Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
1998-07-13 CVE-1999-1434 Unspecified vulnerability in Slackware Linux
login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.
local
low complexity
slackware
7.2
1998-07-11 CVE-1999-1270 Unspecified vulnerability in KDE 1.0
KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.
local
low complexity
kde
4.6
1998-07-10 CVE-1999-1435 Buffer Overflow vulnerability in NEC Socks 5 1.0R5
Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.
local
low complexity
nec
7.2
1998-07-09 CVE-1999-0102 Unspecified vulnerability in Seattle LAB Software Slmail 3.0.2421
Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.
network
low complexity
seattle-lab-software
7.5
1998-07-08 CVE-1999-1436 Unspecified vulnerability in RAY Chan WWW Authorization Gateway 0.1
Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter.
network
low complexity
ray-chan
7.5
1998-07-07 CVE-1999-1437 Unspecified vulnerability in Ralf S. Engelschall Eperl 2.2.12
ePerl 2.2.12 allows remote attackers to read arbitrary files and possibly execute certain commands by specifying a full pathname of the target file as an argument to bar.phtml.
network
low complexity
ralf-s-engelschall
7.5
1998-07-06 CVE-1999-1574 Unspecified vulnerability in IBM AIX 4.3.0
Buffer overflow in the lex routines of nslookup for AIX 4.3 may allow attackers to cause a core dump and possibly execute arbitrary code via "long input strings."
network
low complexity
ibm
7.5
1998-07-03 CVE-1999-1409 The at program in IRIX 6.2 and NetBSD 1.3.2 and earlier allows local users to read portions of arbitrary files by submitting the file to at with the -f argument, which generates error messages that at sends to the user via e-mail.
local
low complexity
sgi netbsd
2.1
1998-07-03 CVE-1999-1202 Unspecified vulnerability in Startech Pop3 Proxy Server and Telnet Server
StarTech (1) POP3 proxy server and (2) telnet server allows remote attackers to cause a denial of service via a long USER command.
network
low complexity
startech
5.0
1998-07-01 CVE-1999-0494 Unspecified vulnerability in Wingate
Denial of service in WinGate proxy through a buffer overflow in POP3.
network
low complexity
wingate
5.0