Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
1995-02-01 CVE-1999-0232 Unspecified vulnerability in Ncsa Httpd Project Ncsa Httpd 1.5C
Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.
network
low complexity
ncsa-httpd-project
critical
10.0
1993-09-17 CVE-1999-1138 Unspecified vulnerability in SCO products
SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.
network
low complexity
sco
critical
10.0
1993-08-09 CVE-1999-0124 Unspecified vulnerability in University of Minnesota Gopherd
Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.
network
low complexity
university-of-minnesota
critical
10.0
1992-07-21 CVE-1999-0214 Unspecified vulnerability in SUN Sunos 4.1/4.1.1/4.1.2
Denial of service by sending forged ICMP unreachable packets.
network
low complexity
sun
critical
10.0
1992-04-27 CVE-1999-1119 Unspecified vulnerability in IBM AIX
FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.
network
low complexity
ibm
critical
10.0
1992-02-25 CVE-1999-1059 Unspecified vulnerability in ATT Svr4 4.0
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.
network
low complexity
att
critical
10.0
1991-12-31 CVE-1999-1032 Unspecified vulnerability in Digital Ultrix 4.1/4.2
Vulnerability in LAT/Telnet Gateway (lattelnet) on Ultrix 4.1 and 4.2 allows attackers to gain root privileges.
network
low complexity
digital
critical
10.0
1991-12-18 CVE-1999-1493 Unspecified vulnerability in HP Apollo Domain OS Sr10.2/Sr10.3
Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().
network
low complexity
hp
critical
10.0
1991-09-27 CVE-1999-0498 TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.
network
low complexity
critical
10.0
1991-05-14 CVE-1999-1193 Unspecified vulnerability in Next
The "me" user in NeXT NeXTstep 2.1 and earlier has wheel group privileges, which could allow the me user to use the su command to become root.
network
low complexity
next
critical
10.0