-
CVE-1999-0953
•
published on January 4, 2000
WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.
-
CVE-1999-0724
•
published on January 4, 2000
Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.
-
CVE-1999-0726
•
published on January 4, 2000
An attacker can conduct a denial of service in Windows NT by executing a program with a malformed file image header.
-
CVE-1999-0732
•
published on January 4, 2000
The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.
-
CVE-1999-0763
•
published on January 4, 2000
NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network.
-
CVE-1999-0771
•
published on January 4, 2000
The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.
-
CVE-1999-0772
•
published on January 4, 2000
Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.
-
CVE-1999-0779
•
published on January 4, 2000
Denial of service in HP-UX SharedX recserv program.
-
CVE-1999-0793
•
published on January 4, 2000
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
-
CVE-1999-0839
•
published on January 4, 2000
Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled.
-
CVE-1999-0851
•
published on January 4, 2000
Denial of service in BIND named via naptr.
-
CVE-1999-0861
•
published on January 4, 2000
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
-
CVE-1999-0869
•
published on January 4, 2000
Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.
-
CVE-1999-0870
•
published on January 4, 2000
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.
-
CVE-1999-0887
•
published on January 4, 2000
FTGate web interface server allows remote attackers to read files via a .. (dot dot) attack.
-
CVE-1999-0892
•
published on January 4, 2000
Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.
-
CVE-1999-0900
•
published on January 4, 2000
Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation.
-
CVE-1999-0934
•
published on January 4, 2000
classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.
-
CVE-1999-0935
•
published on January 4, 2000
classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI form.
-
CVE-1999-0969
•
published on January 4, 2000
The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork.