<?xml version="1.0"?>
<cve xmlns="http://cve.mitre.org/cve/downloads/xml_schema_info.html" xmlns:cve="http://cve.mitre.org/cve/downloads/xml_schema_info.html" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://cve.mitre.org/cve/downloads/xml_schema_info.html cve_schema.xsd" schemaVersion="0.1">
<item type="CVE" name="CVE-1999-0002" seq="1999-0002">
<status>Entry</status>
<desc>Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I">19981006-01-I</ref>
<ref source="CERT">CA-98.12.mountd</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-006.shtml">J-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/121">121</ref>
<ref source="XF">linux-mountd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0003" seq="1999-0003">
<status>Entry</status>
<desc>Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</desc>
<refs>
<ref source="NAI">NAI-29</ref>
<ref source="CERT">CA-98.11.tooltalk</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A">19981101-01-A</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX">19981101-01-PX</ref>
<ref source="XF">aix-ttdbserver</ref>
<ref source="XF">tooltalk</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/122">122</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0005" seq="1999-0005">
<status>Entry</status>
<desc>Arbitrary command execution via IMAP buffer overflow in authenticate command.</desc>
<refs>
<ref source="CERT">CA-98.09.imapd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177">00177</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/130">130</ref>
<ref source="XF">imap-authenticate-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0006" seq="1999-0006">
<status>Entry</status>
<desc>Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.</desc>
<refs>
<ref source="CERT">CA-98.08.qpopper_vul</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I">19980801-01-I</ref>
<ref source="AUSCERT">AA-98.01</ref>
<ref source="XF">qpopper-pass-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/133">133</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0007" seq="1999-0007">
<status>Entry</status>
<desc>Information from SSL-encrypted sessions via PKCS #1.</desc>
<refs>
<ref source="CERT">CA-98.07.PKCS</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx">MS98-002</ref>
<ref source="XF">nt-ssl-fix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0008" seq="1999-0008">
<status>Entry</status>
<desc>Buffer overflow in NIS+, in Sun's rpc.nisd program.</desc>
<refs>
<ref source="CERT">CA-98.06.nisd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170">00170</ref>
<ref source="ISS">June10,1998</ref>
<ref source="XF">nisd-bo-check</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0009" seq="1999-0009">
<status>Entry</status>
<desc>Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="XF">bind-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/134">134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0010" seq="1999-0010">
<status>Entry</status>
<desc>Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="XF">bind-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0011" seq="1999-0011">
<status>Entry</status>
<desc>Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="XF">bind-axfr-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0012" seq="1999-0012">
<status>Entry</status>
<desc>Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</desc>
<refs>
<ref source="CERT">CA-98.04.Win32.WebServers</ref>
<ref source="XF">nt-web8.3</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0013" seq="1999-0013">
<status>Entry</status>
<desc>Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</desc>
<refs>
<ref source="CERT">CA-98.03.ssh-agent</ref>
<ref source="NAI">NAI-24</ref>
<ref source="XF">ssh-agent</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0014" seq="1999-0014">
<status>Entry</status>
<desc>Unauthorized privileged access or denial of service via dtappgather program in CDE.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075">HPSBUX9801-075</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185">00185</ref>
<ref source="CERT">CA-98.02.CDE</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0016" seq="1999-0016">
<status>Entry</status>
<desc>Land IP denial of service.</desc>
<refs>
<ref source="CERT">CA-97.28.Teardrop_Land</ref>
<ref source="FREEBSD">FreeBSD-SA-98:01</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076">HPSBUX9801-076</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/land-pub.shtml</ref>
<ref source="XF">cisco-land</ref>
<ref source="XF">land</ref>
<ref source="XF">95-verv-tcp</ref>
<ref source="XF">land-patch</ref>
<ref source="XF">ver-tcpip-sys</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0017" seq="1999-0017">
<status>Entry</status>
<desc>FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</desc>
<refs>
<ref source="CERT">CA-97.27.FTP_bounce</ref>
<ref source="XF">ftp-bounce</ref>
<ref source="XF">ftp-privileged-port</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0018" seq="1999-0018">
<status>Entry</status>
<desc>Buffer overflow in statd allows root privileges.</desc>
<refs>
<ref source="CERT">CA-97.26.statd</ref>
<ref source="AUSCERT">AA-97.29</ref>
<ref source="XF">statd</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/127">127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0019" seq="1999-0019">
<status>Entry</status>
<desc>Delete or create a file via rpc.statd, due to invalid information.</desc>
<refs>
<ref source="CERT">CA-96.09.rpc.statd</ref>
<ref source="XF">rpc-stat</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0021" seq="1999-0021">
<status>Entry</status>
<desc>Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</desc>
<refs>
<ref source="BUGTRAQ">19971010 Security flaw in Count.cgi (wwwcount)</ref>
<ref source="CERT">CA-97.24.Count_cgi</ref>
<ref source="XF">http-cgi-count</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/128">128</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0022" seq="1999-0022">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via expstr() function.</desc>
<refs>
<ref source="CERT">CA-97.23.rdist</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</ref>
<ref source="XF">rdist-bo3</ref>
<ref source="XF">rdist-sept97</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0023" seq="1999-0023">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via lookup() function.</desc>
<refs>
<ref source="CERT">CA-96.14.rdist_vul</ref>
<ref source="XF">rdist-bo</ref>
<ref source="XF">rdist-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0024" seq="1999-0024">
<status>Entry</status>
<desc>DNS cache poisoning via BIND, by predictable query IDs.</desc>
<refs>
<ref source="CERT">CA-97.22.bind</ref>
<ref source="XF">bind</ref>
<ref source="NAI">NAI-11</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0025" seq="1999-0025">
<status>Entry</status>
<desc>root privileges via buffer overflow in df command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CA-1997-21</ref>
<ref source="AUSCERT">AA-97.19.IRIX.df.buffer.overflow.vul</ref>
<ref source="SGI">SGI:19970505-01-A</ref>
<ref source="SGI">SGI:19970505-02-PX</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/20851">VU#20851</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/346">346</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/440">df-bo(440)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0026" seq="1999-0026">
<status>Entry</status>
<desc>root privileges via buffer overflow in pset command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.20.IRIX.pset.buffer.overflow.vul</ref>
<ref source="XF">pset-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0027" seq="1999-0027">
<status>Entry</status>
<desc>root privileges via buffer overflow in eject command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.21.IRIX.eject.buffer.overflow.vul</ref>
<ref source="XF">eject-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0028" seq="1999-0028">
<status>Entry</status>
<desc>root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.22.IRIX.login.scheme.buffer.overflow.vul</ref>
<ref source="XF">sgi-schemebo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0029" seq="1999-0029">
<status>Entry</status>
<desc>root privileges via buffer overflow in ordist command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.23-IRIX.ordist.buffer.overflow.vul</ref>
<ref source="XF">ordist-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0031" seq="1999-0031">
<status>Entry</status>
<desc>JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.</desc>
<refs>
<ref source="CERT">CA-97.20.javascript</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html">HPSBUX9707-065</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0032" seq="1999-0032">
<status>Entry</status>
<desc>Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</desc>
<refs>
<ref source="BUGTRAQ">19960813 Possible bufferoverflow condition in lpr, xterm and xload</ref>
<ref source="BUGTRAQ">19961025 Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[freebsd-security] 19961025 Vadim Kolontsov: BoS: Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[linux-security] 19961122 LSF Update#14: Vulnerability of the lpr program.</ref>
<ref source="CERT">CA-97.19.bsdlp</ref>
<ref source="AUSCERT">AA-96.12</ref>
<ref source="CIAC">H-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/707">707</ref>
<ref source="XF">bsd-lprbo2</ref>
<ref source="XF">bsd-lprbo</ref>
<ref source="XF">lpr-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0034" seq="1999-0034">
<status>Entry</status>
<desc>Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</desc>
<refs>
<ref source="CERT">CA-97.17.sperl</ref>
<ref source="XF">perl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0035" seq="1999-0035">
<status>Entry</status>
<desc>Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</desc>
<refs>
<ref source="XF">ftp-ftpd</ref>
<ref source="CERT">CA-97.16.ftpd</ref>
<ref source="AUSCERT">AA-97.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0036" seq="1999-0036">
<status>Entry</status>
<desc>IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</desc>
<refs>
<ref source="CERT">CA-97.15.sgi_login</ref>
<ref source="AUSCERT">AA-97.12</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-106.shtml">H-106</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX">19970508-02-PX</ref>
<ref source="OSVDB" url="http://www.osvdb.org/990">990</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/557">sgi-lockout(557)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0037" seq="1999-0037">
<status>Entry</status>
<desc>Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.</desc>
<refs>
<ref source="CERT">CA-97.14.metamail</ref>
<ref source="XF">metamail-header-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0038" seq="1999-0038">
<status>Entry</status>
<desc>Buffer overflow in xlock program allows local users to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-97.13.xlock</ref>
<ref source="XF">xlock-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0039" seq="1999-0039">
<status>Entry</status>
<desc>webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</desc>
<refs>
<ref source="BUGTRAQ">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in</ref>
<ref source="BUGTRAQ">19970507 Re: SGI Advisory: webdist.cgi</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-12.html">CA-1997-12</ref>
<ref source="AUSCERT">AA-97.14</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/374">374</ref>
<ref source="OSVDB" url="http://www.osvdb.org/235">235</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/333">http-sgi-webdist(333)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0040" seq="1999-0040">
<status>Entry</status>
<desc>Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.11.libXt</ref>
<ref source="XF">libXt-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0041" seq="1999-0041">
<status>Entry</status>
<desc>Buffer overflow in NLS (Natural Language Service).</desc>
<refs>
<ref source="CERT">CA-97.10.nls</ref>
<ref source="XF">nls-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0042" seq="1999-0042">
<status>Entry</status>
<desc>Buffer overflow in University of Washington's implementation of IMAP and POP servers.</desc>
<refs>
<ref source="NAI">NAI-21</ref>
<ref source="CERT">CA-97.09.imap_pop</ref>
<ref source="XF">popimap-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0043" seq="1999-0043">
<status>Entry</status>
<desc>Command execution via shell metachars in INN daemon (innd) 1.5 using &quot;newgroup&quot; and &quot;rmgroup&quot; control messages, and others.</desc>
<refs>
<ref source="CERT">CA-97.08.innd</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0044" seq="1999-0044">
<status>Entry</status>
<desc>fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</ref>
<ref source="XF">sgi-fsdump</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0045" seq="1999-0045">
<status>Entry</status>
<desc>List of arbitrary files on Web host via nph-test-cgi script.</desc>
<refs>
<ref source="CERT">CA-97.07.nph-test-cgi_script</ref>
<ref source="XF">http-cgi-nph</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0046" seq="1999-0046">
<status>Entry</status>
<desc>Buffer overflow of rlogin program using TERM environmental variable.</desc>
<refs>
<ref source="CERT">CA-97.06.rlogin-term</ref>
<ref source="XF">rlogin-termbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0047" seq="1999-0047">
<status>Entry</status>
<desc>MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</desc>
<refs>
<ref source="CERT">CA-97.05.sendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/685">685</ref>
<ref source="XF">sendmail-mime-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0048" seq="1999-0048">
<status>Entry</status>
<desc>Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.04.talkd</ref>
<ref source="FREEBSD">FreeBSD-SA-96:21</ref>
<ref source="AUSCERT">AA-97.01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147">00147</ref>
<ref source="XF">talkd-bo</ref>
<ref source="XF">netkit-talkd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0049" seq="1999-0049">
<status>Entry</status>
<desc>Csetup under IRIX allows arbitrary file creation or overwriting.</desc>
<refs>
<ref source="XF">sgi-csetup</ref>
<ref source="CERT">CA-97.03.csetup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0050" seq="1999-0050">
<status>Entry</status>
<desc>Buffer overflow in HP-UX newgrp program.</desc>
<refs>
<ref source="CERT">CA-97.02.hp_newgrp</ref>
<ref source="AUSCERT">AA-96.16.HP-UX.newgrp.Buffer.Overrun.Vulnerability</ref>
<ref source="XF">hp-newgrpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0051" seq="1999-0051">
<status>Entry</status>
<desc>Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</desc>
<refs>
<ref source="XF">sgi-licensemanager</ref>
<ref source="CERT">CA-97.01.flex_lm</ref>
<ref source="AUSCERT">AA-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0052" seq="1999-0052">
<status>Entry</status>
<desc>IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:08</ref>
<ref source="OSVDB" url="http://www.osvdb.org/908">908</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1389">freebsd-ip-frag-dos(1389)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0053" seq="1999-0053">
<status>Entry</status>
<desc>TCP RST denial of service in FreeBSD.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:07</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6094">6094</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0054" seq="1999-0054">
<status>Entry</status>
<desc>Sun's ftpd daemon can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171">00171</ref>
<ref source="XF">sun-ftpd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0055" seq="1999-0055">
<status>Entry</status>
<desc>Buffer overflows in Sun libnsl allow root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172">00172</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only">IX80543</ref>
<ref source="RSI">RSI.0005.05-14-98.SUN.LIBNSL</ref>
<ref source="XF">sun-libnsl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0056" seq="1999-0056">
<status>Entry</status>
<desc>Buffer overflow in Sun's ping program can give root access to local users.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174">00174</ref>
<ref source="XF">sun-ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0057" seq="1999-0057">
<status>Entry</status>
<desc>Vacation program allows command execution by remote users through a sendmail command.</desc>
<refs>
<ref source="NAI">NAI-19</ref>
<ref source="XF">vacation</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087">HPSBUX9811-087</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0058" seq="1999-0058">
<status>Entry</status>
<desc>Buffer overflow in PHP cgi program, php.cgi allows shell access.</desc>
<refs>
<ref source="NAI">NAI-12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/712">712</ref>
<ref source="XF">http-cgi-phpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0059" seq="1999-0059">
<status>Entry</status>
<desc>IRIX fam service allows an attacker to obtain a list of all files on the server.</desc>
<refs>
<ref source="NAI">NAI-16</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/353">353</ref>
<ref source="OSVDB" url="http://www.osvdb.org/164">164</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/325">irix-fam(325)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0060" seq="1999-0060">
<status>Entry</status>
<desc>Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</desc>
<refs>
<ref source="NAI">NAI-26</ref>
<ref source="XF">ascend-config-kill</ref>
<ref source="ASCEND">http://www.ascend.com/2695.html</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0062" seq="1999-0062">
<status>Entry</status>
<desc>The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</desc>
<refs>
<ref source="XF">openbsd-chpass</ref>
<ref source="NAI">NAI-28</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7559">7559</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0063" seq="1999-0063">
<status>Entry</status>
<desc>Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</desc>
<refs>
<ref source="AUSCERT">ESB-98.197</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/iossyslog-pub.shtml</ref>
<ref source="XF">cisco-syslog-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0064" seq="1999-0064">
<status>Entry</status>
<desc>Buffer overflow in AIX lquerylv program gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">May28,1997</ref>
<ref source="XF">lquerylv-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0065" seq="1999-0065">
<status>Entry</status>
<desc>Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181">00181</ref>
<ref source="XF">hp-dtmail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0066" seq="1999-0066">
<status>Entry</status>
<desc>AnyForm CGI remote execution.</desc>
<refs>
<ref source="BUGTRAQ">19950731 SECURITY HOLE: &quot;AnyForm&quot; CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/719">719</ref>
<ref source="XF">http-cgi-anyform</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0067" seq="1999-0067">
<status>Entry</status>
<desc>phf CGI program allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19960923 PHF Attacks - Fun and games for the whole family</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</ref>
<ref source="AUSCERT">AA-96.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/629">629</ref>
<ref source="OSVDB" url="http://www.osvdb.org/136">136</ref>
<ref source="XF">http-cgi-phf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0068" seq="1999-0068">
<status>Entry</status>
<desc>CGI PHP mylog script allows an attacker to read any file on the target server.</desc>
<refs>
<ref source="BUGTRAQ">19971019 Vulnerability in PHP Example Logging Scripts</ref>
<ref source="XF">http-cgi-php-mylog</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3396">3396</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0069" seq="1999-0069">
<status>Entry</status>
<desc>Solaris ufsrestore buffer overflow.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169">00169</ref>
<ref source="XF">sun-ufsrestore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8158">8158</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0070" seq="1999-0070">
<status>Entry</status>
<desc>test-cgi program allows an attacker to list files on the server.</desc>
<refs>
<ref source="XF">http-cgi-test</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0071" seq="1999-0071">
<status>Entry</status>
<desc>Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</desc>
<refs>
<ref source="XF">http-apache-cookie</ref>
<ref source="NAI">NAI-2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0072" seq="1999-0072">
<status>Entry</status>
<desc>Buffer overflow in AIX xdat gives root access to local users.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:004.1</ref>
<ref source="XF">ibm-xdat</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0073" seq="1999-0073">
<status>Entry</status>
<desc>Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</desc>
<refs>
<ref source="CERT">CA-95:14.Telnetd_Environment_Vulnerability</ref>
<ref source="XF">linkerbug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0074" seq="1999-0074">
<status>Entry</status>
<desc>Listening TCP ports are sequentially allocated, allowing spoofing attacks.</desc>
<refs>
<ref source="XF">seqport</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0075" seq="1999-0075">
<status>Entry</status>
<desc>PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</desc>
<refs>
<ref source="BUGTRAQ">19961016 Re: ftpd bug? Was: bin/1805: Bug in ftpd</ref>
<ref source="XF">ftp-pasvcore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5742">5742</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0077" seq="1999-0077">
<status>Entry</status>
<desc>Predictable TCP sequence numbers allow spoofing.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/static/139.php">tcp-seq-predict(139)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0079" seq="1999-0079">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</desc>
<refs>
<ref source="XF">ftp-pasv-dos</ref>
<ref source="XF">ftp-pasvdos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0080" seq="1999-0080">
<status>Entry</status>
<desc>Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the &quot;site exec&quot; command.</desc>
<refs>
<ref source="BUGTRAQ">19950531 SECURITY: problem with some wu-ftpd-2.4 binaries (fwd)</ref>
<ref source="CERT">CA-95:16.wu-ftpd.vul</ref>
<ref source="XF">ftp-execdotdot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0081" seq="1999-0081">
<status>Entry</status>
<desc>wu-ftp allows files to be overwritten via the rnfr command.</desc>
<refs>
<ref source="XF">ftp-rnfr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0082" seq="1999-0082">
<status>Entry</status>
<desc>CWD ~root command in ftpd allows root access.</desc>
<refs>
<ref source="XF">ftp-cwd</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0083" seq="1999-0083">
<status>Entry</status>
<desc>getcwd() file descriptor leak in FTP.</desc>
<refs>
<ref source="XF">cwdleak</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0084" seq="1999-0084">
<status>Entry</status>
<desc>Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/78">nfs-mknod(78)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0085" seq="1999-0085">
<status>Entry</status>
<desc>Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</desc>
<refs>
<ref source="BUGTRAQ">19960821 rwhod buffer overflow</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/119">rwhod(119)</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/118">rwhod-vuln(118)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0087" seq="1999-0087">
<status>Entry</status>
<desc>Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</desc>
<refs>
<ref source="XF">ibm-telnetdos</ref>
<ref source="ERS">ERS-SVA-E01-1998:003.1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7992">7992</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0090" seq="1999-0090">
<status>Entry</status>
<desc>Buffer overflow in AIX rcp command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-rcp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0091" seq="1999-0091">
<status>Entry</status>
<desc>Buffer overflow in AIX writesrv command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-writesrv</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0093" seq="1999-0093">
<status>Entry</status>
<desc>AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:008.1</ref>
<ref source="XF">ibm-nslookup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0094" seq="1999-0094">
<status>Entry</status>
<desc>AIX piodmgrsu command allows local users to gain additional group privileges.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:007.1</ref>
<ref source="XF">ibm-piodmgrsu</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0095" seq="1999-0095">
<status>Entry</status>
<desc>The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-88.01</ref>
<ref source="CERT">CA-93.14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1">1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/195">195</ref>
<ref source="XF">smtp-debug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0096" seq="1999-0096">
<status>Entry</status>
<desc>Sendmail decode alias can be used to overwrite sensitive files.</desc>
<refs>
<ref source="CERT">CA-93.16</ref>
<ref source="CERT">CA-95.05</ref>
<ref source="CIAC">A-13</ref>
<ref source="CIAC">A-14</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
<ref source="XF">smtp-dcod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0097" seq="1999-0097">
<status>Entry</status>
<desc>The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:009.1</ref>
<ref source="XF">ibm-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0099" seq="1999-0099">
<status>Entry</status>
<desc>Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-95.13.syslog.vul</ref>
<ref source="XF">smtp-syslog</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0100" seq="1999-0100">
<status>Entry</status>
<desc>Remote access in AIX innd 1.5.1, using control messages.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:002.1</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0101" seq="1999-0101">
<status>Entry</status>
<desc>Buffer overflow in AIX and Solaris &quot;gethostbyname&quot; library call allows root access through corrupt DNS host names.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:001.1</ref>
<ref source="ERS">ERS-SVA-E01-1996:007.1</ref>
<ref source="SUN">00137a</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13</ref>
<ref source="NAI">NAI-1</ref>
<ref source="XF">ghbn-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0102" seq="1999-0102">
<status>Entry</status>
<desc>Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</desc>
<refs>
<ref source="XF">slmail-fromheader-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0103" seq="1999-0103">
<status>Entry</status>
<desc>Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</desc>
<refs>
<ref source="CERT">CA-96.01.UDP_service_denial</ref>
<ref source="XF">echo</ref>
<ref source="XF">chargen</ref>
<ref source="XF">chargen-patch</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0108" seq="1999-0108">
<status>Entry</status>
<desc>The printers program in IRIX has a buffer overflow that gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">another day, another buffer overflow...</ref>
<ref source="XF">printers-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0109" seq="1999-0109">
<status>Entry</status>
<desc>Buffer overflow in ffbconfig in Solaris 2.5.1.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140">00140</ref>
<ref source="AUSCERT">AA-97.06</ref>
<ref source="XF">ffbconfig-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0111" seq="1999-0111">
<status>Entry</status>
<desc>RIP v1 is susceptible to spoofing.</desc>
<refs>
<ref source="XF">rip</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0112" seq="1999-0112">
<status>Entry</status>
<desc>Buffer overflow in AIX dtterm program for the CDE.</desc>
<refs>
<ref source="BUGTRAQ">19970520 AIX 4.2 dtterm exploit</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/878">dtterm-bo(878)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0113" seq="1999-0113">
<status>Entry</status>
<desc>Some implementations of rlogin allow root access if given a -froot parameter.</desc>
<refs>
<ref source="BUGTRAQ">19940729 -froot??? (AIX rlogin bug)</ref>
<ref source="CERT">CA-94.09.bin.login.vulnerability</ref>
<ref source="CIAC">E-26</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/458">458</ref>
<ref source="XF">rlogin-froot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0115" seq="1999-0115">
<status>Entry</status>
<desc>AIX bugfiler program allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ">19970909 AIX bugfiler</ref>
<ref source="XF">ibm-bugfiler</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1800">1800</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0116" seq="1999-0116">
<status>Entry</status>
<desc>Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</desc>
<refs>
<ref source="CERT">CA-96.21.tcp_syn.flooding</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0117" seq="1999-0117">
<status>Entry</status>
<desc>AIX passwd allows local users to gain root access.</desc>
<refs>
<ref source="XF">ibm-passwd</ref>
<ref source="CERT">CA-92:07.AIX.passwd.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0118" seq="1999-0118">
<status>Entry</status>
<desc>AIX infod allows local users to gain root access through an X display.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91158980826979&amp;w=2">19981119 RSI.0011.11-09-98.AIX.INFOD</ref>
<ref source="XF">aix-infod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0120" seq="1999-0120">
<status>Entry</status>
<desc>Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</ref>
<ref source="CERT">CA-94.06.utmp.vulnerability</ref>
<ref source="XF">utmp-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0122" seq="1999-0122">
<status>Entry</status>
<desc>Buffer overflow in AIX lchangelv gives root access.</desc>
<refs>
<ref source="BUGTRAQ">Jul21,1999</ref>
<ref source="XF">lchangelv-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0124" seq="1999-0124">
<status>Entry</status>
<desc>Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</desc>
<refs>
<ref source="CERT">CA-93:11.UMN.UNIX.gopher.vulnerability</ref>
<ref source="XF">gopher-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0125" seq="1999-0125">
<status>Entry</status>
<desc>Buffer overflow in SGI IRIX mailx program.</desc>
<refs>
<ref source="XF">sgi-mailx-bo</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX">19980605-01-PX</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0126" seq="1999-0126">
<status>Entry</status>
<desc>SGI IRIX buffer overflow in xterm and Xaw allows root access.</desc>
<refs>
<ref source="CERT">VB-98.04.xterm.Xaw</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-010.shtml">J-010</ref>
<ref source="XF">xfree86-xterm-xaw</ref>
<ref source="XF">xfree86-xaw</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0128" seq="1999-0128">
<status>Entry</status>
<desc>Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</desc>
<refs>
<ref source="XF">ping-death</ref>
<ref source="CERT">CA-96.26.ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0129" seq="1999-0129">
<status>Entry</status>
<desc>Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</desc>
<refs>
<ref source="CERT">CA-96.25.sendmail_groups</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0130" seq="1999-0130">
<status>Entry</status>
<desc>Local users can start Sendmail in daemon mode and gain root privileges.</desc>
<refs>
<ref source="CERT">CA-96.24.sendmail.daemon.mode</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/716">716</ref>
<ref source="XF">sendmail-daemon-mode</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0131" seq="1999-0131">
<status>Entry</status>
<desc>Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</desc>
<refs>
<ref source="CERT">CA-96.20.sendmail_vul</ref>
<ref source="XF">smtp-875bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/717">717</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0132" seq="1999-0132">
<status>Entry</status>
<desc>Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11723">11723</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/401">expreserve(401)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0133" seq="1999-0133">
<status>Entry</status>
<desc>fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT">CA-96.18.fm_fls</ref>
<ref source="XF">fmaker-logfile</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0134" seq="1999-0134">
<status>Entry</status>
<desc>vold in Solaris 2.x allows local users to gain root access.</desc>
<refs>
<ref source="XF">sol-voldtmp</ref>
<ref source="CERT">CA-96.17.Solaris_vold_vul</ref>
<ref source="AUSCERT">AL-96.04</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8159">8159</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0135" seq="1999-0135">
<status>Entry</status>
<desc>admintool in Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sun-admintool</ref>
<ref source="CERT">CA-96.16.Solaris_admintool_vul</ref>
<ref source="AUSCERT">AL-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0136" seq="1999-0136">
<status>Entry</status>
<desc>Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sol-KCMSvuln</ref>
<ref source="AUSCERT">AL-96.02</ref>
<ref source="CERT">CA-96.15.Solaris_KCMS_vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0137" seq="1999-0137">
<status>Entry</status>
<desc>The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</desc>
<refs>
<ref source="XF">linux-dipbo</ref>
<ref source="CERT">CA-96.13.dip_vul</ref>
<ref source="XF">dip-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0138" seq="1999-0138">
<status>Entry</status>
<desc>The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</desc>
<refs>
<ref source="CERT">CA-96.12.suidperl_vul</ref>
<ref source="XF">sperl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0139" seq="1999-0139">
<status>Entry</status>
<desc>Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</desc>
<refs>
<ref source="XF">sol-mkcookie</ref>
<ref source="RSI">RSI.0012.12-03-98.SOLARIS.MKCOOKIE</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8205">8205</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0141" seq="1999-0141">
<status>Entry</status>
<desc>Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</desc>
<refs>
<ref source="XF">http-java-applet</ref>
<ref source="CERT">CA-96.07.java_bytecode_verifier</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0142" seq="1999-0142">
<status>Entry</status>
<desc>The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</desc>
<refs>
<ref source="CERT">CA-96.05.java_applet_security_mgr</ref>
<ref source="XF">http-java-appletsecmgr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0143" seq="1999-0143">
<status>Entry</status>
<desc>Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</desc>
<refs>
<ref source="CERT">CA-96.03.kerberos_4_key_server</ref>
<ref source="XF">kerberos-bf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0145" seq="1999-0145">
<status>Entry</status>
<desc>Sendmail WIZ command enabled, allowing root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</ref>
<ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0146" seq="1999-0146">
<status>Entry</status>
<desc>The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</desc>
<refs>
<ref source="BUGTRAQ">19970715 Bug CGI campas</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1975">1975</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/298">http-cgi-campas(298)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0147" seq="1999-0147">
<status>Entry</status>
<desc>The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</desc>
<refs>
<ref source="XF">http-cgi-glimpse</ref>
<ref source="AUSCERT">AA-97.28</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0148" seq="1999-0148">
<status>Entry</status>
<desc>The handler CGI program in IRIX allows arbitrary command execution.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/380">380</ref>
<ref source="XF">http-sgi-handler</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0149" seq="1999-0149">
<status>Entry</status>
<desc>The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970420 IRIX 6.x /cgi-bin/wrap bug</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/373">373</ref>
<ref source="OSVDB" url="http://www.osvdb.org/247">247</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/290">http-sgi-wrap(290)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0150" seq="1999-0150">
<status>Entry</status>
<desc>The Perl fingerd program allows arbitrary command execution from remote users.</desc>
<refs>
<ref source="XF">perl-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0151" seq="1999-0151">
<status>Entry</status>
<desc>The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</desc>
<refs>
<ref source="CERT">CA-95.07a.REVISED.satan.vul</ref>
<ref source="CERT">CA-95.06.satan.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0152" seq="1999-0152">
<status>Entry</status>
<desc>The DG/UX finger daemon allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19970811 dgux in.fingerd vulnerability</ref>
<ref source="XF">dgux-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0153" seq="1999-0153">
<status>Entry</status>
<desc>Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</desc>
<refs>
<ref source="XF">win-oob</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1666">1666</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0155" seq="1999-0155">
<status>Entry</status>
<desc>The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</desc>
<refs>
<ref source="XF">gscript-dsafer</ref>
<ref source="CERT">CA-95.10.ghostscript</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0157" seq="1999-0157">
<status>Entry</status>
<desc>Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/nifrag.shtml</ref>
<ref source="XF">cisco-fragmented-attacks</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1097">1097</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0158" seq="1999-0158">
<status>Entry</status>
<desc>Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml">20010913 Cisco PIX Firewall Manager File Exposure</ref>
<ref source="XF">cisco-pix-file-exposure</ref>
<ref source="OSVDB" url="http://www.osvdb.org/685">685</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0159" seq="1999-0159">
<status>Entry</status>
<desc>Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/ioslogin-pub.shtml</ref>
<ref source="XF">cisco-ios-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0160" seq="1999-0160">
<status>Entry</status>
<desc>Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</desc>
<refs>
<ref source="CISCO">19971001 Vulnerabilities in Cisco CHAP Authentication</ref>
<ref source="CIAC">I-002A</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1099">1099</ref>
<ref source="XF">cisco-chap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0161" seq="1999-0161">
<status>Entry</status>
<desc>In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/707/1.html</ref>
<ref source="XF">cisco-acl-tacacs</ref>
<ref source="OSVDB" url="http://www.osvdb.org/797">797</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0162" seq="1999-0162">
<status>Entry</status>
<desc>The &quot;established&quot; keyword in some Cisco IOS software allowed an attacker to bypass filtering.</desc>
<refs>
<ref source="CISCO">19950601 &quot;Established&quot; Keyword May Allow Packets to Bypass Filter</ref>
<ref source="XF">cisco-acl-established</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0164" seq="1999-0164">
<status>Entry</status>
<desc>A race condition in the Solaris ps command allows an attacker to overwrite critical files.</desc>
<refs>
<ref source="XF">sol-pstmprace</ref>
<ref source="AUSCERT">AA-95.07</ref>
<ref source="CERT">CA-95.09.Solaris.ps.vul</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8346">8346</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0166" seq="1999-0166">
<status>Entry</status>
<desc>NFS allows users to use a &quot;cd ..&quot; command to access other directories besides the exported file system.</desc>
<refs>
<ref source="XF">nfs-cd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0167" seq="1999-0167">
<status>Entry</status>
<desc>In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</desc>
<refs>
<ref source="XF">nfs-guess</ref>
<ref source="CERT">CA-91.21.SunOS.NFS.Jumbo.and.fsirand</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0168" seq="1999-0168">
<status>Entry</status>
<desc>The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</desc>
<refs>
<ref source="XF">nfs-portmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0170" seq="1999-0170">
<status>Entry</status>
<desc>Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</desc>
<refs>
<ref source="XF">nfs-ultrix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0172" seq="1999-0172">
<status>Entry</status>
<desc>FormMail CGI program allows remote execution of commands.</desc>
<refs>
<ref source="XF">http-cgi-formmail-exe</ref>
<ref source="BUGTRAQ">Aug02,1995</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0173" seq="1999-0173">
<status>Entry</status>
<desc>FormMail CGI program can be used by web servers other than the host server that the program resides on.</desc>
<refs>
<ref source="XF">http-cgi-formmail-use</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0174" seq="1999-0174">
<status>Entry</status>
<desc>The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970208 view-source</ref>
<ref source="XF">http-cgi-viewsrc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0175" seq="1999-0175">
<status>Entry</status>
<desc>The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</desc>
<refs>
<ref source="XF">http-nov-convert</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0176" seq="1999-0176">
<status>Entry</status>
<desc>The Webgais program allows a remote user to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ">Jul10,1997</ref>
<ref source="XF">http-webgais-query</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0177" seq="1999-0177">
<status>Entry</status>
<desc>The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</desc>
<refs>
<ref source="NTBUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="NTBUGTRAQ">19970905 Re: FW: [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="BUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="XF">http-website-uploader</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0178" seq="1999-0178">
<status>Entry</status>
<desc>Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2078">2078</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8">8</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/295">http-website-winsample(295)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0179" seq="1999-0179">
<status>Entry</status>
<desc>Windows NT crashes or locks up when a Samba client executes a &quot;cd ..&quot; command on a file share.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q140818">Q140818</ref>
<ref source="XF">nt-samba-dotdot</ref>
<ref source="XF">nt-351</ref>
<ref source="XF">nt-35</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0180" seq="1999-0180">
<status>Entry</status>
<desc>in.rshd allows users to login with a NULL username and execute commands.</desc>
<refs>
<ref source="XF">rsh-null</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0181" seq="1999-0181">
<status>Entry</status>
<desc>The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</desc>
<refs>
<ref source="XF">walld</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0182" seq="1999-0182">
<status>Entry</status>
<desc>Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-110.shtml">H-110</ref>
<ref source="CERT">VB-97.10.samba</ref>
<ref source="XF">nt-samba-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0183" seq="1999-0183">
<status>Entry</status>
<desc>Linux implementations of TFTP would allow access to files outside the restricted directory.</desc>
<refs>
<ref source="XF">linux-tftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0184" seq="1999-0184">
<status>Entry</status>
<desc>When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</desc>
<refs>
<ref source="XF">dns-updates</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0185" seq="1999-0185">
<status>Entry</status>
<desc>In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156">00156</ref>
<ref source="XF">sun-ftpd/logind</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0188" seq="1999-0188">
<status>Entry</status>
<desc>The passwd command in Solaris can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182">00182</ref>
<ref source="XF">sun-passwd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0189" seq="1999-0189">
<status>Entry</status>
<desc>Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</desc>
<refs>
<ref source="NAI">NAI-15</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142">00142</ref>
<ref source="XF">rpc-32771</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0190" seq="1999-0190">
<status>Entry</status>
<desc>Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167">00167</ref>
<ref source="XF">sun-rpcbind</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0191" seq="1999-0191">
<status>Entry</status>
<desc>IIS newdsn.exe CGI script allows remote users to overwrite files.</desc>
<refs>
<ref source="XF">http-cgi-newdsn</ref>
<ref source="OSVDB" url="http://www.osvdb.org/275">275</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0192" seq="1999-0192">
<status>Entry</status>
<desc>Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</desc>
<refs>
<ref source="SNI">SNI-20</ref>
<ref source="XF">bsd-tel-tgetent</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0194" seq="1999-0194">
<status>Entry</status>
<desc>Denial of service in in.comsat allows attackers to generate messages.</desc>
<refs>
<ref source="XF">comsat</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0196" seq="1999-0196">
<status>Entry</status>
<desc>websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</desc>
<refs>
<ref source="BUGTRAQ">19970704 Vulnerability in websendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2077">2077</ref>
<ref source="OSVDB" url="http://www.osvdb.org/237">237</ref>
<ref source="XF">http-webgais-smail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0201" seq="1999-0201">
<status>Entry</status>
<desc>A quote cwd command on FTP servers can reveal the full path of the home directory of the &quot;ftp&quot; user.</desc>
<refs>
<ref source="XF">ftp-home</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0202" seq="1999-0202">
<status>Entry</status>
<desc>The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</desc>
<refs>
<ref source="XF">ftp-exectar</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0203" seq="1999-0203">
<status>Entry</status>
<desc>In Sendmail, attackers can gain root privileges via SMTP by specifying an improper &quot;mail from&quot; address and an invalid &quot;rcpt to&quot; address that would cause the mail to bounce to a program.</desc>
<refs>
<ref source="CERT">CA-95.08</ref>
<ref source="CIAC">E-03</ref>
<ref source="XF">smtp-sendmail-version5</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0204" seq="1999-0204">
<status>Entry</status>
<desc>Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</desc>
<refs>
<ref source="XF">ident-bo</ref>
<ref source="CIAC">F-13</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0206" seq="1999-0206">
<status>Entry</status>
<desc>MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</desc>
<refs>
<ref source="XF">sendmail-mime-bo</ref>
<ref source="AUSCERT">AA-96.06a</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0207" seq="1999-0207">
<status>Entry</status>
<desc>Remote attacker can execute commands through Majordomo using the Reply-To field and a &quot;lists&quot; command.</desc>
<refs>
<ref source="XF">majordomo-exe</ref>
<ref source="CERT">CA-94.11.majordomo.vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0208" seq="1999-0208">
<status>Entry</status>
<desc>rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</desc>
<refs>
<ref source="XF">rpc-update</ref>
<ref source="CERT">CA-95.17.rpc.ypupdated.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0209" seq="1999-0209">
<status>Entry</status>
<desc>The SunView (SunTools) selection_svc facility allows remote users to read files.</desc>
<refs>
<ref source="CERT">CA-90.05.sunselection.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/8">8</ref>
<ref source="XF">selsvc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0210" seq="1999-0210">
<status>Entry</status>
<desc>Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88053459921223&amp;w=2">19971126 Solaris 2.5.1 automountd exploit (fwd)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104">HPSBUX9910-104</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/235">235</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0211" seq="1999-0211">
<status>Entry</status>
<desc>Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</desc>
<refs>
<ref source="CERT">CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/24">24</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0212" seq="1999-0212">
<status>Entry</status>
<desc>Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/168">00168</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-048.shtml">I-048</ref>
<ref source="XF">sun-mountd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0214" seq="1999-0214">
<status>Entry</status>
<desc>Denial of service by sending forged ICMP unreachable packets.</desc>
<refs>
<ref source="XF">icmp-unreachable</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0215" seq="1999-0215">
<status>Entry</status>
<desc>Routed allows attackers to append data to files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX">19981004-01-PX</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-012.shtml">J-012</ref>
<ref source="XF">ripapp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0217" seq="1999-0217">
<status>Entry</status>
<desc>Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</desc>
<refs>
<ref source="XF">udp-bomb</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0218" seq="1999-0218">
<status>Entry</status>
<desc>Livingston portmaster machines could be rebooted via a series of commands.</desc>
<refs>
<ref source="XF">portmaster-reboot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0219" seq="1999-0219">
<status>Entry</status>
<desc>Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2">19990503 Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="BUGTRAQ">19990909 Exploit: Serv-U Ver2.5 FTPd Win9x/NT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/269">269</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/205">ftp-servu(205)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0221" seq="1999-0221">
<status>Entry</status>
<desc>Denial of service of Ascend routers through port 150 (remote administration).</desc>
<refs>
<ref source="XF">ascend-150-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0223" seq="1999-0223">
<status>Entry</status>
<desc>Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.</desc>
<refs>
<ref source="BUGTRAQ">19961109 Syslogd and Solaris 2.4</ref>
<ref source="SUNBUG">1249320</ref>
<ref source="CONFIRM" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches">http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches</ref>
<ref source="XF">sol-syslogd-crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1878">1878</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0224" seq="1999-0224">
<status>Entry</status>
<desc>Denial of service in Windows NT messenger service through a long username.</desc>
<refs>
<ref source="XF">nt-messenger</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0225" seq="1999-0225">
<status>Entry</status>
<desc>Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp">19980214 Windows NT Logon Denial of Service</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=180963">Q180963</ref>
<ref source="XF">nt-logondos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0227" seq="1999-0227">
<status>Entry</status>
<desc>Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154087">Q154087</ref>
<ref source="XF">nt-lsass-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0228" seq="1999-0228">
<status>Entry</status>
<desc>Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</desc>
<refs>
<ref source="XF">nt-rpc-ver</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q162567">Q162567</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0230" seq="1999-0230">
<status>Entry</status>
<desc>Buffer overflow in Cisco 7xx routers through the telnet service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/pwbuf-pub.shtml</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1102">1102</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0233" seq="1999-0233">
<status>Entry</status>
<desc>IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q148188">Q148188</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q155056">Q155056</ref>
<ref source="XF">http-iis-cmd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0234" seq="1999-0234">
<status>Entry</status>
<desc>Bash treats any character with a value of 255 as a command separator.</desc>
<refs>
<ref source="XF">bash-cmd</ref>
<ref source="CERT">CA-96.22.bash_vuls</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0236" seq="1999-0236">
<status>Entry</status>
<desc>ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</desc>
<refs>
<ref source="XF">http-scriptalias</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0237" seq="1999-0237">
<status>Entry</status>
<desc>Remote execution of arbitrary commands through Guestbook CGI program.</desc>
<refs>
<ref source="XF">http-cgi-guestbook</ref>
<ref source="CERT">VB-97.02</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0239" seq="1999-0239">
<status>Entry</status>
<desc>Netscape FastTrack Web server lists files when a lowercase &quot;get&quot; command is used instead of an uppercase GET.</desc>
<refs>
<ref source="XF">fastrack-get-directory-list</ref>
<ref source="OSVDB" url="http://www.osvdb.org/122">122</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0244" seq="1999-0244">
<status>Entry</status>
<desc>Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.</desc>
<refs>
<ref source="NAI">NAI-23</ref>
<ref source="XF">radius-accounting-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0245" seq="1999-0245">
<status>Entry</status>
<desc>Some configurations of NIS+ in Linux allowed attackers to log in as the user &quot;+&quot;.</desc>
<refs>
<ref source="BUGTRAQ">19950907 Linux NIS security problem hole and fix</ref>
<ref source="XF">linux-plus</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0247" seq="1999-0247">
<status>Entry</status>
<desc>Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp">19970721 INN news server vulnerabilities</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1443">1443</ref>
<ref source="XF">inn-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0248" seq="1999-0248">
<status>Entry</status>
<desc>A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.</desc>
<refs>
<ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html">http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html</ref>
<ref source="CONFIRM" url="http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1">http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0251" seq="1999-0251">
<status>Entry</status>
<desc>Denial of service in talk program allows remote attackers to disrupt a user's display.</desc>
<refs>
<ref source="XF">talkd-flash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0252" seq="1999-0252">
<status>Entry</status>
<desc>Buffer overflow in listserv allows arbitrary command execution.</desc>
<refs>
<ref source="XF">smtp-listserv</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0256" seq="1999-0256">
<status>Entry</status>
<desc>Buffer overflow in War FTP allows remote execution of commands.</desc>
<refs>
<ref source="XF">war-ftpd</ref>
<ref source="OSVDB" url="http://www.osvdb.org/875">875</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0259" seq="1999-0259">
<status>Entry</status>
<desc>cfingerd lists all users on a system via search.**@target.</desc>
<refs>
<ref source="BUGTRAQ">19970523 cfingerd vulnerability</ref>
<ref source="XF">cfinger-user-enumeration</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0260" seq="1999-0260">
<status>Entry</status>
<desc>The jj CGI program allows command execution via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19961224 jj cgi</ref>
<ref source="XF">http-cgi-jj</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0262" seq="1999-0262">
<status>Entry</status>
<desc>Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</desc>
<refs>
<ref source="BUGTRAQ">19980804 remote exploit in faxsurvey cgi-script</ref>
<ref source="BUGTRAQ">19980804 PATCH: faxsurvey</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2056">2056</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1532">http-cgi-faxsurvey(1532)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0263" seq="1999-0263">
<status>Entry</status>
<desc>Solaris SUNWadmap can be exploited to obtain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/173">00173</ref>
<ref source="XF">sun-sunwadmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0264" seq="1999-0264">
<status>Entry</status>
<desc>htmlscript CGI program allows remote read access to files.</desc>
<refs>
<ref source="XF">http-htmlscript-file-access</ref>
<ref source="BUGTRAQ">Jan27,1998</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0265" seq="1999-0265">
<status>Entry</status>
<desc>ICMP redirect messages may crash or lock up a host.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154174">Q154174</ref>
<ref source="ISS">ICMP Redirects Against Embedded Controllers</ref>
<ref source="XF">icmp-redirect</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0266" seq="1999-0266">
<status>Entry</status>
<desc>The info2www CGI script allows remote file access or remote command execution.</desc>
<refs>
<ref source="BUGTRAQ">19980303 Vulnerabilites in some versions of info2www CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1995">1995</ref>
<ref source="XF">http-cgi-info2www</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0267" seq="1999-0267">
<status>Entry</status>
<desc>Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</desc>
<refs>
<ref source="XF">http-port</ref>
<ref source="CERT">CA-95.04.NCSA.http.daemon.for.unix.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0268" seq="1999-0268">
<status>Entry</status>
<desc>MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.</desc>
<refs>
<ref source="BUGTRAQ">19980630 Security vulnerabilities in MetaInfo products</ref>
<ref source="BUGTRAQ">19980703 Followup to MetaInfo vulnerabilities</ref>
<ref source="OSVDB" url="http://www.osvdb.org/110">110</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3969">3969</ref>
<ref source="XF">metaweb-server-dot-attack</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0269" seq="1999-0269">
<status>Entry</status>
<desc>Netscape Enterprise servers may list files through the PageServices query.</desc>
<refs>
<ref source="XF">netscape-server-pageservices</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0270" seq="1999-0270">
<status>Entry</status>
<desc>Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as &quot;pfdisplay&quot;) for SGI's Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.</desc>
<refs>
<ref source="BUGTRAQ">19980317 IRIX performer_tools bug</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P">19980401-01-P</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-041.shtml">I-041</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/64">64</ref>
<ref source="OSVDB" url="http://www.osvdb.org/134">134</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/810">sgi-pfdispaly(810)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0272" seq="1999-0272">
<status>Entry</status>
<desc>Denial of service in Slmail v2.5 through the POP3 port.</desc>
<refs>
<ref source="XF">slmail-username-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0273" seq="1999-0273">
<status>Entry</status>
<desc>Denial of service through Solaris 2.5.1 telnet by sending ^D characters.</desc>
<refs>
<ref source="XF">sun-telnet-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0274" seq="1999-0274">
<status>Entry</status>
<desc>Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn't made.</desc>
<refs>
<ref source="NAI">NAI-5</ref>
<ref source="XF">nt-dns-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0275" seq="1999-0275">
<status>Entry</status>
<desc>Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</desc>
<refs>
<ref source="XF">nt-dnscrash</ref>
<ref source="XF">nt-dnsver</ref>
<ref source="MS">Q169461</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0276" seq="1999-0276">
<status>Entry</status>
<desc>mSQL v2.0.1 and below allows remote execution through a buffer overflow.</desc>
<refs>
<ref source="XF">msql-debug-bo</ref>
<ref source="SEKURE">sekure.01-99.msql</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0277" seq="1999-0277">
<status>Entry</status>
<desc>The WorkMan program can be used to overwrite any file to get root access.</desc>
<refs>
<ref source="XF">workman</ref>
<ref source="CERT">CA-96.23.workman_vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0278" seq="1999-0278">
<status>Entry</status>
<desc>In IIS, remote attackers can obtain source code for ASP files by appending &quot;::$DATA&quot; to the URL.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-003.mspx">MS98-003</ref>
<ref source="XF">iis-asp-data-check</ref>
<ref source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:913">oval:org.mitre.oval:def:913</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0279" seq="1999-0279">
<status>Entry</status>
<desc>Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19971217 CGI security hole in EWS (Excite for Web Servers)</ref>
<ref source="BUGTRAQ">19980115 Excite announcement</ref>
<ref source="CERT">VB-98.01.excite</ref>
<ref source="XF">excite-cgi-search-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0280" seq="1999-0280">
<status>Entry</status>
<desc>Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</desc>
<refs>
<ref source="NTBUGTRAQ">19970317 Internet Explorer Bug #4</ref>
<ref source="CIAC">H-38</ref>
<ref source="XF">http-ie-lnkurl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0281" seq="1999-0281">
<status>Entry</status>
<desc>Denial of service in IIS using long URLs.</desc>
<refs>
<ref source="XF">http-iis-longurl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0288" seq="1999-0288">
<status>Entry</status>
<desc>The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.</desc>
<refs>
<ref source="NTBUGTRAQ">19970801 WINS flooding</ref>
<ref source="BUGTRAQ">19970801 WINS flooding</ref>
<ref source="BUGTRAQ">19970815 Re: WINS flooding</ref>
<ref source="MISC" url="http://safenetworks.com/Windows/wins.html">http://safenetworks.com/Windows/wins.html</ref>
<ref source="MSKB">155701</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1233">nt-winsupd-fix(1233)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0289" seq="1999-0289">
<status>Entry</status>
<desc>The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.</desc>
<refs>
</refs>
</item>

<item type="CVE" name="CVE-1999-0290" seq="1999-0290">
<status>Entry</status>
<desc>The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.</desc>
<refs>
<ref source="BUGTRAQ">19980221 WinGate DoS</ref>
<ref source="BUGTRAQ">19980326 WinGate Intermediary Fix/Update</ref>
<ref source="XF">wingate-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0291" seq="1999-0291">
<status>Entry</status>
<desc>The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.</desc>
<refs>
<ref source="XF">wingate-unpassworded</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0292" seq="1999-0292">
<status>Entry</status>
<desc>Denial of service through Winpopup using large user names.</desc>
<refs>
<ref source="XF">nt-winpopup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0293" seq="1999-0293">
<status>Entry</status>
<desc>AAA authentication on Cisco systems allows attackers to execute commands without authorization.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/aaapair-pub.shtml</ref>
<ref source="XF">cisco-ios-aaa-auth</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0294" seq="1999-0294">
<status>Entry</status>
<desc>All records in a WINS database can be deleted through SNMP for a denial of service.</desc>
<refs>
<ref source="XF">nt-wins-snmp2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0295" seq="1999-0295">
<status>Entry</status>
<desc>Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</desc>
<refs>
<ref source="XF">sun-sysdef</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157">00157</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0296" seq="1999-0296">
<status>Entry</status>
<desc>Solaris volrmmount program allows attackers to read any file.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/162">00162</ref>
<ref source="XF">sun-volrmmount</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0297" seq="1999-0297">
<status>Entry</status>
<desc>Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</desc>
<refs>
<ref source="NAI">NAI-3</ref>
<ref source="AUSCERT">AA-96.21</ref>
<ref source="CIAC">H-17</ref>
<ref source="XF">vixie-cron</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0299" seq="1999-0299">
<status>Entry</status>
<desc>Buffer overflow in FreeBSD lpd through long DNS hostnames.</desc>
<refs>
<ref source="NAI">NAI-9</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6093">6093</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0300" seq="1999-0300">
<status>Entry</status>
<desc>nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155">00155</ref>
<ref source="XF">sun-niscache</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0301" seq="1999-0301">
<status>Entry</status>
<desc>Buffer overflow in SunOS/Solaris ps command.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149">00149</ref>
<ref source="AUSCERT">AUSCERT-97.17</ref>
<ref source="XF">sun-ps2bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0302" seq="1999-0302">
<status>Entry</status>
<desc>SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/176">00176</ref>
<ref source="XF">sun-ftp-server</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0303" seq="1999-0303">
<status>Entry</status>
<desc>Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.</desc>
<refs>
<ref source="XF">bnu-uucpd-bo</ref>
<ref source="RSI">RSI.0002.05-18-98.BNU.UUCPD</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0304" seq="1999-0304">
<status>Entry</status>
<desc>mmap function in BSD allows local attackers in the kmem group to modify memory through devices.</desc>
<refs>
<ref source="XF">bsd-mmap</ref>
<ref source="FREEBSD">FreeBSD-SA-98:02</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0305" seq="1999-0305">
<status>Entry</status>
<desc>The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.</desc>
<refs>
<ref source="OPENBSD">Feb15,1998 &quot;IP Source Routing Problem&quot;</ref>
<ref source="MISC" url="http://www.openbsd.org/advisories/sourceroute.txt">http://www.openbsd.org/advisories/sourceroute.txt</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11502">11502</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/736">bsd-sourceroute(736)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0308" seq="1999-0308">
<status>Entry</status>
<desc>HP-UX gwind program allows users to modify arbitrary files.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018">HPSBUX9410-018</ref>
<ref source="XF">hpux-gwind-overwrite</ref>
<ref source="CIAC">H-03: HP-UX suid Vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0309" seq="1999-0309">
<status>Entry</status>
<desc>HP-UX vgdisplay program gives root access to local users.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056">HPSBUX9702-056</ref>
<ref source="XF">hpux-vgdisplay</ref>
<ref source="CIAC">H-27: HP-UX vgdisplay Buffer Overrun Vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0310" seq="1999-0310">
<status>Entry</status>
<desc>SSH 1.2.25 on HP-UX allows access to new user accounts.</desc>
<refs>
<ref source="XF">ssh-1225</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0311" seq="1999-0311">
<status>Entry</status>
<desc>fpkg2swpk in HP-UX allows local users to gain root access.</desc>
<refs>
<ref source="XF">hpux-fpkg2swpk</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042">HPSBUX9612-042</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0312" seq="1999-0312">
<status>Entry</status>
<desc>HP ypbind allows attackers with root privileges to modify NIS data.</desc>
<refs>
<ref source="XF">nis-ypbind</ref>
<ref source="CERT">CA-93:01.REVISED.HP.NIS.ypbind.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0313" seq="1999-0313">
<status>Entry</status>
<desc>disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</desc>
<refs>
<ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/214">214</ref>
<ref source="OSVDB" url="http://www.osvdb.org/936">936</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1441">sgi-disk-bandwidth(1441)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0314" seq="1999-0314">
<status>Entry</status>
<desc>ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</desc>
<refs>
<ref source="MISC" url="http://www.securityfocus.com/bid/213/exploit">http://www.securityfocus.com/bid/213/exploit</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/213">213</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6788">6788</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1199">sgi-ioconfig(1199)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0315" seq="1999-0315">
<status>Entry</status>
<desc>Buffer overflow in Solaris fdformat command gives root access to local users.</desc>
<refs>
<ref source="XF">fdformat-bo</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138">00138</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0316" seq="1999-0316">
<status>Entry</status>
<desc>Buffer overflow in Linux splitvt command gives root access to local users.</desc>
<refs>
<ref source="XF">linux-splitvt</ref>
<ref source="CIAC">G-08</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0318" seq="1999-0318">
<status>Entry</status>
<desc>Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</desc>
<refs>
<ref source="BUGTRAQ">19961125 Security Problems in XMCD</ref>
<ref source="BUGTRAQ">19961125 XMCD v2.1 released (was: Security Problems in XMCD)</ref>
<ref source="XF">xmcd-envbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0320" seq="1999-0320">
<status>Entry</status>
<desc>SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/166">00166</ref>
<ref source="XF">sun-rpc.cmsd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0321" seq="1999-0321">
<status>Entry</status>
<desc>Buffer overflow in Solaris kcms_configure command allows local users to gain root access.</desc>
<refs>
<ref source="XF">sun-kcms-configure-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0322" seq="1999-0322">
<status>Entry</status>
<desc>The open() function in FreeBSD allows local attackers to write to arbitrary files.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-97:05</ref>
<ref source="XF">freebsd-open</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6092">6092</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0323" seq="1999-0323">
<status>Entry</status>
<desc>FreeBSD mmap function allows users to modify append-only or immutable files.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:04</ref>
<ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc">1998-003</ref>
<ref source="XF">bsd-mmap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0324" seq="1999-0324">
<status>Entry</status>
<desc>ppl program in HP-UX allows local users to create root files through symlinks.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053">HPSBUX9702-053</ref>
<ref source="CIAC">H-31</ref>
<ref source="XF">hp-ppllog</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0325" seq="1999-0325">
<status>Entry</status>
<desc>vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</desc>
<refs>
<ref source="XF">hp-vhe</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013">HPSBUX9406-013</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0326" seq="1999-0326">
<status>Entry</status>
<desc>Vulnerability in HP-UX mediainit program.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071">HPSBUX9710-071</ref>
<ref source="XF">hp-mediainit</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0327" seq="1999-0327">
<status>Entry</status>
<desc>SGI syserr program allows local users to corrupt files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
<ref source="XF">sgi-syserr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0328" seq="1999-0328">
<status>Entry</status>
<desc>SGI permissions program allows local users to gain root privileges.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref>
<ref source="XF">sgi-permtool</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0329" seq="1999-0329">
<status>Entry</status>
<desc>SGI mediad program allows local users to gain root access.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX">19980602-01-PX</ref>
<ref source="XF">sgi-mediad</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0332" seq="1999-0332">
<status>Entry</status>
<desc>Buffer overflow in NetMeeting allows denial of service and remote command execution.</desc>
<refs>
<ref source="XF">nt-netmeeting</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q184346">Q184346</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0334" seq="1999-0334">
<status>Entry</status>
<desc>In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</desc>
<refs>
<ref source="XF">sol-startup</ref>
<ref source="CERT">CA-93.19.Solaris.Startup.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0335" seq="1999-0335">
<status>Entry</status>
<desc>DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</desc>
<refs>
</refs>
</item>

<item type="CVE" name="CVE-1999-0337" seq="1999-0337">
<status>Entry</status>
<desc>AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</desc>
<refs>
<ref source="CERT">CA-94.10.IBM.AIX.bsh.vulnerability.html</ref>
<ref source="XF">ibm-bsh</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0338" seq="1999-0338">
<status>Entry</status>
<desc>AIX Licensed Program Product performance tools allow local users to gain root access.</desc>
<refs>
<ref source="XF">ibm-perf-tools</ref>
<ref source="CERT">CA-94.03.AIX.performance.tools </ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0339" seq="1999-0339">
<status>Entry</status>
<desc>Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.</desc>
<refs>
<ref source="XF">sol-sun-libauth</ref>
<ref source="RSI">RSI.0007.05-26-98</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0340" seq="1999-0340">
<status>Entry</status>
<desc>Buffer overflow in Linux Slackware crond program allows local users to gain root access.</desc>
<refs>
<ref source="KSRT">005</ref>
<ref source="XF">linux-crond</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0341" seq="1999-0341">
<status>Entry</status>
<desc>Buffer overflow in the Linux mail program &quot;deliver&quot; allows local users to gain root access.</desc>
<refs>
<ref source="KSRT">006</ref>
<ref source="XF">linux-deliver</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0342" seq="1999-0342">
<status>Entry</status>
<desc>Linux PAM modules allow local users to gain root access using temporary files.</desc>
<refs>
<ref source="REDHAT">http://www.redhat.com/corp/support/errata/rh42-errata-general.html#pam</ref>
<ref source="XF">linux-pam-passwd-tmprace</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0343" seq="1999-0343">
<status>Entry</status>
<desc>A malicious Palace server can force a client to execute arbitrary programs.</desc>
<refs>
<ref source="BUGTRAQ">19981002 Announcements from The Palace (fwd)</ref>
<ref source="XF">palace-malicious-servers-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0344" seq="1999-0344">
<status>Entry</status>
<desc>NT users can gain debug-level access on a system process using the Sechole exploit.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-009.mspx">MS98-009</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q190288">Q190288</ref>
<ref source="XF">nt-priv-fix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0346" seq="1999-0346">
<status>Entry</status>
<desc>CGI PHP mlog script allows an attacker to read any file on the target server.</desc>
<refs>
<ref source="BUGTRAQ">19971019 Vulnerability in PHP Example Logging Scripts</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
<ref source="XF">http-cgi-php-mlog</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3397">3397</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0348" seq="1999-0348">
<status>Entry</status>
<desc>IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.</desc>
<refs>
<ref source="NTBUGTRAQ">Jan27,1999</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q197003">Q197003</ref>
<ref source="OSVDB" url="http://www.osvdb.org/930">930</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0349" seq="1999-0349">
<status>Entry</status>
<desc>A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/IIS Remote FTP Exploit/DoS Attack.html">IIS Remote FTP Exploit/DoS Attack</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx">MS99-003</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q188348">Q188348</ref>
<ref source="BUGTRAQ">Jan27,1999</ref>
<ref source="XF">iis-remote-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0350" seq="1999-0350">
<status>Entry</status>
<desc>Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.</desc>
<refs>
<ref source="L0PHT">Feb8,1999</ref>
<ref source="XF">clearcase-temp-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0351" seq="1999-0351">
<status>Entry</status>
<desc>FTP PASV &quot;Pizza Thief&quot; denial of service and unauthorized data access.  Attackers can steal data by connecting to a port that was intended for use by a client.</desc>
<refs>
<ref source="INFOWAR">01</ref>
<ref source="MISC" url="http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt">http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3389">pasv-pizza-thief-dos(3389)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0353" seq="1999-0353">
<status>Entry</status>
<desc>rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091">HPSBUX9902-091</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-026.shtml">J-026</ref>
<ref source="XF">pcnfsd-world-write</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0355" seq="1999-0355">
<status>Entry</status>
<desc>Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.</desc>
<refs>
<ref source="ISS">Multiple vulnerabilities in ControlIT(tm) (formerly Remotely Possible/32) enterprise management software</ref>
<ref source="XF">controlit-reboot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0357" seq="1999-0357">
<status>Entry</status>
<desc>Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted &quot;oshare&quot; packets, possibly involving invalid fragmentation offsets.</desc>
<refs>
<ref source="BUGTRAQ">19990125 Win98 crash?</ref>
<ref source="XF">win98-oshare-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0358" seq="1999-0358">
<status>Entry</status>
<desc>Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.</desc>
<refs>
<ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12121">19990125 Digital Unix 4.0 exploitable buffer overflows</ref>
<ref source="COMPAQ">SSRT0583U</ref>
<ref source="XF">du-inc</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-027.shtml">J-027</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0362" seq="1999-0362">
<status>Entry</status>
<desc>WS_FTP server remote denial of service through cwd command.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02021999.html">AD02021999</ref>
<ref source="XF">wsftp-remote-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/217">217</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0363" seq="1999-0363">
<status>Entry</status>
<desc>SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.</desc>
<refs>
<ref source="BUGTRAQ">Feb02,1999</ref>
<ref source="XF">plp-lpc-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/328">328</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0365" seq="1999-0365">
<status>Entry</status>
<desc>The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.</desc>
<refs>
<ref source="BUGTRAQ">Feb04,1999</ref>
<ref source="XF">metamail-header-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0366" seq="1999-0366">
<status>Entry</status>
<desc>In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-004.mspx">MS99-004</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q214840">Q214840</ref>
<ref source="XF">nt-sp4-auth-error</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0367" seq="1999-0367">
<status>Entry</status>
<desc>NetBSD netstat command allows local users to access kernel memory.</desc>
<refs>
<ref source="NETBSD">1999-002</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7571">7571</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0368" seq="1999-0368">
<status>Entry</status>
<desc>Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.</desc>
<refs>
<ref source="NETECT">palmetto.ftpd</ref>
<ref source="CERT">CA-99.03</ref>
<ref source="XF">palmetto-ftpd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0369" seq="1999-0369">
<status>Entry</status>
<desc>The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183">00183</ref>
<ref source="XF">sun-sdtcm-convert-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0371" seq="1999-0371">
<status>Entry</status>
<desc>Lynx allows a local user to overwrite sensitive files through /tmp symlinks.</desc>
<refs>
<ref source="BUGTRAQ">19990211 Lynx /tmp problem</ref>
<ref source="CERT">VB-97.05.lynx</ref>
<ref source="XF">lynx-temp-files-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0372" seq="1999-0372">
<status>Entry</status>
<desc>The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-005.mspx">MS99-005</ref>
<ref source="XF">nt-backoffice-setup</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q217004">Q217004</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0373" seq="1999-0373">
<status>Entry</status>
<desc>Buffer overflow in the &quot;Super&quot; utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.</desc>
<refs>
<ref source="ISS">Buffer Overflow in &quot;Super&quot; package in Debian Linux</ref>
<ref source="XF">linux-super-bo</ref>
<ref source="XF">linux-super-logging-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0374" seq="1999-0374">
<status>Entry</status>
<desc>Debian GNU/Linux cfengine package is susceptible to a symlink attack.</desc>
<refs>
<ref source="DEBIAN">19990215</ref>
<ref source="BUGTRAQ">Feb16,1999</ref>
<ref source="XF">linux-cfengine-symlinks</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0375" seq="1999-0375">
<status>Entry</status>
<desc>Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.</desc>
<refs>
<ref source="NAI">February 16, 1999</ref>
<ref source="BUGTRAQ">Feb16,1999</ref>
<ref source="XF">nfr-webd-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0376" seq="1999-0376">
<status>Entry</status>
<desc>Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-006.mspx">MS99-006</ref>
<ref source="BUGTRAQ">Feb20,1999</ref>
<ref source="L0PHT">Feb18,1999</ref>
<ref source="XF">nt-knowndlls-list</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0377" seq="1999-0377">
<status>Entry</status>
<desc>Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine's process tables through multiple connections to network services.</desc>
<refs>
<ref source="BUGTRAQ">Feb22,1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0378" seq="1999-0378">
<status>Entry</status>
<desc>InterScan VirusWall for Solaris doesn't scan files for viruses when a single HTTP request includes two GET commands.</desc>
<refs>
<ref source="BUGTRAQ">19990222 BlackHats Advisory -- InterScan VirusWall</ref>
<ref source="BUGTRAQ">19990225 Patch for InterScan VirusWall for Unix now available</ref>
<ref source="XF">viruswall-http-request</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6167">6167</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0379" seq="1999-0379">
<status>Entry</status>
<desc>Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-007.mspx">MS99-007</ref>
<ref source="BUGTRAQ">19990223 Microsoft Security Bulletin (MS99-007)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/498">498</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1019">1019</ref>
<ref source="XF">win-resourcekit-taskpads</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0380" seq="1999-0380">
<status>Entry</status>
<desc>SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91999015212415&amp;w=2">199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91996412724720&amp;w=2">19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92110501504997&amp;w=2">SLmail 3.2 Build 3113 (Web Administration Security Fix)</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/497">497</ref>
<ref source="XF" url="http://xforce.iss.net/static/5392.php">slmail-ras-ntfs-bypass(5392)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0382" seq="1999-0382">
<status>Entry</status>
<desc>The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-008.mspx">MS99-008</ref>
<ref source="XF">nt-screen-saver</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0383" seq="1999-0383">
<status>Entry</status>
<desc>ACC Tigris allows public access without a login.</desc>
<refs>
<ref source="BUGTRAQ">19990103 Tigris vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/183">183</ref>
<ref source="OSVDB" url="http://www.osvdb.org/267">267</ref>
<ref source="XF">acc-tigris-login</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0384" seq="1999-0384">
<status>Entry</status>
<desc>The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.</desc>
<refs>
<ref source="XF">forms-vuln-patch</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-001.mspx">MS99-001</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0385" seq="1999-0385">
<status>Entry</status>
<desc>The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-009.mspx">MS99-009</ref>
<ref source="ISS">LDAP Buffer overflow against Microsoft Directory Services</ref>
<ref source="XF">ldap-exchange-overflow</ref>
<ref source="XF">ldap-mds-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0386" seq="1999-0386">
<status>Entry</status>
<desc>Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-010.mspx">MS99-010</ref>
<ref source="XF">pws-file-access</ref>
<ref source="OSVDB" url="http://www.osvdb.org/111">111</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0387" seq="1999-0387">
<status>Entry</status>
<desc>A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.</desc>
<refs>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-052.asp">MS99-052</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q168115">Q168115</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/829">829</ref>
<ref source="XF">9x-plaintext-pwd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0388" seq="1999-0388">
<status>Entry</status>
<desc>DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.</desc>
<refs>
<ref source="XF">datalynx-suguard-relative-paths</ref>
<ref source="L0PHT">Jan3,1999</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3186">3186</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0390" seq="1999-0390">
<status>Entry</status>
<desc>Buffer overflow in Dosemu Slang library in Linux.</desc>
<refs>
<ref source="BUGTRAQ">19990104 Dosemu/S-Lang Overflow + sploit</ref>
<ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt">CSSA-1999-006.1</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/187">187</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0391" seq="1999-0391">
<status>Entry</status>
<desc>The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.</desc>
<refs>
<ref source="L0PHT">Jan. 5, 1999</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0392" seq="1999-0392">
<status>Entry</status>
<desc>Buffer overflow in Thomas Boutell's cgic library version up to 1.05.</desc>
<refs>
<ref source="BUGTRAQ">Jan10,1999</ref>
<ref source="XF">http-cgic-library-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0393" seq="1999-0393">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.</desc>
<refs>
<ref source="BUGTRAQ">19981212 ** Sendmail 8.9.2 DoS - exploit ** get what you want!</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91694391227372&amp;w=2">19990121 Sendmail 8.8.x/8.9.x bugware</ref>
<ref source="XF">sendmail-parsing-redirection</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0395" seq="1999-0395">
<status>Entry</status>
<desc>A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.</desc>
<refs>
<ref source="ISS" url="http://xforce.iss.net/alerts/advise17.php">19990118 Vulnerability in the BackWeb Polite Agent Protocol</ref>
<ref source="XF">backweb-polite-agent-protocol</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0396" seq="1999-0396">
<status>Entry</status>
<desc>A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.</desc>
<refs>
<ref source="NETBSD">1999-001</ref>
<ref source="OPENBSD">Feb17,1999</ref>
<ref source="XF">netbsd-tcp-race</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0402" seq="1999-0402">
<status>Entry</status>
<desc>wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.</desc>
<refs>
<ref source="BUGTRAQ">Feb2,1999</ref>
<ref source="XF">wget-permissions</ref>
<ref source="DEBIAN">19990220</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0403" seq="1999-0403">
<status>Entry</status>
<desc>A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91821080015725&amp;w=2">19990204 Cyrix bug: freeze in hell, badboy</ref>
<ref source="XF">cyrix-hang</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0404" seq="1999-0404">
<status>Entry</status>
<desc>Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.</desc>
<refs>
<ref source="BUGTRAQ">Feb14,1999</ref>
<ref source="XF">mailmax-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0405" seq="1999-0405">
<status>Entry</status>
<desc>A buffer overflow in lsof allows local users to obtain root privilege.</desc>
<refs>
<ref source="HERT">002</ref>
<ref source="BUGTRAQ">Feb18,1999</ref>
<ref source="DEBIAN">19990220a</ref>
<ref source="XF">lsof-bo</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3163">3163</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0407" seq="1999-0407">
<status>Entry</status>
<desc>By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91983486431506&amp;w=2">19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92000623021036&amp;w=2">19990209 Re: IIS4 allows proxied password attacks over NetBIOS</ref>
<ref source="XF">iis-iisadmpwd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0408" seq="1999-0408">
<status>Entry</status>
<desc>Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.</desc>
<refs>
<ref source="BUGTRAQ">19990225 Cobalt root exploit</ref>
<ref source="XF">cobalt-raq-history-exposure</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/337">337</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0409" seq="1999-0409">
<status>Entry</status>
<desc>Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.</desc>
<refs>
<ref source="BUGTRAQ">19990304 Linux /usr/bin/gnuplot overflow</ref>
<ref source="XF">gnuplot-home-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/319">319</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0410" seq="1999-0410">
<status>Entry</status>
<desc>The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.</desc>
<refs>
<ref source="BUGTRAQ">Mar5,1999</ref>
<ref source="XF">sol-cancel</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/293">293</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0412" seq="1999-0412">
<status>Entry</status>
<desc>In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.</desc>
<refs>
<ref source="BUGTRAQ">Feb19,1999</ref>
<ref source="XF">iis-isapi-execute</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/501">501</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0413" seq="1999-0413">
<status>Entry</status>
<desc>A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX">19990301-01-PX</ref>
<ref source="XF">irix-font-path-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0414" seq="1999-0414">
<status>Entry</status>
<desc>In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.</desc>
<refs>
<ref source="NAI">Linux Blind TCP Spoofing</ref>
<ref source="XF">linux-blind-spoof</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0415" seq="1999-0415">
<status>Entry</status>
<desc>The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router's configuration.</desc>
<refs>
<ref source="ISS">19990311 Remote Reconfiguration and Denial of Service Vulnerabilities in Cisco 700 ISDN Routers</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
<ref source="XF">cisco-router-commands</ref>
<ref source="XF">cisco-web-config</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0416" seq="1999-0416">
<status>Entry</status>
<desc>Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router's TELNET port.</desc>
<refs>
<ref source="ISS">19990311 Remote Reconfiguration and Denial of Service Vulnerabilities in Cisco 700 ISDN Routers</ref>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref>
<ref source="XF">cisco-web-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0417" seq="1999-0417">
<status>Entry</status>
<desc>64 bit Solaris 7 procfs allows local users to perform a denial of service.</desc>
<refs>
<ref source="BUGTRAQ">Mar9,1999</ref>
<ref source="XF">solaris-psinfo-crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/448">448</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1001">1001</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0420" seq="1999-0420">
<status>Entry</status>
<desc>umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.</desc>
<refs>
<ref source="NETBSD">1999-006</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0421" seq="1999-0421">
<status>Entry</status>
<desc>During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</desc>
<refs>
<ref source="ISS">Short-Term High-Risk Vulnerability During Slackware 3.6 Network Installations</ref>
<ref source="XF">linux-slackware-install</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/338">338</ref>
<ref source="OSVDB" url="http://www.osvdb.org/981">981</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0422" seq="1999-0422">
<status>Entry</status>
<desc>In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the &quot;noexec&quot; flag set.</desc>
<refs>
<ref source="NETBSD">1999-007</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0423" seq="1999-0423">
<status>Entry</status>
<desc>Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093">HPSBUX9903-093</ref>
<ref source="XF">hp-hpterm-files</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0424" seq="1999-0424">
<status>Entry</status>
<desc>talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.</desc>
<refs>
<ref source="SUSE">Mar18,1999</ref>
<ref source="XF">netscape-talkback-overwrite</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0425" seq="1999-0425">
<status>Entry</status>
<desc>talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.</desc>
<refs>
<ref source="SUSE">Mar18,1999</ref>
<ref source="XF">netscape-talkback-kill</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0428" seq="1999-0428">
<status>Entry</status>
<desc>OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.</desc>
<refs>
<ref source="BUGTRAQ">19990322 OpenSSL/SSLeay Security Alert</ref>
<ref source="XF">ssl-session-reuse</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3936">3936</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0429" seq="1999-0429">
<status>Entry</status>
<desc>The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the &quot;Encrypt Saved Mail&quot; preference.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92221437025743&amp;w=2">19990323</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92241547418689&amp;w=2">19990324 Re: LNotes encryption</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92246997917866&amp;w=2">19990326 Lotus Notes Encryption Bug</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92249282302994&amp;w=2">19990326 Re: Lotus Notes security advisory</ref>
<ref source="XF">lotus-client-encryption</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0430" seq="1999-0430">
<status>Entry</status>
<desc>Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.</desc>
<refs>
<ref source="ISS">Remote Denial of Service Vulnerability in Cisco Catalyst Series Ethernet Switches</ref>
<ref source="CISCO">Cisco Catalyst Supervisor Remote Reload</ref>
<ref source="XF">cisco-catalyst-crash</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1103">1103</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0432" seq="1999-0432">
<status>Entry</status>
<desc>ftp on HP-UX 11.00 allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094">HPSBUX9903-094</ref>
<ref source="XF">hp-ftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0433" seq="1999-0433">
<status>Entry</status>
<desc>XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</desc>
<refs>
<ref source="SUSE">Mar28,1999</ref>
<ref source="BUGTRAQ">19990321 X11R6 NetBSD Security Problem</ref>
<ref source="XF">xfree86-temp-directories</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0436" seq="1999-0436">
<status>Entry</status>
<desc>Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095">HPSBUX9903-095</ref>
<ref source="XF">hp-desms-servers</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0437" seq="1999-0437">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.</desc>
<refs>
<ref source="ISS">WebRamp Denial of Service Attacks</ref>
<ref source="XF">webramp-device-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0438" seq="1999-0438">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.</desc>
<refs>
<ref source="ISS">WebRamp Denial of Service Attacks</ref>
<ref source="XF">webramp-ipchange</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0439" seq="1999-0439">
<status>Entry</status>
<desc>Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.</desc>
<refs>
<ref source="BUGTRAQ">19990405 Re: [SECURITY] new version of procmail with security fixes</ref>
<ref source="DEBIAN">19990422</ref>
<ref source="CALDERA">CSSA-1999:007</ref>
<ref source="XF">procmail-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0440" seq="1999-0440">
<status>Entry</status>
<desc>The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92333596624452&amp;w=2">19990405 Security Hole in Java 2 (and JDK 1.1.x)</ref>
<ref source="CONFIRM" url="http://java.sun.com/pr/1999/03/pr990329-01.html">http://java.sun.com/pr/1999/03/pr990329-01.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1939">1939</ref>
<ref source="XF">java-unverified-code</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0441" seq="1999-0441">
<status>Entry</status>
<desc>Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.</desc>
<refs>
<ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02221999.html">AD02221999</ref>
<ref source="XF">wingate-redirector-dos</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/509">509</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0442" seq="1999-0442">
<status>Entry</status>
<desc>Solaris ff.core allows local users to modify files.</desc>
<refs>
<ref source="BUGTRAQ">19990107 really silly ff.core exploit for Solaris</ref>
<ref source="BUGTRAQ">19990108 ff.core exploit on Solaris (2.)7</ref>
<ref source="BUGTRAQ">19990408 Solaris7 and ff.core</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/327">327</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0445" seq="1999-0445">
<status>Entry</status>
<desc>In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.</desc>
<refs>
<ref source="CISCO">Cisco IOS(R) Software Input Access List Leakage with NAT</ref>
<ref source="XF">cisco-natacl-leakage</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1104">1104</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0446" seq="1999-0446">
<status>Entry</status>
<desc>Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.</desc>
<refs>
<ref source="NETBSD">1999-008</ref>
<ref source="XF">netbsd-vfslocking-panic</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7051">7051</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0447" seq="1999-0447">
<status>Entry</status>
<desc>Local users can gain privileges using the debug utility in the MPE/iX operating system.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006">HPSBMP9904-006</ref>
<ref source="XF">mpeix-debug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0448" seq="1999-0448">
<status>Entry</status>
<desc>IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.</desc>
<refs>
<ref source="BUGTRAQ">19990121 IIS 4 Request Logging Security Advisory</ref>
<ref source="XF">iis-http-request-logging</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0449" seq="1999-0449">
<status>Entry</status>
<desc>The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.</desc>
<refs>
<ref source="BUGTRAQ">19990126 IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="NTBUGTRAQ">19990126 IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="BUGTRAQ">19990125 Re: [NTSEC] IIS 4 Advisory - ExAir sample site DoS</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/193">193</ref>
<ref source="OSVDB" url="http://www.osvdb.org/2">2</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3">3</ref>
<ref source="OSVDB" url="http://www.osvdb.org/4">4</ref>
<ref source="XF">iis-exair-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0457" seq="1999-0457">
<status>Entry</status>
<desc>Linux ftpwatch program allows local users to gain root privileges.</desc>
<refs>
<ref source="BUGTRAQ">Jan17,1999</ref>
<ref source="DEBIAN">19990117</ref>
<ref source="XF">ftpwatch-vuln</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/317">317</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999