Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
1997-09-15 CVE-1999-1214 Credentials Management vulnerability in multiple products
The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.
local
low complexity
sgi bsd freebsd netbsd openbsd CWE-255
2.1
1997-09-12 CVE-1999-0079 Unspecified vulnerability in Bisonware FTP Server 3.5
Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.
network
low complexity
bisonware
5.0
1997-09-08 CVE-1999-1275 Unspecified vulnerability in IBM Lotus CC Mail 8.0
Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.
local
low complexity
ibm
4.6
1997-09-01 CVE-1999-1133 Unspecified vulnerability in HP Hp-Ux 10/9
HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.
local
low complexity
hp
4.6
1997-09-01 CVE-1999-0237 Unspecified vulnerability in Webcom CGI Guestbook
Remote execution of arbitrary commands through Guestbook CGI program.
network
low complexity
webcom
7.5
1997-09-01 CVE-1999-0191 Unspecified vulnerability in Microsoft Internet Information Server 3.0
IIS newdsn.exe CGI script allows remote users to overwrite files.
network
low complexity
microsoft
6.4
1997-09-01 CVE-1999-0183 Linux implementations of TFTP would allow access to files outside the restricted directory.
network
low complexity
tftp linux
6.4
1997-09-01 CVE-1999-0177 Unspecified vulnerability in Oreilly Website 2.0
The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.
network
low complexity
oreilly
7.5
1997-09-01 CVE-1999-0148 Unspecified vulnerability in SGI Irix
The handler CGI program in IRIX allows arbitrary command execution.
network
low complexity
sgi
7.5
1997-09-01 CVE-1999-0115 Unspecified vulnerability in IBM AIX
AIX bugfiler program allows local users to gain root access.
local
low complexity
ibm
7.2