Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
1999-02-18 CVE-1999-1495 Unspecified vulnerability in Suse Linux 6.0
xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.
local
low complexity
suse
2.1
1999-02-18 CVE-1999-0405 A buffer overflow in lsof allows local users to obtain root privilege.
local
low complexity
debian freebsd redhat suse
7.2
1999-02-17 CVE-1999-1405 Unspecified vulnerability in IBM AIX
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.
network
low complexity
ibm
critical
10.0
1999-02-17 CVE-1999-1060 Unspecified vulnerability in Tetrix Tetrinet 1.13.16
Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.
network
low complexity
tetrix
5.0
1999-02-17 CVE-1999-0396 A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.
network
high complexity
netbsd openbsd
2.6
1999-02-16 CVE-1999-1180 Remote Security vulnerability in Oreilly Website and Website PRO
O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.
network
low complexity
oreilly
5.0
1999-02-16 CVE-1999-0375 Unspecified vulnerability in Network Flight Recorder Network Flight Recorder
Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.
network
low complexity
network-flight-recorder
7.5
1999-02-16 CVE-1999-0374 Unspecified vulnerability in Debian Linux 2.0
Debian GNU/Linux cfengine package is susceptible to a symlink attack.
local
low complexity
debian
2.1
1999-02-15 CVE-1999-1260 Unspecified vulnerability in Hughes Msql
mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.
network
low complexity
hughes
7.5
1999-02-15 CVE-1999-0714 Unspecified vulnerability in Digital Unix
Vulnerability in Compaq Tru64 UNIX edauth command.
local
low complexity
digital
2.1