Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
1997-09-19 CVE-1999-0956 Unspecified vulnerability in Next Nextstep
The NeXT NetInfo _writers property allows local users to gain root privileges or conduct a denial of service.
local
low complexity
next
7.2
1997-09-19 CVE-1999-0667 Unspecified vulnerability in ARP Protocol ARP Protocol
The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.
network
low complexity
arp-protocol
critical
10.0
1997-09-15 CVE-1999-1214 Credentials Management vulnerability in multiple products
The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID.
local
low complexity
sgi bsd freebsd netbsd openbsd CWE-255
2.1
1997-09-12 CVE-1999-0079 Unspecified vulnerability in Bisonware FTP Server 3.5
Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.
network
low complexity
bisonware
5.0
1997-09-08 CVE-1999-1275 Unspecified vulnerability in IBM Lotus CC Mail 8.0
Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.
local
low complexity
ibm
4.6
1997-09-01 CVE-1999-1133 Unspecified vulnerability in HP Hp-Ux 10/9
HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.
local
low complexity
hp
4.6
1997-09-01 CVE-1999-0237 Unspecified vulnerability in Webcom CGI Guestbook
Remote execution of arbitrary commands through Guestbook CGI program.
network
low complexity
webcom
7.5
1997-09-01 CVE-1999-0191 Unspecified vulnerability in Microsoft Internet Information Server 3.0
IIS newdsn.exe CGI script allows remote users to overwrite files.
network
low complexity
microsoft
6.4
1997-09-01 CVE-1999-0183 Linux implementations of TFTP would allow access to files outside the restricted directory.
network
low complexity
tftp linux
6.4
1997-09-01 CVE-1999-0177 Unspecified vulnerability in Oreilly Website 2.0
The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.
network
low complexity
oreilly
7.5