Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
1998-07-15 CVE-1999-1582 Unspecified vulnerability in Cisco PIX Firewall
By design, the "established" command on the Cisco PIX firewall allows connections from one host to arbitrary ports of a target host if an alternative conduit has already been allowed, which can cause administrators to configure less restrictive access controls than intended if they do not understand this functionality.
network
low complexity
cisco
7.5
1998-07-15 CVE-1999-1433 Unspecified vulnerability in HP Jetadmin Rev.D.01.09
HP JetAdmin D.01.09 on Solaris allows local users to change the permissions of arbitrary files via a symlink attack on the /tmp/jetadmin.log file.
local
low complexity
hp
7.2
1998-07-15 CVE-1999-1297 Unspecified vulnerability in SUN Sunos
cmdtool in OpenWindows 3.0 and XView 3.0 in SunOS 4.1.4 and earlier allows attackers with physical access to the system to display unechoed characters (such as those from password prompts) via the L2/AGAIN key.
local
low complexity
sun
2.1
1998-07-15 CVE-1999-0213 Unspecified vulnerability in SUN Solaris and Sunos
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.
network
low complexity
sun
critical
10.0
1998-07-14 CVE-1999-0006 Buffer Overflow vulnerability in Qualcomm Qpopper 2.4
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.
network
low complexity
qualcomm
critical
10.0
1998-07-13 CVE-1999-1434 Unspecified vulnerability in Slackware Linux
login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.
local
low complexity
slackware
7.2
1998-07-11 CVE-1999-1270 Unspecified vulnerability in KDE 1.0
KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.
local
low complexity
kde
4.6
1998-07-10 CVE-1999-1435 Buffer Overflow vulnerability in NEC Socks 5 1.0R5
Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.
local
low complexity
nec
7.2
1998-07-09 CVE-1999-0102 Unspecified vulnerability in Seattle LAB Software Slmail 3.0.2421
Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.
network
low complexity
seattle-lab-software
7.5
1998-07-08 CVE-1999-1436 Unspecified vulnerability in RAY Chan WWW Authorization Gateway 0.1
Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter.
network
low complexity
ray-chan
7.5