-
CVE-1999-0129
•
published on September 29, 1999
Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.
-
CVE-1999-0131
•
published on September 29, 1999
Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.
-
CVE-1999-0134
•
published on September 29, 1999
vold in Solaris 2.x allows local users to gain root access.
-
CVE-1999-0135
•
published on September 29, 1999
admintool in Solaris allows a local user to write to arbitrary files and gain root access.
-
CVE-1999-0136
•
published on September 29, 1999
Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.
-
CVE-1999-0138
•
published on September 29, 1999
The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.
-
CVE-1999-0139
•
published on September 29, 1999
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
-
CVE-1999-0146
•
published on September 29, 1999
The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.
-
CVE-1999-0148
•
published on September 29, 1999
The handler CGI program in IRIX allows arbitrary command execution.
-
CVE-1999-0150
•
published on September 29, 1999
The Perl fingerd program allows arbitrary command execution from remote users.
-
CVE-1999-0158
•
published on September 29, 1999
Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.
-
CVE-1999-0159
•
published on September 29, 1999
Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.
-
CVE-1999-0164
•
published on September 29, 1999
A race condition in the Solaris ps command allows an attacker to overwrite critical files.
-
CVE-1999-0168
•
published on September 29, 1999
The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place. For example, NFS file systems could be mounted through the portmapper despite export restrictions.
-
CVE-1999-0170
•
published on September 29, 1999
Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.
-
CVE-1999-0174
•
published on September 29, 1999
The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.
-
CVE-1999-0176
•
published on September 29, 1999
The Webgais program allows a remote user to execute arbitrary commands.
-
CVE-1999-0179
•
published on September 29, 1999
Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share.
-
CVE-1999-0181
•
published on September 29, 1999
The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.
-
CVE-1999-0190
•
published on September 29, 1999
Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.