CVE-1999-0381
super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.
CVE-1999-0376
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.
CVE-1999-0372
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
CVE-1999-0369
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
CVE-1999-0368
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
CVE-1999-0363
SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.
CVE-1999-0360
MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.
CVE-1999-0350
Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.
CVE-1999-0347
Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.
CVE-1999-0335
DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0032. Reason: This candidate is a duplicate of CVE-1999-0032. Notes: All CVE users should reference CVE-1999-0032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-1999-0328
SGI permissions program allows local users to gain root privileges.
CVE-1999-0321
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
CVE-1999-0315
Buffer overflow in Solaris fdformat command gives root access to local users.
CVE-1999-0314
ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.
CVE-1999-0294
All records in a WINS database can be deleted through SNMP for a denial of service.
CVE-1999-0288
The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.
CVE-1999-0284
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
CVE-1999-0283
The Java Web Server would allow remote users to obtain the source code for CGI programs.
CVE-1999-0278
In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.
CVE-1999-0269
Netscape Enterprise servers may list files through the PageServices query.
CVE-1999-0268
MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
CVE-1999-0267
Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.
CVE-1999-0266
The info2www CGI script allows remote file access or remote command execution.
CVE-1999-0262
Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
CVE-1999-0256
Buffer overflow in War FTP allows remote execution of commands.
CVE-1999-0239
Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.
CVE-1999-0236
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
CVE-1999-0235
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
CVE-1999-0233
IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
CVE-1999-0224
Denial of service in Windows NT messenger service through a long username.
CVE-1999-0219
Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.
CVE-1999-0210
Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.
CVE-1999-0209
The SunView (SunTools) selection_svc facility allows remote users to read files.
CVE-1999-0208
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
CVE-1999-0207
Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.
CVE-1999-0204
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
CVE-1999-0196
websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).
CVE-1999-0193
Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.
CVE-1999-0192
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
CVE-1999-0191
IIS newdsn.exe CGI script allows remote users to overwrite files.
CVE-1999-0182
Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.
CVE-1999-0178
Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.
CVE-1999-0176
The Webgais program allows a remote user to execute arbitrary commands.
