CVE-1999-0226
Published Jan 1, 1999Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
Severity archive
43,592 critical severity CVEs — 43,592 Critical, 125,443 High, 163,751 Medium, 17,997 Low, 2,140 Unrated across the current result set.
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
Linux cfingerd could be exploited to gain root access.
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
Buffer overflow in ircd allows arbitrary command execution.
MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
The Java Web Server would allow remote users to obtain the source code for CGI programs.
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.
NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
A service or application has a backdoor password that was placed there by the developer.
A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable,…
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
A trust relationship exists between two Unix hosts.
An SSH server allows authentication through the .rhosts file.
A superfluous NFS server is running, but it is not importing or exporting any file systems.
NFS exports system-critical data to the world, e.g. / or a password file.
A Unix account with a name other than "root" has UID 0, i.e. root privileges.