Mon, Jul 31 · 04:00 AM CDTCVE-1999-0066
9.8/10 · Must read/watchNVDvuln
Summary
AnyForm CGI remote execution.
CVECVE-1999-0066
SeverityCRITICAL
TypeUPDATED
PublishedMon, Jul 31 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Wed, Mar 20 · 05:00 AM CSTCVE-1999-0067
10.0/10 · Must read/watchNVDvuln
Summary
phf CGI program allows remote command execution through shell metacharacters.
CVECVE-1999-0067
SeverityHIGH
TypeUPDATED
PublishedWed, Mar 20 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Fri, Oct 13 · 04:00 AM CDTCVE-1999-0073
10.0/10 · Must read/watchNVDvuln
Summary
Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.
CVECVE-1999-0073
SeverityHIGH
TypeUPDATED
PublishedFri, Oct 13 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Thu, Nov 30 · 05:00 AM CSTCVE-1999-0080
10.0/10 · Must read/watchNVDvuln
Summary
Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.
CVECVE-1999-0080
SeverityHIGH
TypeUPDATED
PublishedThu, Nov 30 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Fri, Nov 11 · 05:00 AM CSTCVE-1999-0082
10.0/10 · Must read/watchNVDvuln
Summary
CWD ~root command in ftpd allows root access.
CVECVE-1999-0082
SeverityHIGH
TypeUPDATED
PublishedFri, Nov 11 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Sat, Oct 01 · 04:00 AM CDTCVE-1999-0095
10.0/10 · Must read/watchNVDvuln
Summary
The debug command in Sendmail is enabled, allowing attackers to execute commands as root.
CVECVE-1999-0095
SeverityHIGH
TypeUPDATED
PublishedSat, Oct 01 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Thu, Oct 19 · 04:00 AM CDTCVE-1999-0099
10.0/10 · Must read/watchNVDvuln
Summary
Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.
CVECVE-1999-0099
SeverityHIGH
TypeUPDATED
PublishedThu, Oct 19 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Mon, May 23 · 04:00 AM CDTCVE-1999-0113
10.0/10 · Must read/watchNVDvuln
Summary
Some implementations of rlogin allow root access if given a -froot parameter.
CVECVE-1999-0113
SeverityHIGH
TypeUPDATED
PublishedMon, May 23 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Mon, Aug 09 · 04:00 AM CDTCVE-1999-0124
10.0/10 · Must read/watchNVDvuln
Summary
Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.
CVECVE-1999-0124
SeverityHIGH
TypeUPDATED
PublishedMon, Aug 09 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Thu, Aug 17 · 04:00 AM CDTCVE-1999-0203
10.0/10 · Must read/watchNVDvuln
Summary
In Sendmail, attackers can gain root privileges via SMTP by specifying an improper "mail from" address and an invalid "rcpt to" address that would cause the mail to bounce to a program.
CVECVE-1999-0203
SeverityHIGH
TypeUPDATED
PublishedThu, Aug 17 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Tue, Dec 12 · 05:00 AM CSTCVE-1999-0208
10.0/10 · Must read/watchNVDvuln
Summary
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
CVECVE-1999-0208
SeverityHIGH
TypeUPDATED
PublishedTue, Dec 12 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Tue, Jul 21 · 04:00 AM CDTCVE-1999-0214
10.0/10 · Must read/watchNVDvuln
Summary
Denial of service by sending forged ICMP unreachable packets.
CVECVE-1999-0214
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 21 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Wed, Feb 01 · 05:00 AM CSTCVE-1999-0232
10.0/10 · Must read/watchNVDvuln
Summary
Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.
CVECVE-1999-0232
SeverityHIGH
TypeUPDATED
PublishedWed, Feb 01 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Sun, Feb 25 · 05:00 AM CSTCVE-1999-0233
10.0/10 · Must read/watchNVDvuln
Summary
IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
CVECVE-1999-0233
SeverityHIGH
TypeUPDATED
PublishedSun, Feb 25 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Fri, Feb 17 · 05:00 AM CSTCVE-1999-0235
10.0/10 · Must read/watchNVDvuln
Summary
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
CVECVE-1999-0235
SeverityHIGH
TypeUPDATED
PublishedFri, Feb 17 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Wed, Nov 01 · 05:00 AM CSTCVE-1999-0241
10.0/10 · Must read/watchNVDvuln
Summary
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.
CVECVE-1999-0241
SeverityHIGH
TypeUPDATED
PublishedWed, Nov 01 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Fri, Sep 27 · 04:00 AM CDTCVE-1999-0498
10.0/10 · Must read/watchNVDvuln
Summary
TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.
CVECVE-1999-0498
SeverityHIGH
TypeUPDATED
PublishedFri, Sep 27 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Tue, Dec 31 · 05:00 AM CSTCVE-1999-1032
10.0/10 · Must read/watchNVDvuln
Summary
Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.
CVECVE-1999-1032
SeverityHIGH
TypeUPDATED
PublishedTue, Dec 31 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Tue, Feb 25 · 05:00 AM CSTCVE-1999-1059
10.0/10 · Must read/watchNVDvuln
Summary
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.
CVECVE-1999-1059
SeverityHIGH
TypeUPDATED
PublishedTue, Feb 25 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Mon, Apr 27 · 04:00 AM CDTCVE-1999-1119
10.0/10 · Must read/watchNVDvuln
Summary
FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.
CVECVE-1999-1119
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 27 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Fri, Sep 17 · 04:00 AM CDTCVE-1999-1138
10.0/10 · Must read/watchNVDvuln
Summary
SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.
CVECVE-1999-1138
SeverityHIGH
TypeUPDATED
PublishedFri, Sep 17 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Tue, May 14 · 04:00 AM CDTCVE-1999-1193
10.0/10 · Must read/watchNVDvuln
Summary
The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.
CVECVE-1999-1193
SeverityHIGH
TypeUPDATED
PublishedTue, May 14 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Wed, Jan 03 · 05:00 AM CSTCVE-1999-1319
10.0/10 · Must read/watchNVDvuln
Summary
Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.
CVECVE-1999-1319
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 03 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT
Thu, Oct 26 · 04:00 AM CDTCVE-1999-1467
10.0/10 · Must read/watchNVDvuln
Summary
Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.
CVECVE-1999-1467
SeverityHIGH
TypeUPDATED
PublishedThu, Oct 26 · 04:00 AM CDT
ModifiedThu, Apr 16 · 12:27 AM CDT
Wed, Dec 18 · 05:00 AM CSTCVE-1999-1493
10.0/10 · Must read/watchNVDvuln
Summary
Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().
CVECVE-1999-1493
SeverityHIGH
TypeUPDATED
PublishedWed, Dec 18 · 05:00 AM CST
ModifiedThu, Apr 16 · 12:27 AM CDT