Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
1999-05-21 CVE-1999-1393 Unspecified vulnerability in Apple Macos 8.5/8.6
Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible.
local
low complexity
apple
4.6
1999-05-19 CVE-1999-1031 Denial of Service vulnerability in Behold Software web Page Counter 2.7
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.
network
low complexity
behold-software
5.0
1999-05-19 CVE-1999-1030 Denial of Service vulnerability in Behold Software web Page Counter 2.7
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.
network
low complexity
behold-software
5.0
1999-05-19 CVE-1999-0765 Unspecified vulnerability in SGI Irix 6.0
SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.
network
low complexity
sgi
critical
10.0
1999-05-17 CVE-1999-1510 Unspecified vulnerability in Bisonware FTP Server
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.
network
low complexity
bisonware
7.5
1999-05-17 CVE-1999-1156 Unspecified vulnerability in Bisonware FTP Server
BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns.
network
low complexity
bisonware
5.0
1999-05-17 CVE-1999-0489 Unspecified vulnerability in Microsoft Windows NT 4.0
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
network
low complexity
microsoft
critical
10.0
1999-05-15 CVE-1999-1366 Unspecified vulnerability in David Harris Pegasus Mail
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.
local
low complexity
david-harris
3.6
1999-05-13 CVE-1999-1029 Unspecified vulnerability in SSH Ssh2
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.
network
low complexity
ssh
7.5
1999-05-12 CVE-1999-1368 Unspecified vulnerability in Broadcom Inoculateit 4.53
AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.
network
low complexity
broadcom
7.5