CVE-1999-0364
Published Jan 1, 1999Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
Severity archive
43,458 critical severity CVEs — 43,458 Critical, 125,144 High, 163,487 Medium, 17,970 Low, 2,179 Unrated across the current result set.
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
A service or application has a backdoor password that was placed there by the developer.
A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable,…
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
A trust relationship exists between two Unix hosts.
An SSH server allows authentication through the .rhosts file.
A superfluous NFS server is running, but it is not importing or exporting any file systems.
NFS exports system-critical data to the world, e.g. / or a password file.
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
Two or more Unix accounts have the same UID.
A system-critical Unix file or directory has inappropriate permissions.
A system-critical Windows NT file or directory has inappropriate permissions.
IIS has the #exec function enabled for Server Side Include (SSI) files.
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.
A Sendmail alias allows input to be piped to a program.
rpc.admind in Solaris is not running in a secure mode.
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.