CVE-1999-0401
Published Jan 1, 1999A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
351,347 results · Sorted by Highest Buzz score first
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
A service or application has a backdoor password that was placed there by the developer.
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
A system-critical NETBIOS/SMB share has inappropriate access control.
A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.
A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
A trust relationship exists between two Unix hosts.
An SSH server allows authentication through the .rhosts file.
Windows NT automatically logs in an administrator upon rebooting.
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
Two or more Unix accounts have the same UID.
A system-critical Windows NT file or directory has inappropriate permissions.
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.
rpc.admind in Solaris is not running in a secure mode.
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.