CVE-1999-0774
Published Aug 31, 1999Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.
Severity archive
124,926 high severity CVEs — 43,427 Critical, 124,926 High, 163,439 Medium, 17,961 Low, 2,024 Unrated across the current result set.
Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.
Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-on…
Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.
Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges…
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.
The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.
Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
The WebRamp web administration utility has a default password.
Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.
.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.
WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.
Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to ex…
The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.
IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules…
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediar…
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fin…
Denial of service in Windows NT Local Security Authority (LSA) through a malformed LSA request.