Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
1999-03-30 CVE-1999-0434 XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
network
low complexity
caldera debian netbsd redhat suse
7.5
1999-03-23 CVE-1999-1397 Remote Registry vulnerability in Microsoft Index Server 2.0
Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.
network
low complexity
microsoft
7.5
1999-03-23 CVE-1999-1370 Unspecified vulnerability in Microsoft Internet Explorer 5.0
The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.
local
low complexity
microsoft
7.2
1999-03-22 CVE-1999-0481 Denial-Of-Service vulnerability in Openbsd 2.4
Denial of service in "poll" in OpenBSD.
network
low complexity
openbsd
5.0
1999-03-22 CVE-1999-0428 Remote Security vulnerability in SSLeay
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
network
low complexity
openssl ssleay
7.5
1999-03-21 CVE-1999-0482 Denial-Of-Service vulnerability in OpenBSD Kernel
OpenBSD kernel crash through TSS handling, as caused by the crashme program.
network
low complexity
openbsd
5.0
1999-03-21 CVE-1999-0433 XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
local
low complexity
xfree86-project slackware redhat netbsd suse
4.6
1999-03-18 CVE-1999-0425 Unspecified vulnerability in Netscape Communicator 4.5
talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.
network
low complexity
netscape
6.4
1999-03-18 CVE-1999-0424 Unspecified vulnerability in Netscape Communicator 4.5
talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.
local
low complexity
netscape
2.1
1999-03-17 CVE-1999-0462 Unspecified vulnerability in Suse Linux 5.3
suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g.
local
low complexity
suse
7.2