-
CVE-1999-0137
•
published on September 29, 1999
The dip program on many Linux systems allows local users to gain root access via a buffer overflow.
-
CVE-1999-0149
•
published on September 29, 1999
The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.
-
CVE-1999-0153
•
published on September 29, 1999
Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.
-
CVE-1999-0161
•
published on September 29, 1999
In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.
-
CVE-1999-0166
•
published on September 29, 1999
NFS allows users to use a "cd .." command to access other directories besides the exported file system.
-
CVE-1999-0177
•
published on September 29, 1999
The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.
-
CVE-1999-0180
•
published on September 29, 1999
in.rshd allows users to login with a NULL username and execute commands.
-
CVE-1999-0183
•
published on September 29, 1999
Linux implementations of TFTP would allow access to files outside the restricted directory.
-
CVE-1999-0192
•
published on September 29, 1999
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
-
CVE-1999-0202
•
published on September 29, 1999
The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.
-
CVE-1999-0208
•
published on September 29, 1999
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
-
CVE-1999-0219
•
published on September 29, 1999
Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.
-
CVE-1999-0228
•
published on September 29, 1999
Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.
-
CVE-1999-0236
•
published on September 29, 1999
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
-
CVE-1999-0260
•
published on September 29, 1999
The jj CGI program allows command execution via shell metacharacters.
-
CVE-1999-0262
•
published on September 29, 1999
Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
-
CVE-1999-0263
•
published on September 29, 1999
Solaris SUNWadmap can be exploited to obtain root access.
-
CVE-1999-0272
•
published on September 29, 1999
Denial of service in Slmail v2.5 through the POP3 port.
-
CVE-1999-0276
•
published on September 29, 1999
mSQL v2.0.1 and below allows remote execution through a buffer overflow.
-
CVE-1999-0281
•
published on September 29, 1999
Denial of service in IIS using long URLs.