-
CVE-1999-0379
•
published on September 29, 1999
Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.
-
CVE-1999-0382
•
published on September 29, 1999
The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.
-
CVE-1999-0383
•
published on September 29, 1999
ACC Tigris allows public access without a login.
-
CVE-1999-0384
•
published on September 29, 1999
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
-
CVE-1999-0385
•
published on September 29, 1999
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
-
CVE-1999-0386
•
published on September 29, 1999
Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.
-
CVE-1999-0388
•
published on September 29, 1999
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
-
CVE-1999-0391
•
published on September 29, 1999
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
-
CVE-1999-0392
•
published on September 29, 1999
Buffer overflow in Thomas Boutell's cgic library version up to 1.05.
-
CVE-1999-0396
•
published on September 29, 1999
A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.
-
CVE-1999-0402
•
published on September 29, 1999
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
-
CVE-1999-0404
•
published on September 29, 1999
Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.
-
CVE-1999-0405
•
published on September 29, 1999
A buffer overflow in lsof allows local users to obtain root privilege.
-
CVE-1999-0410
•
published on September 29, 1999
The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.
-
CVE-1999-0412
•
published on September 29, 1999
In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.
-
CVE-1999-0413
•
published on September 29, 1999
A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.
-
CVE-1999-0414
•
published on September 29, 1999
In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.
-
CVE-1999-0417
•
published on September 29, 1999
64 bit Solaris 7 procfs allows local users to perform a denial of service.
-
CVE-1999-0420
•
published on September 29, 1999
umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.
-
CVE-1999-0422
•
published on September 29, 1999
In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the "noexec" flag set.