Last Modified: 16 Apr 2026

    Denial of service in Windows NT messenger service through a long username.

    Source:Fyodor
    Published:23 Jul 1999
    7.8
    High

    CVE-1999-0219

    Last Modified: 27 Sept 2016

    Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.

    Source:Arne Vidstrom
    Published:1 Jul 1997
    6.4
    Medium

    CVE-1999-0215

    Last Modified: 25 Aug 2012

    Routed allows attackers to append data to files.

    Source:Rootshell
    Published:26 Oct 1998
    10
    Critical

    CVE-1999-0210

    Last Modified: 16 Nov 2017

    Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.

    Source:anonymous
    Published:26 Nov 1997
    5
    Medium

    CVE-1999-0209

    Last Modified: 7 Mar 2011

    The SunView (SunTools) selection_svc facility allows remote users to read files.

    Source:Metasploit
    Published:14 Aug 1990
    10
    Critical

    CVE-1999-0208

    Last Modified: 5 Aug 2012

    rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.

    Source:Josh D
    Published:12 Dec 1995
    7.5
    High

    CVE-1999-0207

    Last Modified: 17 Aug 2012

    Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.

    Source:Razvan Dragomirescu
    Published:9 Jun 1994
    10
    Critical

    CVE-1999-0204

    Last Modified: 4 Dec 2016

    Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.

    Source:CIAC
    Published:1 Jan 1997
    5
    Medium

    CVE-1999-0196

    Last Modified: 13 Aug 2012

    websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).

    Source:Razvan Dragomirescu
    Published:8 Jul 1997
    5
    Medium

    CVE-1999-0193

    Last Modified: 8 Dec 2016

    Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.

    Source:Rootshell
    Published:1 Dec 1997
    10
    Critical

    CVE-1999-0192

    Last Modified: 30 Jun 2012

    Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.

    Source:m0f0
    Published:18 Oct 1997
    6.4
    Medium

    CVE-1999-0191

    Last Modified: 7 Aug 2012

    IIS newdsn.exe CGI script allows remote users to overwrite files.

    Source:Vytis Fedaravicius
    Published:1 Sept 1997
    10
    Critical

    CVE-1999-0182

    Last Modified: 7 Aug 2012

    Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.

    Published:30 Sept 1997
    7.5
    High

    CVE-1999-0178

    Last Modified: 13 Aug 2012

    Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.

    Source:Solar Designer
    Published:1 Jan 1997
    7.5
    High

    CVE-1999-0176

    Last Modified: 12 Aug 2012

    The Webgais program allows a remote user to execute arbitrary commands.

    Source:Razvan Dragomirescu
    Published:10 Jul 1997