Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
1998-12-03 CVE-1999-0936 BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.
network
low complexity
critical
10.0
1998-12-01 CVE-1999-0869 Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.
network
high complexity
microsoft netscape
2.6
1998-12-01 CVE-1999-0478 Unspecified vulnerability in Sendmail
Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.
network
low complexity
sendmail
5.0
1998-12-01 CVE-1999-0463 Unspecified vulnerability in L0Pht L0Phtcrack 2.5
Remote attackers can perform a denial of service using IRIX fcagent.
network
low complexity
l0pht
5.0
1998-12-01 CVE-1999-0385 Classic Buffer Overflow vulnerability in Microsoft Exchange Server 5.5
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
network
low complexity
microsoft CWE-120
critical
10.0
1998-12-01 CVE-1999-0342 Unspecified vulnerability in PAM
Linux PAM modules allow local users to gain root access using temporary files.
local
high complexity
pam
6.2
1998-12-01 CVE-1999-0321 Unspecified vulnerability in SUN Solaris
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
local
low complexity
sun
7.2
1998-11-30 CVE-1999-1073 Unspecified vulnerability in Excite EWS 1.1
Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.
local
low complexity
excite
7.2
1998-11-30 CVE-1999-1072 Unspecified vulnerability in Excite EWS 1.1
Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.
local
low complexity
excite
7.2
1998-11-30 CVE-1999-1071 Unspecified vulnerability in Excite EWS 1.1
Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.
local
low complexity
excite
7.2