Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-1999-1196 1 Hummingbird 1 Exceed 2008-09-05 5.0 MEDIUM N/A
Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.
CVE-1999-1197 1 Sun 1 Sunos 2008-09-05 7.2 HIGH N/A
TIOCCONS in SunOS 4.1.1 does not properly check the permissions of a user who tries to redirect console output and input, which could allow a local user to gain privileges.
CVE-1999-1198 1 Next 1 Next 2008-09-05 7.2 HIGH N/A
BuildDisk program on NeXT systems before 2.0 does not prompt users for the root password, which allows local users to gain root privileges.
CVE-1999-1102 4 Apple, Bsd, Sgi and 1 more 4 A Ux, Bsd, Irix and 1 more 2008-09-05 2.1 LOW N/A
lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered after invoking lpr 1000 times.
CVE-1999-0810 1 Samba 1 Samba 2008-09-05 10.0 HIGH N/A
Denial of service in Samba NETBIOS name service daemon (nmbd).
CVE-1999-0940 1 Mutt 1 Mutt Mail Client 2008-09-05 7.5 HIGH N/A
Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages.
CVE-1999-0926 1 Apache 1 Http Server 2008-09-05 10.0 HIGH N/A
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.
CVE-1999-1012 1 Lotus 1 Domino 2008-09-05 5.0 MEDIUM N/A
SMTP component of Lotus Domino 4.6.1 on AS/400, and possibly other operating systems, allows a remote attacker to crash the mail server via a long string.
CVE-1999-1190 1 Admiral Systems 1 Emailclub 2008-09-05 10.0 HIGH N/A
Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.
CVE-1999-1162 1 Sco 2 Open Desktop, Unix 2008-09-05 6.4 MEDIUM N/A
Vulnerability in passwd in SCO UNIX 4.0 and earlier allows attackers to cause a denial of service by preventing users from being able to log into the system.
CVE-1999-1124 1 Allaire 1 Coldfusion 2008-09-05 7.5 HIGH N/A
HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host.
CVE-1999-0847 1 Freechess.org 1 Fics Program 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in free internet chess server (FICS) program, xboard.
CVE-1999-1059 1 Att 1 Svr4 2008-09-05 10.0 HIGH N/A
Vulnerability in rexec daemon (rexecd) in AT&T TCP/IP 4.0 for various SVR4 systems allows remote attackers to execute arbitrary commands.
CVE-1999-0923 1 Allaire 1 Coldfusion Server 2008-09-05 7.5 HIGH N/A
Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.
CVE-1999-0784 1 Oracle 1 Database Server 2008-09-05 5.0 MEDIUM N/A
Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.
CVE-1999-0577 1 Microsoft 1 Windows Nt 2008-09-05 10.0 HIGH N/A
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
CVE-1999-0744 1 Netscape 2 Enterprise Server, Fasttrack Server 2008-09-05 7.5 HIGH N/A
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.
CVE-1999-0579 1 Microsoft 1 Windows Nt 2008-09-05 10.0 HIGH N/A
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
CVE-1999-0568 1 Sun 1 Solaris 2008-09-05 10.0 HIGH N/A
rpc.admind in Solaris is not running in a secure mode.
CVE-1999-0578 1 Microsoft 1 Windows Nt 2008-09-05 4.6 MEDIUM N/A
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.
CVE-1999-0581 1 Microsoft 1 Windows Nt 2008-09-05 10.0 HIGH N/A
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
CVE-1999-0570 1 Microsoft 1 Windows Nt 2008-09-05 10.0 HIGH N/A
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
CVE-1999-0477 1 Allaire 1 Coldfusion Server 2008-09-05 7.5 HIGH N/A
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.
CVE-1999-0400 1 Linux 1 Linux Kernel 2008-09-05 4.6 MEDIUM N/A
Denial of service in Linux 2.2.0 running the ldd command on a core file.
CVE-1999-0560 1 Microsoft 1 Windows Nt 2008-09-05 10.0 HIGH N/A
A system-critical Windows NT file or directory has inappropriate permissions.
CVE-1999-0451 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.
CVE-1999-0460 1 Linux 1 Linux Kernel 2008-09-05 2.1 LOW N/A
Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.
CVE-1999-0730 1 Debian 1 Debian Linux 2008-09-05 10.0 HIGH N/A
The zsoelim program in the Debian man-db package allows local users to overwrite files via a symlink attack.
CVE-1999-0453 1 Cisco 1 Router 2008-09-05 5.0 MEDIUM N/A
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).
CVE-1999-0123 1 Slackware 1 Slackware Linux 2008-09-05 3.7 LOW N/A
Race condition in Linux mailx command allows local users to read user files.
CVE-1999-0119 1 Microsoft 1 Windows Nt 2008-09-05 10.0 HIGH N/A
Windows NT 4.0 beta allows users to read and delete shares.
CVE-1999-0053 1 Freebsd 1 Freebsd 2008-09-05 5.0 MEDIUM N/A
TCP RST denial of service in FreeBSD.
CVE-1999-0140 1 Microsoft 1 Windows Nt 2008-09-05 5.0 MEDIUM N/A
Denial of service in RAS/PPTP on NT systems.
CVE-1999-0231 1 Seattle Lab Software 1 Slmail 2008-09-05 5.0 MEDIUM N/A
Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.
CVE-1999-0248 1 Ssh 1 Ssh 2008-09-05 10.0 HIGH N/A
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
CVE-1999-0299 1 Freebsd 1 Freebsd 2008-09-05 9.3 HIGH N/A
Buffer overflow in FreeBSD lpd through long DNS hostnames.
CVE-1999-0089 1 Ibm 1 Aix 2008-09-05 7.2 HIGH N/A
Buffer overflow in AIX libDtSvc library can allow local users to gain root access.
CVE-1999-0088 1 Ibm 1 Aix 2008-09-05 10.0 HIGH N/A
IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.
CVE-1999-0285 1 Microsoft 1 Windows Nt 2008-09-05 10.0 HIGH N/A
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
CVE-2008-3939 1 Avtech 1 Pager Enterprise 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
CVE-2008-3937 1 Opendb 1 Opendb 2008-09-05 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.
CVE-2008-3938 1 Opendb 1 Opendb 2008-09-05 5.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action.
CVE-2008-3935 1 D-ic 2 Shop V50, Shop V52 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2008-3397 1 Runesoft 1 Cerberus Cms 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Runesoft Cerberus CMS before 3_1.4_0.9 allows remote attackers to inject arbitrary web script or HTML via a cerberus_user cookie.
CVE-2008-3893 1 Microsoft 1 Windows Vista 2008-09-05 1.9 LOW N/A
Microsoft Bitlocker in Windows Vista before SP1 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer during boot, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
CVE-2004-2706 1 Phrozensmoke 1 Gyach Enhanced 2008-09-05 5.0 MEDIUM N/A
Unspecified vulnerability in Gyach Enhanced (Gyach-E) before 1.0.4 allows remote attackers to cause a denial of service (crash) via conference packets with error messages.
CVE-2004-2700 1 Aspdotnetstorefront 1 Aspdotnetstorefront 2008-09-05 9.0 HIGH N/A
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.
CVE-2003-1562 1 Openbsd 1 Openssh 2008-09-05 7.6 HIGH N/A
sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.
CVE-2007-3652 1 Fascript 1 Faname 2008-09-05 6.8 MEDIUM N/A
SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same issue as CVE-2008-0328.
CVE-2007-3650 1 Mywebland 1 Mybloggie 2008-09-05 5.0 MEDIUM N/A
myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error messages.