Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
1997-08-24 CVE-1999-1225 rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.
network
low complexity
digital linux netbsd openbsd sun
5.0
1997-08-19 CVE-1999-1250 Unspecified vulnerability in Blue World Communications Lasso CGI
Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files.
network
low complexity
blue-world-communications
5.0
1997-08-13 CVE-1999-0024 DNS cache poisoning via BIND, by predictable query IDs.
network
low complexity
isc sco sun nec ibm bsdi
5.0
1997-08-01 CVE-1999-1262 Unspecified vulnerability in Netscape Communicator
Java in Netscape 4.5 does not properly restrict applets from connecting to other hosts besides the one from which the applet was loaded, which violates the Java security model and could allow remote attackers to conduct unauthorized activities.
network
high complexity
netscape
5.1
1997-08-01 CVE-1999-0566 Unspecified vulnerability in IBM AIX
An attacker can write to syslog files from any location, causing a denial of service by filling up the logs, and hiding activities.
network
low complexity
ibm
5.0
1997-07-31 CVE-1999-1308 Unspecified vulnerability in HP Hp-Ux 10.20
Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.
local
low complexity
hp
4.6
1997-07-25 CVE-1999-1217 Unspecified vulnerability in Microsoft Windows NT
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.
local
low complexity
microsoft
4.6
1997-07-23 CVE-1999-1068 Unspecified vulnerability in Oracle Http Server 2.1
Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.
network
low complexity
oracle
5.0
1997-07-16 CVE-1999-0026 Unspecified vulnerability in SGI Irix
root privileges via buffer overflow in pset command on SGI IRIX systems.
local
low complexity
sgi
4.6
1997-07-10 CVE-1999-1463 Unspecified vulnerability in Microsoft Windows NT 3.5.1/4.0
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.
network
low complexity
microsoft
5.0