-
CVE-1999-0227
•
published on September 29, 1999
Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.
-
CVE-1999-0234
•
published on September 29, 1999
Bash treats any character with a value of 255 as a command separator.
-
CVE-1999-0237
•
published on September 29, 1999
Remote execution of arbitrary commands through Guestbook CGI program.
-
CVE-1999-0252
•
published on September 29, 1999
Buffer overflow in listserv allows arbitrary command execution.
-
CVE-1999-0264
•
published on September 29, 1999
htmlscript CGI program allows remote read access to files.
-
CVE-1999-0274
•
published on September 29, 1999
Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.
-
CVE-1999-0277
•
published on September 29, 1999
The WorkMan program can be used to overwrite any file to get root access.
-
CVE-1999-0279
•
published on September 29, 1999
Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.
-
CVE-1999-0292
•
published on September 29, 1999
Denial of service through Winpopup using large user names.
-
CVE-1999-0295
•
published on September 29, 1999
Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.
-
CVE-1999-0366
•
published on September 29, 1999
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.
-
CVE-1999-0368
•
published on September 29, 1999
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
-
CVE-1999-0372
•
published on September 29, 1999
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
-
CVE-1999-0373
•
published on September 29, 1999
Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.
-
CVE-1999-0384
•
published on September 29, 1999
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
-
CVE-1999-0388
•
published on September 29, 1999
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
-
CVE-1999-0396
•
published on September 29, 1999
A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.
-
CVE-1999-0404
•
published on September 29, 1999
Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.
-
CVE-1999-0423
•
published on September 29, 1999
Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.
-
CVE-1999-0430
•
published on September 29, 1999
Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.