Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
1997-08-01 CVE-1999-0566 Unspecified vulnerability in IBM AIX
An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.
network
low complexity
ibm
5.0
1997-07-31 CVE-1999-1308 Unspecified vulnerability in HP Hp-Ux 10.20
Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.
local
low complexity
hp
4.6
1997-07-25 CVE-1999-1217 Unspecified vulnerability in Microsoft Windows NT
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.
local
low complexity
microsoft
4.6
1997-07-23 CVE-1999-1068 Unspecified vulnerability in Oracle Http Server 2.1
Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.
network
low complexity
oracle
5.0
1997-07-16 CVE-1999-0026 Unspecified vulnerability in SGI Irix
root privileges via buffer overflow in pset command on SGI IRIX systems.
local
low complexity
sgi
4.6
1997-07-10 CVE-1999-1463 Unspecified vulnerability in Microsoft Windows NT 3.5.1/4.0
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.
network
low complexity
microsoft
5.0
1997-07-08 CVE-1999-0196 Unspecified vulnerability in Webgais Development Team Webgais 1.0
websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).
network
low complexity
webgais-development-team
5.0
1997-07-04 CVE-1999-1326 Unspecified vulnerability in Washington University Wu-Ftpd 2.4
wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.
network
low complexity
washington-university
5.0
1997-07-01 CVE-1999-0628 The rwho/rwhod service is running, which exposes machine status and user information.
network
low complexity
netbsd ibm freebsd linux
5.0
1997-07-01 CVE-1999-0195 Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.
network
low complexity
sgi linux
5.0