CVE-1999-0489
Published May 17, 1999MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in M…
- Buzz score
- 4.0
Severity archive
43,592 critical severity CVEs — 43,592 Critical, 125,443 High, 163,751 Medium, 17,997 Low, 2,140 Unrated across the current result set.
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in M…
The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.
Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX obje…
Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.
The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.
BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.
Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.
Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.
ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which coul…
rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.
The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.
Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.
Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use t…
ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.
Windows NT 4.0 beta allows users to read and delete shares.
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
finger 0@host on some systems may print information on some user accounts.
finger .@host on some systems may print information on some user accounts.
Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.
Attackers can do a denial of service of IRC by crashing the server.