<?xml version="1.0" encoding="UTF-8"?>
<nvd nvd_xml_version="1.2" pub_date="2008-09-05" xmlns="http://nvd.nist.gov/feeds/cve/1.2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://nvd.nist.gov/feeds/cve/1.2 http://nvd.nist.gov/schema/nvdcve.xsd"><!--This XML file has been upgraded to support CVSS version 2.  The following new attributes have been added to CVS entries:
* CVSS_version - Indicates the version of the CVSS data
* CVSS_base_score - The CVSSv2 base score
* CVSS_impact_subscore - The CVSSv2 impact sub-score
* CVSS_exploit_subscore - the CVSSv2 exploit sub-score

The following attributes have been mapped to new content in CVS entries:
* CVSS_score - This attribute is the same as the CVSS_base_score and is now deprecated.
* CVSS_vector - Contains the new CVSSv2 vector string--><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2008-06-20" name="CVE-1999-0001" published="1999-12-30" seq="1999-0001" severity="Medium" type="CVE"><desc><descript source="cve">ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1998-13.html">CA-1998-13</ref><ref source="" url="http://www.openbsd.org/errata23.html#tcpfix"></ref><ref source="OSVDB" url="http://www.osvdb.org/5707">5707</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="1.0"/><vers num="1.1"/><vers num="1.1.5.1"/><vers num="1.2"/><vers num="2.0"/><vers num="2.0.1"/><vers num="2.0.5"/><vers num="2.1.5"/><vers num="2.1.6"/><vers num="2.1.6.1"/><vers num="2.1.7"/><vers num="2.1.7.1"/><vers num="2.2"/><vers num="2.2.2"/><vers num="2.2.3"/><vers num="2.2.4"/><vers num="2.2.5"/><vers num="2.2.6"/><vers num="2.2.8"/><vers num="3.0"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/><vers num="2.3"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0002" published="1998-10-12" seq="1999-0002" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.12.mountd.html">CA-98.12</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/121">BID 121</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1411.php">linux-mountd-bo(1411)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I">19981006-01-I</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-006.shtml">J-006</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/><vers num="3.0.3"/><vers num="2.1"/><vers num="2.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="1.1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0003" published="1998-04-01" seq="1999-0003" severity="High" type="CVE"><desc><descript source="cve">Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.11.tooltalk.html">CA-98.11</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/122">BID 122</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/813.php">aix-ttdbserver(813)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1408.php">tooltalk(1408)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A">19981101-01-A</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX">19981101-01-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/122">122</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod><prod name="TED CDE" vendor="TriTreal"><vers num="4.3"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers num="1.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.3"/><vers num="10.2"/><vers num="10.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0004" published="1997-12-16" seq="1999-0004" severity="Medium" type="CVE"><desc><descript source="cve">MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-98.10.mime_buffer_overflows.html">CERT:CA-98.10.mime_buffer_overflows</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1217.php">outlook-long-name</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-008.asp">MS98-008</ref></refs><vuln_soft><prod name="UnixWare" vendor="SCO"><vers num="7.0"/></prod><prod name="dtmail" vendor="HP"><vers num=""/></prod><prod name="Pine" vendor="University of Washington"><vers num="4.02"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-1999-0005" published="1998-07-20" seq="1999-0005" severity="High" type="CVE"><desc><descript source="cve">Arbitrary command execution via IMAP buffer overflow in authenticate command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.09.imapd.html">CA-98.09.imapd</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/130">BID 130</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177">00177</ref><ref source="BID" url="http://www.securityfocus.com/bid/130">130</ref></refs><vuln_soft><prod name="Netscape Messaging Server" vendor="Netscape"><vers num="3.55"/></prod><prod name="IMAP" vendor="University of Washington"><vers num="10.234"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0006" published="1998-07-14" seq="1999-0006" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in POP servers based on BSD/Qualcomm&apos;s qpopper allows remote attackers to gain root access using a long PASS command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1890.php">qpopper-pass-overflow(1890)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.08.qpopper_vul.html">CA-98.08.qpopper_vul</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/133">BID 133</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I">19980801-01-I</ref><ref source="BID" url="http://www.securityfocus.com/bid/133">133</ref></refs><vuln_soft><prod name="qpopper" vendor="Qualcomm"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0007" published="1998-06-26" seq="1999-0007" severity="Medium" type="CVE"><desc><descript source="cve">Information from SSL-encrypted sessions via PKCS #1.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.07.PKCS.html">CA-98.07.PKCS</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/676">BID 676</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx">MS98-002</ref></refs><vuln_soft><prod name="Site Server" vendor="Microsoft"><vers num="3.0"/></prod><prod name="SSLeay" vendor="SSLeay"><vers num="0.9"/><vers num="0.8.1"/><vers num="0.6.6"/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/></prod><prod name="Collabra Server" vendor="Netscape"><vers num="3.5.2"/></prod><prod name="exchange srv" vendor="Microsoft"><vers num="5.5"/></prod><prod name="Netscape Messaging Server" vendor="Netscape"><vers num="3.54"/></prod><prod name="Netscape Directory Server" vendor="Netscape"><vers num="3.12"/><vers num="3.1P1"/><vers num="1.3P5"/></prod><prod name="Certificate Server" vendor="Netscape"><vers num="1.0P1"/></prod><prod name="FastTrack" vendor="Netscape"><vers num="3.0.1B"/></prod><prod name="Netscape Proxy Server" vendor="Netscape"><vers num="3.5.1"/></prod><prod name="Secure WebServer" vendor="Open Market"><vers num="2.1"/></prod><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.51"/><vers num="3.0.1b"/><vers num="2.0"/></prod><prod name="StongHold Web Server" vendor="C2Net"><vers num="2.3"/><vers num="2.2"/><vers num="2.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0008" published="1998-06-08" seq="1999-0008" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NIS+, in Sun&apos;s rpc.nisd program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.06.nisd.html">CA-98.06.nisd</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/962.php">nisd-bo-check(962)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/104">bugtraq id 104</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170">00170</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers num="2.5.1"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.34"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0009" published="1998-04-08" seq="1999-0009" severity="High" type="CVE"><desc><descript source="cve">Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.05.bind_problems.html">CA-98.05.bind_problems</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/895.php">bind-bo(895)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/134">BID 134</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref><ref source="BID" url="http://www.securityfocus.com/bid/134">134</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/><vers num="4.0.5 IPR"/><vers num="4.0.5H"/><vers num="4.0.5G"/><vers num="4.0.5F"/><vers num="4.0.5E"/><vers num="4.0.5D"/><vers num="4.0.5A"/><vers num="4.0.5 IOP"/><vers num="4.0.5"/><vers num="4.0.4T"/><vers num="4.0.4B"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1T"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.3.3"/><vers num="3.3.2"/><vers num="3.3.1"/><vers num="3.3"/><vers num="3.2"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2.1"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="DG_UX" vendor="Data General"><vers num="5.4_4.11"/><vers num="5.4_4.1"/><vers num="5.4_3.1"/><vers num="5.4_3.0"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/><vers num="5.0"/></prod><prod name="UnixWare" vendor="SCO"><vers num="7.0"/><vers num="2.1"/></prod><prod name="BIND" vendor="ISC"><vers num="8.1.1"/><vers num="8.1"/><vers num="4.9.6"/></prod><prod name="UX_4800" vendor="NEC"><vers num="64"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0010" published="1998-04-08" seq="1999-0010" severity="Medium" type="CVE"><desc><descript source="cve">Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.05.bind_problems.html">CA-98.05.bind_problems</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/896.php">bind-dos(896)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref></refs><vuln_soft><prod name="Unix" vendor="SCO"><vers num="3.2v4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="DG_UX" vendor="Data General"><vers num="Y2K patchR4.20MU03"/><vers num="Y2K patchR4.20MU02"/><vers num="Y2K patchR4.20MU01"/><vers num="Y2K patchR4.11MU05"/><vers num="Y2K patchR4.12MU03"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/><vers num="7.0"/></prod><prod name="BIND" vendor="ISC"><vers num="8"/><vers num="4.9"/></prod><prod name="UX_4800" vendor="NEC"><vers num="11"/><vers num="13"/></prod><prod name="Solaris" vendor="Sun"><vers num="5.3"/><vers num="5.4"/><vers num="5.5"/><vers num="5.5.1"/><vers num="5.6"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1.x"/><vers num="4.2.x"/><vers num="4.3.x"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.2"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-02-27" name="CVE-1999-0011" published="1998-04-08" seq="1999-0011" severity="High" type="CVE"><desc><descript source="cve">Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.05.bind_problems.html">CA-98.05.bind_problems</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2346.php">bind-axfr-dos (2346)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref></refs><vuln_soft><prod name="Unix" vendor="SCO"><vers num="3.2v4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="DG_UX" vendor="Data General"><vers num="Y2K patchR4.20MU03"/><vers num="Y2K patchR4.20MU02"/><vers num="Y2K patchR4.20MU01"/><vers num="Y2K patchR4.11MU05"/><vers num="Y2K patchR4.12MU03"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/><vers num="7.0"/></prod><prod name="BIND" vendor="ISC"><vers num="8"/><vers num="4.9"/></prod><prod name="UX_4800" vendor="NEC"><vers num="11"/><vers num="13"/></prod><prod name="Solaris" vendor="Sun"><vers num="5.3"/><vers num="5.4"/><vers num="5.5"/><vers num="5.5.1"/><vers num="5.6"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1.x"/><vers num="4.2.x"/><vers num="4.3.x"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.2"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0012" published="1998-02-06" seq="1999-0012" severity="Medium" type="CVE"><desc><descript source="cve">Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.04.Win32.WebServers.html">CA-98.04.Win32.WebServers</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/709.php">nt-web8.3(709)</ref></refs><vuln_soft><prod name="Personal Web Server" vendor="Microsoft"><vers num="4.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.0"/></prod><prod name="Frontpage" vendor="Microsoft"><vers num=""/></prod><prod name="FastTrack" vendor="Netscape"><vers num="2.01"/><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0013" published="1998-01-22" seq="1999-0013" severity="High" type="CVE"><desc><descript source="cve">Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.03.ssh-agent.html">CA-98.03.ssh-agent</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/700.php">ssh-agent(700)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/138">bugtraq id 138</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.9"/><vers num="1.2.8"/><vers num="1.2.7"/><vers num="1.2.6"/><vers num="1.2.5"/><vers num="1.2.4"/><vers num="1.2.3"/><vers num="1.2.2"/><vers num="1.2.14"/><vers num="1.2.13"/><vers num="1.2.12"/><vers num="1.2.11"/><vers num="1.2.10"/><vers num="1.2.1"/><vers num="1.2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0014" published="1998-01-21" seq="1999-0014" severity="High" type="CVE"><desc><descript source="cve">Unauthorized privileged access or denial of service via dtappgather program in CDE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.02.CDE.html">CA-98.02.CDE</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075">HPSBUX9801-075</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185">00185</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.10"/><vers num="10.20"/><vers edition="VVOS" num="10.24"/><vers num="11.0"/></prod><prod name="CDE" vendor="CDE"><vers num="1.2"/><vers num="1.2_x86"/><vers num="1.02"/><vers num="1.02_x86"/><vers num="1.01"/><vers num="1.01_x86"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0015" published="1997-12-16" seq="1999-0015" severity="Medium" type="CVE"><desc><descript source="cve">Teardrop IP denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-97.28.Teardrop_Land.html">CERT:CA-97.28 Denial of Service Attack</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.3u1"/><vers num="4.1.4"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="3.5"/><vers num="3.5.1"/><vers num="4.0"/><vers num="3.5.1 SP1"/><vers num="3.5.1 SP2"/><vers num="4.0 SP1"/><vers num="4.0 SP2"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="0.0a"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.2.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="9.0"/><vers num="9.1"/><vers num="9.3"/><vers num="9.4"/><vers num="9.5"/><vers num="9.7"/><vers num="10"/><vers num="10.1"/><vers num="10.16"/><vers num="10.20"/><vers num="10.24"/><vers num="10.30"/><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0016" published="1997-12-01" seq="1999-0016" severity="Medium" type="CVE"><desc><descript source="cve">Land IP denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1" buffer="1"/><exception/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.28.Teardrop_Land.html">CA-97.28.Teardrop_Land</ref><ref adv="1" patch="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-98:01.land.asc">FreeBSD-SA-98:01</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1246.php">cisco-land(1246)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/288.php">land(288)</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/770/land-pub.shtml">http://www.cisco.com/warp/public/770/land-pub.shtml</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076">HPSBUX9801-076</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="7000"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.0"/><vers num="1.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.30"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/><vers num="9.4"/><vers num="9.3"/><vers num="9.5"/><vers num="9.7"/><vers num="9.1"/><vers num="9.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3u1"/><vers num="4.1.4"/></prod><prod name="WinSock" vendor="Microsoft"><vers num="2.0"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="inet" vendor="GNU"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0017" published="1997-12-10" seq="1999-0017" severity="High" type="CVE"><desc><descript source="cve">FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.27.FTP_bounce.html">CA-97.27.FTP_bounce</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/199.php">ftp-bounce(199)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/892.php">ftp-privileged-port(892)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.0"/><vers num="1.1"/><vers num="1.2"/><vers num="1.2.1"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.5.1"/><vers edition="x86" num="5.5.1"/><vers num="5.5"/><vers edition="x86" num="5.5"/><vers num="5.4"/><vers edition="x86" num="5.4"/><vers num="5.3"/><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/></prod><prod name="Wu-ftpd" vendor="Washington University"><vers num="2.4"/></prod><prod name="inet" vendor="GNU"><vers num="5.01"/><vers num="6.01"/><vers num="6.02"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.7"/><vers num="2.1.0"/><vers num="2.0"/><vers num="1.2"/><vers num="1.1"/><vers num="1.0"/></prod><prod name="Reliant UNIX" vendor="Siemens"><vers num=""/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.4"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-16" name="CVE-1999-0018" published="1997-12-05" seq="1999-0018" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in statd allows root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.26.statd.html">CA-97.26</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/696.php">statd(696)</ref><ref patch="1" source="BID" url="http://www.securityfocus.com/bid/127">127</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="3.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod><prod name="IRIX" vendor="SGI"><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0019" published="1996-04-24" seq="1999-0019" severity="Medium" type="CVE"><desc><descript source="cve">Delete or create a file via rpc.statd, due to invalid information.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.09.rpc.statd.html">CA-96.09.rpc.statd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/109.php">rps-stat(109)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.1"/></prod><prod name="CX_UX" vendor="NightHawk"><vers num=""/></prod><prod name="DG_UX" vendor="Data General"><vers num="4.11"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="2"/><vers num="3"/></prod><prod name="Unixware" vendor="SCO"><vers num="2"/></prod><prod name="MP-RAS" vendor="NCR"><vers num="2.03"/><vers num="3.0"/></prod><prod name="PowerUX" vendor="NightHawk"><vers num=""/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.4"/><vers num="5.3"/><vers num="5.4"/><vers edition="x86" num="5.4"/><vers num="5.5"/><vers edition="x86" num="5.5"/></prod><prod name="OpenServer" vendor="SCO"><vers num="3.0"/><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="3.2"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-1999-0020" published="1999-01-01" reject="1" seq="1999-0020" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0032.  Reason: This candidate is a duplicate of CVE-1999-0032.  Notes: All CVE users should reference CVE-1999-0032 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0021" published="1997-11-05" seq="1999-0021" severity="High" type="CVE"><desc><descript source="cve">Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.24.Count_cgi.html">CA-97.24.Count_cgi</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/586.php">http-cgi-count(586)</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/128">bugtraq id 128</ref><ref source="BID" url="http://www.securityfocus.com/bid/128">128</ref></refs><vuln_soft><prod name="wwwcount" vendor="Muhammad A. Muquit"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0022" published="1996-07-03" seq="1999-0022" severity="High" type="CVE"><desc><descript source="cve">Local user gains root privileges via buffer overflow in rdist, via expstr() function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.23.rdist.html">CA-97.23.rdist</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/129">BID 129</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/559.php">rdist-bo3(559)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/540.php">rdist-sept97(540)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/><vers num="3.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers edition="U1" num="4.1.3"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="1.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.0"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0023" published="1996-07-24" seq="1999-0023" severity="High" type="CVE"><desc><descript source="cve">Local user gains root privileges via buffer overflow in rdist, via lookup() function.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.14.rdist_vul.html">CA-96.14.rdist_vul</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/421.php">rdist-bo(421)</ref></refs><vuln_soft><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.2"/><vers num="5.0"/><vers num="2.0"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.0"/><vers num="2.0.5"/><vers num="2.1.0"/><vers num="2.2"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="2.0"/><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.0"/><vers num="2.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="1.1"/><vers num="1.1.1a"/><vers num="1.1.2"/><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.3u1"/><vers num="4.1.4"/><vers num="5.3"/><vers num="5.4"/><vers num="5.5"/><vers num="5.5.1"/></prod><prod name="TCP/IP" vendor="SCO"><vers num="1.2.0"/><vers num="1.2.1"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod><prod name="inet" vendor="inet"><vers num="5.01"/><vers num="6.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0" modified="2008-05-19" name="CVE-1999-0024" published="1997-08-13" seq="1999-0024" severity="Medium" type="CVE"><desc><descript source="cve">DNS cache poisoning via BIND, by predictable query IDs.</descript></desc><loss_types><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.22.bind.html">CA-97.22.bind</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/485.php">bind(485)</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/678">BID 678</ref></refs><vuln_soft><prod name="Unix" vendor="SCO"><vers num="3.2v4"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/></prod><prod name="BIND" vendor="ISC"><vers num="8.1"/><vers num="4.9.5"/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num="4.2MP"/><vers num="4.2"/></prod><prod name="UX_4800" vendor="NEC"><vers num="64"/></prod><prod name="UP-UX_V" vendor="NEC"><vers num="4.2MP"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0025" published="1997-07-16" seq="1999-0025" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in df command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/440.php">AUSCERT:AA-97.19.IRIX.df.buffer.overflow.vul,XF:df-bo</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CA-1997-21</ref><ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/20851">VU#20851</ref><ref source="BID" url="http://www.securityfocus.com/bid/346">346</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/440">df-bo(440)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0026" published="1997-07-16" seq="1999-0026" severity="Medium" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in pset command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/442.php">pset-bo(442)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0027" published="1997-07-16" seq="1999-0027" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in eject command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CERT:CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/441.php">AUSCERT:AA-97.21.IRIX.eject.buffer.overflow.vul,XF:eject-bo</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0028" published="1997-07-16" seq="1999-0028" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/443.php">sgi-schemebo(443)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0029" published="1997-07-16" seq="1999-0029" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in ordist command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.21.sgi_buffer_overflow.html">CA-97.21.sgi_buffer_overflow</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/444.php">ordist-bo(444)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0030" published="1997-07-16" seq="1999-0030" severity="High" type="CVE"><desc><descript source="cve">root privileges via buffer overflow in xlock command on SGI IRIX systems.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CERT:CA-97.21.sgi_buffer_overflow</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0031" published="1997-07-08" seq="1999-0031" severity="Low" type="CVE"><desc><descript source="cve">JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user&apos;s web activities, aka the Bell Labs vulnerability.</descript></desc><loss_types><conf/></loss_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.20.javascript.html">CA-97.20 JavaScript Vulnerability</ref><ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html">HPSBUX9707-065</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="2.0"/><vers num="3.0"/><vers num="4.0"/></prod><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0.0"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0032" published="1996-10-25" seq="1999-0032" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.19.bsdlp.html">CA-97.19.bsdlp</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/707">BID 707</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/843.php">lpr-bo(843)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/409.php">bsd-lprbo(409)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/446.php">bsd-lprbo2(446)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/707">707</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="NeXTstep" vendor="NeXT"><vers num="4.1"/><vers num="4.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0033" published="1997-06-12" seq="1999-0033" severity="High" type="CVE"><desc><descript source="cve">Command execution in Sun systems via buffer overflow in the at program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-97.18.at.html">Vulnerability in the At(1) program</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/705.php">sun-atbo(705)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num=""/></prod><prod name="MP-RAS" vendor="NCR"><vers num="3.0"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="OpenServer" vendor="SCO"><vers num="3.0"/><vers num="5.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.3"/><vers edition="x86" num="5.4"/><vers num="5.4"/><vers edition="x86" num="5.5"/><vers num="5.5"/><vers edition="x86" num="5.5.1"/><vers num="5.5.1"/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/><vers num="3.2v4"/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0034" published="1997-05-29" seq="1999-0034" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.17.sperl.html">CA-97.17.sperl</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/448.php">perl-suid(448)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/708">bugtraq id 708</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="Perl" vendor="Larry Wall"><vers num="5.3"/></prod><prod name="Freeware" vendor="SGI"><vers num="2.0"/><vers num="1.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.0"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-07" name="CVE-1999-0035" published="1997-05-29" seq="1999-0035" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/><race/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.16.ftpd.html">CA-97.16.ftpd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/449.php">ftp-ftpd(449)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod><prod name="inet" vendor="GNU"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0036" published="1997-05-26" seq="1999-0036" severity="High" type="CVE"><desc><descript source="cve">IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.15.sgi_login.html">CA-97.15.sgi_login</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/392">bugtraq id 392</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/557.php">sgi-lockout(557)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-106.shtml">H-106</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX">19970508-02-PX</ref><ref source="OSVDB" url="http://www.osvdb.org/990">990</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/557">sgi-lockout(557)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0037" published="1997-05-21" seq="1999-0037" severity="High" type="CVE"><desc><descript source="cve">Arbitrary command execution via metamail package using message headers, when user processes attacker&apos;s message using metamail.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.14.metamail.html">CA-97.14.metamail</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1676.php">metamail-header-commands(1676)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Linux" vendor="Red Hat"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0038" published="1997-04-26" seq="1999-0038" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in xlock program allows local users to execute commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.13.xlock.html">CA-97.13.xlock</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/224">BID 224</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/483.php">xlock-bo(483)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="DG_UX" vendor="Data General"><vers num="7.0"/><vers num="6.0"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.8"/><vers num="10.34"/><vers num="10.30"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/><vers num="0.93"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0039" published="1997-05-06" seq="1999-0039" severity="High" type="CVE"><desc><descript source="cve">webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.12.webdist.html">CA-97.12.webdist</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/374">BID 374</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/333.php">http-sgi-webdist(333)</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1997-12.html">CA-1997-12</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/374">374</ref><ref source="OSVDB" url="http://www.osvdb.org/235">235</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/333">http-sgi-webdist(333)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0040" published="1997-05-01" seq="1999-0040" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.11.libXt.html">CA-97.11.libXt</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/237">BID 237</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/489.php">libXt-bo(489)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.0"/><vers num="4.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/><vers num="4.1.3"/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num="4.2MP"/><vers num="4.2"/></prod><prod name="UX_4800" vendor="NEC"><vers num="64"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="HP-UX" vendor="HP"><vers num="9.10"/><vers num="9.1"/><vers num="9.0"/><vers num="10.9"/><vers num="10.8"/><vers num="10.34"/><vers num="10.30"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.0"/><vers num="1.1.5.1"/></prod><prod name="UP-UX_V" vendor="NEC"><vers num="4.2MP"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="2.0.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0041" published="1997-02-13" seq="1999-0041" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NLS (Natural Language Service).</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.10.nls.html">CA-97.10.nls</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/711">BID 711</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/450.php">nls-bo(450)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2.5"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.0"/></prod><prod name="libc" vendor="Linux"><vers num="5.3.12"/><vers num="5.2.18"/><vers num="5.0.9"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="3.1"/></prod><prod name="UNICOS_mk" vendor="Cray"><vers num="1.5"/></prod><prod name="UNICOS" vendor="Cray"><vers num="9.2"/><vers num="9.0"/><vers num="1.3 MAX"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0042" published="1997-04-07" seq="1999-0042" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in University of Washington&apos;s implementation of IMAP and POP servers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.09.imap_pop.html">CA-97.09.imap_pop</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/96.php">popimap-bo(96)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.0"/><vers num="2.0"/></prod><prod name="IMAP" vendor="University of Washington"><vers num="4"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="3.0"/></prod><prod name="POP" vendor="University of Washington"><vers num="3"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-03-29" name="CVE-1999-0043" published="1996-12-04" seq="1999-0043" severity="High" type="CVE"><desc><descript source="cve">Command execution via shell metachars in INN daemon (innd) 1.5 using &quot;newgroup&quot; and &quot;rmgroup&quot; control messages, and others.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.08.innd.html">CA-97.08.innd</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=580o28$9jp@senator-bedfellow.MIT.EDU"></ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/687">BID 687</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/184.php">inn-controlmsg(184)</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="1.5"/><vers num="1.4unoff4"/><vers num="1.4unoff3"/><vers num="1.4sec2"/><vers num="1.4sec"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.1"/><vers num="4.0"/></prod><prod name="Goah_NetworkSV" vendor="NEC"><vers num="3.1"/><vers num="2.2"/><vers num="1.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod><prod name="News Server" vendor="Netscape"><vers num="1.1"/></prod><prod name="Goah_IntraSV" vendor="NEC"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0044" published="1996-12-03" seq="1999-0044" severity="High" type="CVE"><desc><descript source="cve">fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/355">BID 355</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2106.php">sgi-fsdump(2106)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0045" published="1996-12-10" seq="1999-0045" severity="High" type="CVE"><desc><descript source="cve">List of arbitrary files on Web host via nph-test-cgi script.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.07.nph-test-cgi_script.html">CA-97.07.nph-test-cgi_script</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/686">BID 686</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/289.php">http-cgi-nph(289)</ref></refs><vuln_soft><prod name="Netscape Commerce Server" vendor="Netscape"><vers num="1.12"/></prod><prod name="Netscape Communications Server" vendor="Netscape"><vers num="1.12"/><vers num="1.1"/></prod><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="2.0a"/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.1"/><vers num="1.0.5"/><vers num="1.0.3"/><vers num="1.0.2"/><vers num="1.0"/><vers num="0.8.14"/><vers num="0.8.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0046" published="1997-02-06" seq="1999-0046" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow of rlogin program using TERM environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.06.rlogin-term.html">CA-97.06.rlogin-term</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/242">BID 242</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/423.php">rlogin-termbo(423)</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.1"/><vers num="1.0"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0B"/><vers num="4.0A"/><vers num="4.0"/><vers num="3.2G"/></prod><prod name="Ultrix" vendor="Digital"><vers num="4.5"/><vers num="4.4"/><vers num="4.3a"/><vers num="4.3"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/><vers num="3.0"/><vers num="2.2"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="NeXTstep" vendor="NeXT"><vers num="4.0"/><vers num="3.3"/><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.1"/><vers num="2.0"/><vers num="1.0a"/><vers num="1.0"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="0.93"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.9"/><vers num="10.8"/><vers num="10.34"/><vers num="10.30"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/></prod><prod name="DG_UX" vendor="Data General"><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/><vers num="2.0.1"/><vers num="2.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0047" published="1997-01-28" seq="1999-0047" severity="High" type="CVE"><desc><descript source="cve">MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.05.sendmail.html">CA-97.05.sendmail</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/685">bugtraq id 685</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1835.php">sendmail-mime-bo2(1835)</ref><ref source="BID" url="http://www.securityfocus.com/bid/685">685</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.8.4"/><vers num="8.8.3"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-07" name="CVE-1999-0048" published="1997-01-27" seq="1999-0048" severity="High" type="CVE"><desc><descript source="cve">Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.04.talkd.html">CA-97.04.talkd</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/453.php">talkd-bo(453)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/413.php">netkit-talkd(413)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147">00147</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.1"/><vers num="4.1"/><vers num="4.2"/></prod><prod name="NetKit" vendor="Debian"><vers num="0.07"/></prod><prod name="UP-UX_V" vendor="NEC"><vers num=""/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num=""/></prod><prod name="UX_4800" vendor="NEC"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0049" published="1997-01-08" seq="1999-0049" severity="High" type="CVE"><desc><descript source="cve">Csetup under IRIX allows arbitrary file creation or overwriting.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.03.csetup.html">CA_97.04.csetup</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/452.php">sgi-csetup(452)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5"/><vers num="6.0"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0050" published="1996-12-01" seq="1999-0050" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HP-UX newgrp program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.02.hp_newgrp.html">CA-97.02.hp_newgrp</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/683">BID 683</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/451.php">hp-newgrpbo(451)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.9"/><vers num="9.8"/><vers num="9.7"/><vers num="9.6"/><vers num="9.5"/><vers num="9.4"/><vers num="9.3"/><vers num="9.10"/><vers num="9.1"/><vers num="9.0"/><vers num="10.20"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0051" published="1997-01-06" seq="1999-0051" severity="High" type="CVE"><desc><descript source="cve">Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-97.01.flex_lm.html">CA-97.01.flex_lm</ref><ref source="Security Focus" url="http://securityfocus.com/vdb/cve.html?cve=CVE-1999-0051"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/893.php">sgi-licensemanager(893)</ref></refs><vuln_soft><prod name="license_oeo" vendor="SGI"><vers num="3.1.1"/><vers num="3.1"/><vers num="3.0"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4JL"/><vers num="4.1.4"/><vers num="4.1.3u1"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/><vers num="4.0.5 IPR"/><vers num="4.0.5H"/><vers num="4.0.5G"/><vers num="4.0.5F"/><vers num="4.0.5E"/><vers num="4.0.5D"/><vers num="4.0.5A"/><vers num="4.0.5 IOP"/><vers num="4.0.5"/><vers num="4.0.4T"/><vers num="4.0.4B"/><vers num="4.0.4"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1T"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.3.3"/><vers num="3.3.2"/></prod><prod name="FLEXlm" vendor="GLOBEtrotter"><vers num="5.0"/><vers num="4.1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0052" published="1998-11-04" seq="1999-0052" severity="Medium" type="CVE"><desc><descript source="cve">IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/120">BID 120</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1389.php">freebsd-ip-frag-dos(1389)</ref><ref source="OSVDB" url="http://www.osvdb.org/908">908</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1389">freebsd-ip-frag-dos(1389)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2.8"/><vers num="2.2.2"/><vers num="2.1.7.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/><vers num="1.1.5.1"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0053" published="1998-10-13" seq="1999-0053" severity="Medium" type="CVE"><desc><descript source="cve">TCP RST denial of service in FreeBSD.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/6094">6094</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0054" published="1998-06-10" seq="1999-0054" severity="Medium" type="CVE"><desc><descript source="cve">Sun&apos;s ftpd daemon can be subjected to a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/709">BID 709</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1127.php">sun-ftpd(1127)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171">00171</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0055" published="1998-05-14" seq="1999-0055" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in Sun libnsl allow root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/148">BID 148</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1204.php">sun-libnsl(1024)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172">00172</ref><ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only">IX80543</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3.2"/><vers num="4.3.1"/><vers num="4.3"/><vers num="4.2.1"/><vers num="4.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0056" published="1998-09-09" seq="1999-0056" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Sun&apos;s ping program can give root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1365.php">sun-ping(1365)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174">00174</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/></prod><prod name="SunOS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-07" name="CVE-1999-0057" published="1998-11-16" seq="1999-0057" severity="High" type="CVE"><desc><descript source="cve">Vacation program allows command execution by remote users through a sendmail command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/569.php">vacation(569)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087">HPSBUX9811-087</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Vacation" vendor="Eric Allman"><vers num=""/></prod><prod name="VVOS" vendor="HP"><vers num=""/></prod><prod name="Solaris" vendor="Sun"><vers num=""/></prod><prod name="SunOS" vendor="Sun"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num="10.24"/><vers num="10.0"/><vers num="10.9"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0058" published="1997-04-17" seq="1999-0058" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in PHP cgi program, php.cgi allows shell access.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/712">bugtraq id 712</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/293.php">http-cgi-phpbo(293)</ref><ref source="BID" url="http://www.securityfocus.com/bid/712">712</ref></refs><vuln_soft><prod name="PHP_FI" vendor="PHP"><vers num="2.0b10"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.1" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.9" CVSS_score="7.1" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0059" published="1997-07-14" seq="1999-0059" severity="High" type="CVE"><desc><descript source="cve">IRIX fam service allows an attacker to obtain a list of all files on the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/353">bugtraq id 353</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/325.php">irix-fam(325)</ref><ref source="BID" url="http://www.securityfocus.com/bid/353">353</ref><ref source="OSVDB" url="http://www.osvdb.org/164">164</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/325">irix-fam(325)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0060" published="1998-03-16" seq="1999-0060" severity="Medium" type="CVE"><desc><descript source="cve">Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/714">BID 714</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/889.php">ascend-config-kill(889)</ref><ref source="ASCEND" url="http://www.ascend.com/2695.html">http://www.ascend.com/2695.html</ref></refs><vuln_soft><prod name="Ascend TNT Router" vendor="Lucent"><vers num="2.0"/><vers num="1.0"/></prod><prod name="Ascend Pipeline Router" vendor="Lucent"><vers num="6.0"/><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod><prod name="Ascend MAX Router" vendor="Lucent"><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0061" published="1997-10-02" seq="1999-0061" severity="Medium" type="CVE"><desc><descript source="cve">File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/568.php">bsd-lpd(568)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.1"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0062" published="1998-08-03" seq="1999-0062" severity="High" type="CVE"><desc><descript source="cve">The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1220.php">openbsd-chpass(1220)</ref><ref source="OSVDB" url="http://www.osvdb.org/7559">7559</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0063" published="1999-01-11" seq="1999-0063" severity="Medium" type="CVE"><desc><descript source="cve">Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/iossyslog-pub.shtml"></ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/675">BID 675</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1558.php">cisco-syslog-crash(1558)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0.2XD"/><vers num="12.0.2XC"/><vers num="12.0.1XE"/><vers num="12.0.1XB"/><vers num="12.0.1XA3"/><vers num="12.0.1W"/><vers num="12.0T"/><vers num="12.0S"/><vers num="12.0DB"/><vers num="12.0"/><vers num="11.3DB"/><vers num="11.3AA"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0064" published="1997-05-26" seq="1999-0064" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX lquerylv program gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/451">BID 451</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/386.php">lquerylv-bo(386)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0065" published="1998-08-31" seq="1999-0065" severity="High" type="CVE"><desc><descript source="cve">Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/175">BID 175</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1367.php">hp-dtmail(1367)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181">00181</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0066" published="1995-07-31" seq="1999-0066" severity="High" type="CVE"><desc><descript source="cve">AnyForm CGI remote execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/719">BID 719</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/301.php">http-cgi-anyform(301)</ref><ref source="BID" url="http://www.securityfocus.com/bid/719">719</ref></refs><vuln_soft><prod name="AnyForm" vendor="John S. Roberts"><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0067" published="1996-03-20" seq="1999-0067" severity="High" type="CVE"><desc><descript source="cve">phf CGI program allows remote command execution through shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/629">bugtraq id 629</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-96.06.cgi_example_code.html">CA-96.06.cgi_example_code</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/148.php">http-cgi-phf(148)</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</ref><ref source="BID" url="http://www.securityfocus.com/bid/629">629</ref><ref source="OSVDB" url="http://www.osvdb.org/136">136</ref></refs><vuln_soft><prod name="NCSA httpd" vendor="NCSA"><vers edition="export" num="1.5a"/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.0.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0068" published="1997-10-19" seq="1999-0068" severity="High" type="CVE"><desc><descript source="cve">CGI PHP mylog script allows an attacker to read any file on the target server.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/713">bugtraq id 713</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1468.php">http-cgi-php-mylog(1468)</ref><ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref><ref source="OSVDB" url="http://www.osvdb.org/3396">3396</ref></refs><vuln_soft><prod name="PHP_FI" vendor="PHP"><vers num="2.0b10"/><vers num="2.0"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0069" published="1998-04-29" seq="1999-0069" severity="High" type="CVE"><desc><descript source="cve">Solaris ufsrestore buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/966.php">sun-ufsrestore(966)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169">00169</ref><ref source="OSVDB" url="http://www.osvdb.org/8158">8158</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5"/><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0070" published="1996-04-01" seq="1999-0070" severity="Medium" type="CVE"><desc><descript source="cve">test-cgi program allows an attacker to list files on the server.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/149.php">http-cgi-test(149)</ref></refs><vuln_soft><prod name="NCSA Web Server" vendor="NCSA"><vers num=""/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0071" published="1997-09-01" seq="1999-0071" severity="High" type="CVE"><desc><descript source="cve">Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/331.php">http-apache-cookie</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="1.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0072" published="1997-10-22" seq="1999-0072" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX xdat gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/449">bugtraq id 449</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/585.php">ibm-xdat(585)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0073" published="1995-10-13" seq="1999-0073" severity="High" type="CVE"><desc><descript source="cve">Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.14.Telnetd_Environment_Vulnerability.html">CA-95.14.Telnetd_Environment_Vulnerability</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/459">BID 459</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/67.php">linkerbug(67)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/><vers num="5.0"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0"/><vers num="3.2G"/></prod><prod name="OSF_1" vendor="Digital"><vers num="3.2"/><vers num="3.0"/><vers num="2.0"/><vers num="1.3"/><vers num="1.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0074" published="1997-07-01" seq="1999-0074" severity="Medium" type="CVE"><desc><descript source="cve">Listening TCP ports are sequentially allocated, allowing spoofing attacks.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/209.php">seqport(209)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0075" published="1996-10-16" seq="1999-0075" severity="Medium" type="CVE"><desc><descript source="cve">PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</descript></desc><loss_types><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/200.php">ftp-pasvcore(200)</ref><ref source="OSVDB" url="http://www.osvdb.org/5742">5742</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0076" published="1997-07-01" seq="1999-0076" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in wu-ftp from PASV command causes a core dump.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/201.php">ftp-args(201)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0077" published="1995-01-01" seq="1999-0077" severity="Medium" type="CVE"><desc><descript source="cve">Predictable TCP sequence numbers allow spoofing.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/vdb/cve.html?cve=CVE-1999-0077"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/139.php">tcp-seq-predict(139)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.9" CVSS_exploit_subscore="3.4" CVSS_impact_subscore="2.9" CVSS_score="1.9" CVSS_vector="(AV:L/AC:M/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0078" published="1996-04-18" seq="1999-0078" severity="Low" type="CVE"><desc><descript source="cve">pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-96.08.pcnfsd.html">Vulnerabilities in PCNFSD</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.3"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1"/></prod><prod name="NeXTstep" vendor="NeXT"><vers num=""/></prod><prod name="Unixware" vendor="SCO"><vers num="2.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers num="2.5"/></prod><prod name="MP-RAS" vendor="NCR"><vers num="2.03"/><vers num="3.0"/><vers num="3.01"/></prod><prod name="UP-UX_V" vendor="NEC"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num=""/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0079" published="1997-09-12" seq="1999-0079" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/271">bugtraq id 271</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/563.php">ftp-pasv-dos(563)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/202.php">ftp-pasvdos(202)</ref></refs><vuln_soft><prod name="BisonWare FTP Server" vendor="BisonWare"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0080" published="1995-11-30" seq="1999-0080" severity="High" type="CVE"><desc><descript source="cve">Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the &quot;site exec&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.16.wu-ftpd.vul.html">CA-95.16.wu-ftpd.vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/618.php">ftp-execdotdot(618)</ref></refs><vuln_soft><prod name="Wu-ftpd" vendor="Washington University"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0081" published="1997-01-11" seq="1999-0081" severity="Medium" type="CVE"><desc><descript source="cve">wu-ftp allows files to be overwritten via the rnfr command.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/324.php">ftp-rnfr(324)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0082" published="1988-11-11" seq="1999-0082" severity="High" type="CVE"><desc><descript source="cve">CWD ~root command in ftpd allows root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/54.php">ftp-cwd(54)</ref><ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref></refs><vuln_soft><prod name="FTP" vendor="FTP"><vers num=""/></prod><prod name="ftpcd" vendor="ftpcd"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0083" published="1997-06-11" seq="1999-0083" severity="Medium" type="CVE"><desc><descript source="cve">getcwd() file descriptor leak in FTP.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/335.php">cwdleak(335)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0084" published="1990-05-01" seq="1999-0084" severity="High" type="CVE"><desc><descript source="cve">Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/78">nfs-mknod(78)</ref></refs><vuln_soft><prod name="NFS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0085" published="1996-08-21" seq="1999-0085" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/118.php">rwhod-vuln(118)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/119">rwhod(119)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/118">rwhod-vuln(118)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0086" published="1998-01-08" seq="1999-0086" severity="Medium" type="CVE"><desc><descript source="cve">AIX routed allows remote users to modify sensitive files.</descript></desc><loss_types><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-2_num-1.php">IBM-routed</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.x"/><vers num="4.1.x"/><vers num="4.2.x"/><vers num="4.3.x"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0087" published="1998-02-01" seq="1999-0087" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/706.php">ibm-telnetdos(706)</ref><ref source="OSVDB" url="http://www.osvdb.org/7992">7992</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0088" published="1998-10-26" seq="1999-0088" severity="High" type="CVE"><desc><descript source="cve">IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0089" published="1997-10-28" seq="1999-0089" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX libDtSvc library can allow local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs/><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0090" published="1997-10-01" seq="1999-0090" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX rcp command allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/400">BID 400</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2296.php">ibm-rcp(2296)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0091" published="1997-10-28" seq="1999-0091" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX writesrv command allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/399">BID 399</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2295.php">ibm-writesrv(2295)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0092" published="1997-10-29" seq="1999-0092" severity="High" type="CVE"><desc><descript source="cve">Various vulnerabilities in the AIX portmir command allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-1_num-6.phpportmir">IBM-portmir</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0093" published="1997-10-29" seq="1999-0093" severity="High" type="CVE"><desc><descript source="cve">AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/377">BID 377</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/604.php">ibm-nslookup(604)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0094" published="1997-10-29" seq="1999-0094" severity="Medium" type="CVE"><desc><descript source="cve">AIX piodmgrsu command allows local users to gain additional group privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/386">BID 386</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/593.php">ibm-piodmgrsu(593)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0095" published="1988-10-01" seq="1999-0095" severity="High" type="CVE"><desc><descript source="cve">The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-88.01.ftpd.hole.html">CA-88.01</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-93.14.Internet.Security.Scanner.html">CA-93.14</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/1">BID 1</ref><ref source="BID" url="http://www.securityfocus.com/bid/1">1</ref><ref source="OSVDB" url="http://www.osvdb.org/195">195</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="5.58"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0096" published="1996-12-10" seq="1999-0096" severity="Medium" type="CVE"><desc><descript source="cve">Sendmail decode alias can be used to overwrite sensitive files.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.25.sendmail_groups.html">CA-96.25.sendmail_groups</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/126.php">smtp-dcod(126)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.5"/><vers num="2.1.6"/><vers num="2.1.6.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/><vers num="5.0.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0097" published="1997-10-29" seq="1999-0097" severity="High" type="CVE"><desc><descript source="cve">The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/396">BID 396</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/605.php">ibm-ftp(605)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2.1"/><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3c"/><vers num="4.1.3u1"/></prod><prod name="HP-UX" vendor="HP"><vers num="9.9"/><vers num="9.8"/><vers num="9.7"/><vers num="9.6"/><vers num="9.5"/><vers num="9.4"/><vers num="9.3"/><vers num="9.10"/><vers num="9.1"/><vers num="9.0"/><vers num="11.0"/><vers num="10.24"/><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0098" published="1998-04-01" seq="1999-0098" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/886.php">smtp-helo-bo(886)</ref></refs><vuln_soft><prod name="Slmail" vendor="Slmail"><vers num="2.6"/></prod><prod name="AppleShare IP" vendor="Apple"><vers num=""/></prod><prod name="Mercury Mail Server" vendor="Mercury"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0099" published="1995-10-19" seq="1999-0099" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.13.syslog.vul.html">CA-95.13</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/129.php">smtp-syslog(129)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="3.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.0"/><vers num="2.0.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers edition="x86" num="2.4"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.3u1"/><vers num="4.1.4"/></prod><prod name="SPP-UX" vendor="Convex"><vers num="3"/></prod><prod name="ConvexOS" vendor="Convex"><vers num="10.1"/><vers num="10.2"/><vers num="11.0"/><vers num="11.1"/></prod><prod name="UNICOS" vendor="Cray"><vers num="8.0"/><vers num="8.3"/><vers num="9.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0100" published="1997-01-01" seq="1999-0100" severity="High" type="CVE"><desc><descript source="cve">Remote access in AIX innd 1.5.1, using control messages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/184.php">inn-controlmsg(184)</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0101" published="1996-12-10" seq="1999-0101" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX and Solaris &quot;gethostbyname&quot; library call allows root access through corrupt DNS host names.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">IBM AIX(r) Security Vulnerabilities (gethostbyname,lquerypv)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1751.php">ghbn-bo(1751)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0102" published="1998-07-09" seq="1999-0102" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/153">bugtraq id 153</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1595.php">slmail-fromheader-overflow(1595)</ref></refs><vuln_soft><prod name="SLMail" vendor="Seattle Lab Software"><vers num="3.0.2421"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0103" published="1996-02-08" seq="1999-0103" severity="Medium" type="CVE"><desc><descript source="cve">Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.01.UDP_service_denial.html">CA-96.01.UDP_service_denial</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0104" published="1997-12-16" seq="1999-0104" severity="Medium" type="CVE"><desc><descript source="cve">A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-97.28.Teardrop_Land.html">IP Denial of Service</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/343.php">teardrop-mod</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="4.0 SP1"/><vers num="4.0 SP2"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="0a"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="2.0"/></prod><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0105" published="1997-03-01" seq="1999-0105" severity="Low" type="CVE"><desc><descript source="cve">finger allows recursive searches by using a long string of @ symbols.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/47.php">fingerbomb</ref></refs></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0106" published="1997-03-01" seq="1999-0106" severity="Low" type="CVE"><desc><descript source="cve">Finger redirection allows finger bombs.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/47.php">fingerbomb</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0107" published="1997-12-30" seq="1999-0107" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-1_num-10.phplist">apache-dos</ref></refs><vuln_soft><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num="0.8.11"/><vers num="0.8.14"/><vers num="1.0"/><vers num="1.0.2"/><vers num="1.0.3"/><vers num="1.0.5"/><vers num="1.1"/><vers num="1.1.1"/><vers num="1.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0108" published="1998-05-01" seq="1999-0108" severity="High" type="CVE"><desc><descript source="cve">The printers program in IRIX has a buffer overflow that gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/808.php">printers-bo(808)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0109" published="1997-02-10" seq="1999-0109" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ffbconfig in Solaris 2.5.1.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/202">BID 202</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/874.php">ffbconfig-bo(874)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140">00140</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-1999-0110" published="1999-01-01" reject="1" seq="1999-0110" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0315.  Reason: This candidate&apos;s original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315.  Notes: All CVE users should reference CVE-1999-0315 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0111" published="1997-07-01" seq="1999-0111" severity="Medium" type="CVE"><desc><descript source="cve">RIP v1 is susceptible to spoofing.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/703.php">ibm-routed(703)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0112" published="1997-05-01" seq="1999-0112" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX dtterm program for the CDE.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/878.php">dtterm-bo(878)</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/878">dtterm-bo(878)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="4.2"/></prod><prod name="CDE" vendor="CDE"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0113" published="1994-05-23" seq="1999-0113" severity="High" type="CVE"><desc><descript source="cve">Some implementations of rlogin allow root access if given a -froot parameter.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.09.bin.login.vulnerability.html">CA-94.09.bin.login.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/104.php">rlogin-froot(104)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/458">BID 458</ref><ref source="BID" url="http://www.securityfocus.com/bid/458">458</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0114" published="1998-01-01" seq="1999-0114" severity="Medium" type="CVE"><desc><descript source="cve">Local users can execute commands as other users, and read other users&apos; files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/711.php">elm-filter2(711)</ref></refs><vuln_soft><prod name="ELM" vendor="Elm Development Group"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-21" name="CVE-1999-0115" published="1997-09-01" seq="1999-0115" severity="High" type="CVE"><desc><descript source="cve">AIX bugfiler program allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/500.php">ibm-bugfiler(500)</ref><ref adv="1" source="CA" url="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=13">AIX bugfiler file creation vulnerability</ref><ref source="insecure" url="http://www.insecure.org/sploits/aix.bugfiler.html">AIX bugfiler</ref><ref source="BID" url="http://www.securityfocus.com/bid/1800">1800</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.1"/><vers num="3.2"/><vers num="3.2.4"/><vers num="3.2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0116" published="1996-09-19" seq="1999-0116" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.21.tcp_syn_flooding.html">CA-96.21.tcp_syn.flooding</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2.5"/></prod><prod name="SNG" vendor="IBM"><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0117" published="1992-03-31" seq="1999-0117" severity="High" type="CVE"><desc><descript source="cve">AIX passwd allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-92.07.AIX.passwd.vulnerability.html">CA-92.07.AIX.passwd.vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/555.php">ibm-passwd(555)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0118" published="1998-11-01" seq="1999-0118" severity="High" type="CVE"><desc><descript source="cve">AIX infod allows local users to gain root access through an X display.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1407.php">aix-infod(1407)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91158980826979&amp;w=2">19981119 RSI.0011.11-09-98.AIX.INFOD</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/><vers num="4.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0119" published="1999-01-19" seq="1999-0119" severity="High" type="CVE"><desc><descript source="cve">Windows NT 4.0 beta allows users to read and delete shares.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 beta"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0120" published="1994-03-21" seq="1999-0120" severity="High" type="CVE"><desc><descript source="cve">Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.06.utmp.vulnerability.html">CA-94.06.umtp.vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/506.php">utmp-write(506)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="1.1.1a"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0121" published="1999-01-21" seq="1999-0121" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in dtaction command gives root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0122" published="1997-07-21" seq="1999-0122" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in AIX lchangelv gives root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/389">bugtraq id 389</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/845.php">lchangelv-bo(845)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1.5"/><vers num="4.1.4"/><vers num="4.1.3"/><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0123" published="1995-12-01" seq="1999-0123" severity="Low" type="CVE"><desc><descript source="cve">Race condition in Linux mailx command allows local users to read user files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs/><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0124" published="1993-08-09" seq="1999-0124" severity="High" type="CVE"><desc><descript source="cve">Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/544.php">gopher-vuln(544)</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-93.11.UMN.UNIX.gopher.vulnerability.html">CA-93.11.UMN.UNIX.gopher.vulnerability</ref></refs><vuln_soft><prod name="gopherd" vendor="University of Minnesota"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0125" published="1998-01-25" seq="1999-0125" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in SGI IRIX mailx program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/393">BID 393</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1371.php">sgi-mailx-bo(1371)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX">19980605-01-PX</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="4.2"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers edition="HW3" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/></prod><prod name="IRIX" vendor="SGI"><vers num="6.3"/><vers num="5.3"/><vers num="5.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0126" published="1998-05-03" seq="1999-0126" severity="High" type="CVE"><desc><descript source="cve">SGI IRIX buffer overflow in xterm and Xaw allows root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/vul_notes/VN-98.01.XFree86.html">VN-98.01.XFree86</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/963.php">xfree86-xterm-xaw(963)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2096.php">xfree86-xaw(2096)</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-010.shtml">J-010</ref></refs><vuln_soft><prod name="XFree86" vendor="XFree86 Project"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0127" published="1996-12-19" seq="1999-0127" severity="High" type="CVE"><desc><descript source="cve">swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://www.cert.org/advisories/CA-96.27.hp_sw_install.html">Vulnerability in HP Software Installation Programs</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0128" published="1996-12-18" seq="1999-0128" severity="Medium" type="CVE"><desc><descript source="cve">Oversized ICMP ping packets can result in a denial of service, aka Ping o&apos; Death.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.26.ping.html">CA-96.26.ping</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/95.php">ping-death(95)</ref></refs><vuln_soft><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/><vers num="1.1"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/><vers num="5.0.2"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.5.1"/><vers edition="x86" num="5.5.1"/><vers num="5.5"/><vers edition="x86" num="5.5"/><vers num="5.4"/><vers edition="x86" num="5.4"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3.0"/></prod><prod name="OSF_1" vendor="Digital"><vers num="1.3.3"/></prod><prod name="SNG" vendor="IBM"><vers num="2.2"/><vers num="2.1"/><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num="1.3"/><vers num="2.0"/></prod><prod name="TCP/IP" vendor="SCO"><vers num="1.2.1"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0129" published="1996-12-03" seq="1999-0129" severity="Medium" type="CVE"><desc><descript source="cve">Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.25.sendmail_groups.html">CA-96.25.sendmail_groups</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/715">BID 715</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="10.16"/><vers num="10.10"/><vers num="10.1"/><vers num="10.0"/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="1.1"/><vers num="1.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="Sendmail" vendor="Eric Allman"><vers num="8.8.3"/><vers num="8.8.2"/><vers num="8.8.1"/><vers num="8.8"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.6.1"/><vers num="2.1.6"/><vers num="2.1.5"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.2"/><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0130" published="1996-11-16" seq="1999-0130" severity="High" type="CVE"><desc><descript source="cve">Local users can start Sendmail in daemon mode and gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.24.sendmail.daemon.mode.html">CA-96.24.sendmail.daemon.mode</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/716">BID 716</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1837.php">sendmail-daemon-mode(1837)</ref><ref source="BID" url="http://www.securityfocus.com/bid/716">716</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.6"/><vers num="2.1.5"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/></prod><prod name="Network Desktop" vendor="Caldera"><vers num="1.0"/></prod><prod name="Linux" vendor="Red Hat"><vers num="4.0"/></prod><prod name="Sendmail" vendor="Eric Allman"><vers num="8.8.2"/><vers num="8.8.1"/><vers num="8.8"/><vers num="8.7"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="10.10"/><vers num="10.0.1"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0131" published="1996-09-11" seq="1999-0131" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.20.sendmail_vul.html">CA-96.20.sendmal_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/428.php">smtp-875bo(428)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/717">BID 717</ref><ref source="BID" url="http://www.securityfocus.com/bid/717">717</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="10.10"/><vers num="10.0.1"/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/></prod><prod name="OSF_1" vendor="Digital"><vers num="1.3.2"/></prod><prod name="Sendmail" vendor="Eric Allman"><vers num="8.7.5"/><vers num="8.7.4"/><vers num="8.7.3"/><vers num="8.7.2"/><vers num="8.7.1"/><vers num="8.6"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.5"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.2"/><vers num="5.0"/></prod><prod name="AIX" vendor="IBM"><vers num="4.2"/><vers num="4.1"/><vers num="3.2"/></prod><prod name="Linux" vendor="Red Hat"><vers num="3.0.3"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0132" published="1996-08-15" seq="1999-0132" severity="Low" type="CVE"><desc><descript source="cve">Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.19.expreserve.html">CA-96.19.expreserve</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/401.php">expreserve(401)</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</ref><ref source="OSVDB" url="http://www.osvdb.org/11723">11723</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/401">expreserve(401)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/><vers edition="x86" num="2.4"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.3c"/><vers num="4.1.3u1"/></prod><prod name="HP-UX" vendor="HP"><vers num="9"/><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0133" published="1996-08-14" seq="1999-0133" severity="Low" type="CVE"><desc><descript source="cve">fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.18.fm_fls.html">CA-96.18.fm_fls</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/403.php">fmaker-logfile(403)</ref></refs><vuln_soft><prod name="FrameMaker" vendor="Adobe"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0134" published="1996-08-06" seq="1999-0134" severity="High" type="CVE"><desc><descript source="cve">vold in Solaris 2.x allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.17.Solaris_vold_vul.html">CA-96.17.Solaris_vold_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/434.php">sol-voldtmp(434)</ref><ref source="OSVDB" url="http://www.osvdb.org/8159">8159</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="5.5.1"/><vers edition="x86" num="5.5.1"/><vers num="5.5"/><vers edition="x86" num="5.5"/><vers num="5.4"/><vers edition="x86" num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0135" published="1996-07-25" seq="1999-0135" severity="High" type="CVE"><desc><descript source="cve">admintool in Solaris allows a local user to write to arbitrary files and gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.16.Solaris_admintool_vul.html">CA-96.16.Solaris_admintool_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/394.php">sun-admintool(394)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/289">bugtraq id 289</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0136" published="1996-07-31" seq="1999-0136" severity="High" type="CVE"><desc><descript source="cve">Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.15.Solaris_KCMS_vul.html">CA-96.15.Solaris_KCMS_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/482.php">sol-KCMSvuln(482)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5"/><vers num="2.5.1"/></prod><prod name="SunOS" vendor="Sun"><vers num="5.5.1"/><vers edition="x86" num="5.5.1"/><vers num="5.5"/><vers edition="x86" num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0137" published="1996-07-09" seq="1999-0137" severity="High" type="CVE"><desc><descript source="cve">The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.13.dip_vul.html">CA-96.13.dip_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/398.php">linux-dipbo(398)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/86">BID 86</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/881.php">dip-bo(881)</ref></refs><vuln_soft><prod name="dip" vendor="Fred N. van Kempen"><vers num="3.3.7o"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-07" name="CVE-1999-0138" published="1996-06-26" seq="1999-0138" severity="High" type="CVE"><desc><descript source="cve">The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.12.suidperl_vul.html">CA-96.12.suidperl_vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/429.php">sperl-suid(429)</ref></refs><vuln_soft><prod name="A_UX" vendor="Apple"><vers num="3.1.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="1.2"/><vers num="2.0"/></prod><prod name="OSF_1" vendor="Digital"><vers num="1.3"/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num="4.2MP"/><vers num="4.2"/></prod><prod name="UX_4800" vendor="NEC"><vers num=""/></prod><prod name="UP-UX_V" vendor="NEC"><vers num="4.2MP"/></prod><prod name="HP-UX" vendor="HP"><vers num="8"/><vers num="9"/><vers num="10"/></prod><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.0"/><vers num="2.0.5"/><vers num="2.1.0"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0139" published="1998-12-12" seq="1999-0139" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1429.php">sol-mkcookie(1429)</ref><ref source="OSVDB" url="http://www.osvdb.org/8205">8205</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.6"/><vers edition="x86" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0140" published="1999-06-30" seq="1999-0140" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in RAS/PPTP on NT systems.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0141" published="1996-03-29" seq="1999-0141" severity="Low" type="CVE"><desc><descript source="cve">Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/><user_init/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.07.java_bytecode_verifier.html">CA-96.07.java_bytecode_verifier</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/490.php">http-java-applet(490)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</ref></refs><vuln_soft><prod name="Navigator" vendor="Netscape"><vers num="2.02"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0142" published="1996-03-01" seq="1999-0142" severity="High" type="CVE"><desc><descript source="cve">The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer&apos;s Kit 1.0 allows an applet to connect to arbitrary hosts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/492.php">http-java-appletsecmgr(492)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.05.java_applet_security_mgr.html">CA-96.05.java_applet_security_mgr</ref></refs><vuln_soft><prod name="Navigator" vendor="Netscape"><vers num=""/></prod><prod name="Java" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0143" published="1996-02-21" seq="1999-0143" severity="Medium" type="CVE"><desc><descript source="cve">Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.03.kerberos_4_key_server.html">CA-96.03.kerberos_4_key_server</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/64.php">kerberos-bf(64)</ref></refs><vuln_soft><prod name="Kerberos 5" vendor="MIT"><vers num="5.0"/></prod><prod name="Kerberos 4" vendor="MIT"><vers num="4.0"/></prod><prod name="MultiNet" vendor="Process Software"><vers num="3.4"/><vers num="3.5"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0144" published="1997-06-01" seq="1999-0144" severity="Low" type="CVE"><desc><descript source="cve">Denial of service in Qmail by specifying a large number of recipients with the RCPT command.</descript></desc><loss_types><avail/></loss_types><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/208.php">qmail-rcpt</ref><ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref><ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref><ref source="BID" url="http://www.securityfocus.com/bid/2237">2237</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319029&amp;w=2">19970612 Re: Denial of service (qmail-smtpd)</ref></refs></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0145" published="1993-09-30" seq="1999-0145" severity="High" type="CVE"><desc><descript source="cve">Sendmail WIZ command enabled, allowing root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-93.14.Internet.Security.Scanner.html">Internet Security Scanner (ISS)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/131.php">smtp-wiz(131)</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</ref><ref source="CERT" url="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</ref><ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</ref><ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0146" published="1997-07-15" seq="1999-0146" severity="High" type="CVE"><desc><descript source="cve">The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/298.php">http-cgi-campas(298)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1975">1975</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/298">http-cgi-campas(298)</ref></refs><vuln_soft><prod name="Servers" vendor="NCSA"><vers num=""/></prod><prod name="Campas" vendor="NCSA"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0147" published="1997-07-01" seq="1999-0147" severity="High" type="CVE"><desc><descript source="cve">The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/297.php">http-cgi-glimpse(297)</ref></refs><vuln_soft><prod name="Glimpse HTTP" vendor="University of Arizona"><vers num="2.0"/></prod><prod name="WebGlimpse" vendor="University of Arizona"><vers num="1.5" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0148" published="1997-09-01" seq="1999-0148" severity="High" type="CVE"><desc><descript source="cve">The handler CGI program in IRIX allows arbitrary command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/380">bugtraq id 380</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/340.php">http-sgi-handler(340)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/380">380</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0149" published="1997-04-19" seq="1999-0149" severity="High" type="CVE"><desc><descript source="cve">The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/373">bugtraq id 373</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/290.php">http-sgi-wrap(290)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref><ref source="BID" url="http://www.securityfocus.com/bid/373">373</ref><ref source="OSVDB" url="http://www.osvdb.org/247">247</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/290">http-sgi-wrap(290)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0150" published="1997-07-01" seq="1999-0150" severity="High" type="CVE"><desc><descript source="cve">The Perl fingerd program allows arbitrary command execution from remote users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/625.php">perl-fingerd(625)</ref></refs><vuln_soft><prod name="fingerd" vendor="GNU"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="10.0" CVSS_score="7.6" CVSS_vector="(AV:N/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0151" published="1995-04-03" seq="1999-0151" severity="High" type="CVE"><desc><descript source="cve">The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.07a.REVISED.satan.vul.html">CA-95.07a.REVISED.satan.vul</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.06.satan.html">CA-95.06.satan.vul</ref></refs><vuln_soft><prod name="SATAN" vendor="SATAN"><vers num="1.0"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0152" published="1997-08-11" seq="1999-0152" severity="High" type="CVE"><desc><descript source="cve">The DG/UX finger daemon allows remote command execution through shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/302.php">dgux-fingerd(302)</ref></refs><vuln_soft><prod name="DG_UX" vendor="Data General"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0153" published="1997-07-01" seq="1999-0153" severity="Medium" type="CVE"><desc><descript source="cve">Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/173.php">win-oob(173)</ref><ref source="OSVDB" url="http://www.osvdb.org/1666">1666</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0154" published="1999-12-31" seq="1999-0154" severity="Medium" type="CVE"><desc><descript source="cve">IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/336.php">http-iis-aspdot(336)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0155" published="1995-08-31" seq="1999-0155" severity="High" type="CVE"><desc><descript source="cve">The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/404.php">gscript-dsafer(404)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.10.ghostscript.html">CA-95.10.ghostscript</ref></refs><vuln_soft><prod name="Ghostscript" vendor="Aladdin Enterprises"><vers num="3.22"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0156" published="1997-07-01" seq="1999-0156" severity="Medium" type="CVE"><desc><descript source="cve">wu-ftpd FTP daemon allows any user and password combination.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/204.php">ftp-pwless(204)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0157" published="1998-08-18" seq="1999-0157" severity="Medium" type="CVE"><desc><descript source="cve">Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/nifrag.shtml">Cisco PIX and CBAC Fragmentation Attack</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/690">BID 690</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1584.php">cisco-fragmented-attacks(1584)</ref><ref source="OSVDB" url="http://www.osvdb.org/1097">1097</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0T"/><vers num="12.0"/><vers num="11.3T"/><vers num="11.2P"/></prod><prod name="PIX Firewall" vendor="Cisco"><vers num="4.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0158" published="1998-08-31" seq="1999-0158" severity="Medium" type="CVE"><desc><descript source="cve">Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1583.php">cisco-pix-file-exposure(1583)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/691">BID 691</ref><ref source="OSVDB" url="http://www.osvdb.org/685">685</ref></refs><vuln_soft><prod name="PIX Firewall" vendor="Cisco"><vers num="4.2.1"/><vers num="4.1.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0159" published="1998-08-12" seq="1999-0159" severity="Medium" type="CVE"><desc><descript source="cve">Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/ioslogin-pub.shtml">Cisco IOS Remote Router Crash</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1238.php">cisco-ios-crash(1238)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/692">BID 692</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="9.1"/><vers num="11.3.1T"/><vers num="11.3.1ED"/><vers num="11.3.1"/><vers num="11.2.9XA"/><vers num="11.2.9P"/><vers num="11.2.8SA3"/><vers num="11.2.10BC"/><vers num="11.2.10"/><vers num="11.1.17CT"/><vers num="11.1.17CC"/><vers num="11.1.16IA"/><vers num="11.1.16AA"/><vers num="11.1.16"/><vers num="11.1.15CA"/><vers num="11.0.20.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0160" published="1997-10-01" seq="1999-0160" severity="High" type="CVE"><desc><descript source="cve">Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/chapvuln-pub.shtml"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/570.php">cisco-CHAP(570)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/693">bugtraq id 693</ref><ref source="OSVDB" url="http://www.osvdb.org/1099">1099</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="9.1"/><vers num="11.2P"/><vers num="11.2"/><vers num="11.1"/><vers num="11.0"/><vers num="10.3"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0161" published="1995-07-31" seq="1999-0161" severity="High" type="CVE"><desc><descript source="cve">In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/1.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1247.php">cisco-acl-tacacs(1247)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/703">bugtraq id 703</ref><ref source="OSVDB" url="http://www.osvdb.org/797">797</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="10.3.4.2"/><vers num="10.3.3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0162" published="1998-09-01" seq="1999-0162" severity="Medium" type="CVE"><desc><descript source="cve">The &quot;established&quot; keyword in some Cisco IOS software allowed an attacker to bypass filtering.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/2.html"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1248.php">cisco-acl-established(1248)</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/315">bugtraq id 315</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="11.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0163" published="1997-01-01" seq="1999-0163" severity="High" type="CVE"><desc><descript source="cve">In older versions of Sendmail, an attacker could use a pipe character to execute root commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/616.php">smtp-pipe</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0164" published="1995-08-29" seq="1999-0164" severity="Medium" type="CVE"><desc><descript source="cve">A race condition in the Solaris ps command allows an attacker to overwrite critical files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.09.Solaris.ps.vul.html">CA-95.09.Solaris.ps.vul</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/420.php">sol-pstmprace(420)</ref><ref source="OSVDB" url="http://www.osvdb.org/8346">8346</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="5.3"/><vers num="5.4"/><vers edition="x86" num="5.4"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0165" published="1997-03-01" seq="1999-0165" severity="High" type="CVE"><desc><descript source="cve">NFS cache poisoning.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/73.php">nfs-cache(73)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="3.5"/><vers num="4.0"/><vers num="4.0.1"/><vers num="4.0.2"/><vers num="4.0.3"/><vers num="4.1"/><vers num="4.1.1"/><vers num="4.1.2"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="1.1"/><vers num="1.1.1a"/><vers num="1.1.2"/><vers num="1.2"/><vers num="2.0"/><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/><vers num="2.4"/><vers edition="x86" num="2.4"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod><prod name="NFS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0166" published="1997-01-01" seq="1999-0166" severity="Medium" type="CVE"><desc><descript source="cve">NFS allows users to use a &quot;cd ..&quot; command to access other directories besides the exported file system.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/75.php">nfs-cd(75)</ref></refs><vuln_soft><prod name="NFS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0167" published="1991-12-06" seq="1999-0167" severity="Medium" type="CVE"><desc><descript source="cve">In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-91.21.SunOS.NFS.Jumbo.and.fsirand.html">CA-91.21.SunOS.NFS.Jumbo.and.fsirand</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/77.php">nfs-guess(77)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/32">bugtraq id 32</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0168" published="1992-06-04" seq="1999-0168" severity="High" type="CVE"><desc><descript source="cve">The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/46">bugtraq id 46</ref><ref adv="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/673.php">decod-portmap-call (673)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://www.iss.net/security_center/static/80.php">nfs-portmap (80)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.3c"/><vers num="4.1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0169" published="1997-07-01" seq="1999-0169" severity="High" type="CVE"><desc><descript source="cve">NFS allows attackers to read and write any file on the system by specifying a false UID.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/82.php">nfs-uid</ref></refs><vuln_soft><prod name="NFS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0170" published="1997-01-01" seq="1999-0170" severity="High" type="CVE"><desc><descript source="cve">Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/83.php">nfs-ultrix(83)</ref></refs><vuln_soft><prod name="Ultrix" vendor="Digital"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0171" published="1997-01-01" seq="1999-0171" severity="Low" type="CVE"><desc><descript source="cve">Denial of service in syslog by sending it a large number of superfluous messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/136.php">syslog-flood</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0172" published="1995-08-02" seq="1999-0172" severity="High" type="CVE"><desc><descript source="cve">FormMail CGI program allows remote execution of commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/299.php">http-cgi-formmail-exe(299)</ref></refs><vuln_soft><prod name="FormMail" vendor="Matt Wright"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0173" published="1997-01-01" seq="1999-0173" severity="Medium" type="CVE"><desc><descript source="cve">FormMail CGI program can be used by web servers other than the host server that the program resides on.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/300.php">http-cgi-formmail-use(300)</ref></refs><vuln_soft><prod name="FormMail" vendor="Matt Wright"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0174" published="1997-02-01" seq="1999-0174" severity="Medium" type="CVE"><desc><descript source="cve">The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/303">bugtraq id 303</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/291.php">http-cgi-viewsrc(291)</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.6"/><vers num="4.51"/><vers num="4.5"/><vers num="4.0"/><vers num="4.07"/><vers num="4.06"/><vers num="4.05"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0175" published="1996-07-01" seq="1999-0175" severity="Medium" type="CVE"><desc><descript source="cve">The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</descript></desc><loss_types><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/339.php">http-nov-convert(339)</ref></refs><vuln_soft><prod name="Novell Web Server" vendor="Novell"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0176" published="1997-07-10" seq="1999-0176" severity="High" type="CVE"><desc><descript source="cve">The Webgais program allows a remote user to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1467.php">http-webgais-query(1467)</ref></refs><vuln_soft><prod name="WebGAIS" vendor="WebGAIS Development Team"><vers num="1.0B2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0177" published="1997-09-01" seq="1999-0177" severity="High" type="CVE"><desc><descript source="cve">The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/294.php">http-website-uploader(294)</ref></refs><vuln_soft><prod name="Website" vendor="OReilly"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0178" published="1997-01-01" seq="1999-0178" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/295.php">http-website-winsample(295)</ref><ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</ref><ref source="BID" url="http://www.securityfocus.com/bid/2078">2078</ref><ref source="OSVDB" url="http://www.osvdb.org/8">8</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/295">http-website-winsample(295)</ref></refs><vuln_soft><prod name="OReilly Website" vendor="OReilly"><vers num="1.1e"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0179" published="1997-01-01" seq="1999-0179" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT crashes or locks up when a Samba client executes a &quot;cd ..&quot; command on a file share.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/397.php">nt-samba-dotdot(397)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q140818">Q140818</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="3.5"/><vers num="3.5.1"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0180" published="1997-01-01" seq="1999-0180" severity="High" type="CVE"><desc><descript source="cve">in.rshd allows users to login with a NULL username and execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/112.php">rsh-null(112)</ref></refs></entry><entry CVSS_base_score="6.8" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="6.4" CVSS_score="6.8" CVSS_vector="(AV:N/AC:M/Au:N/C:P/I:P/A:P)" CVSS_version="2.0" modified="2007-07-16" name="CVE-1999-0181" published="1994-01-01" seq="1999-0181" severity="Medium" type="CVE"><desc><descript source="cve">The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/150.php">walld(150)</ref></refs><vuln_soft><prod name="rpc.walld" vendor="rpc.walld"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0182" published="1997-09-30" seq="1999-0182" severity="High" type="CVE"><desc><descript source="cve">Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/337.php">nt-samba-bo(337)</ref><ref adv="1" patch="1" source="CERT" url="ftp://ftp.cert.org/pub/cert_bulletins/VB-97.10.samba">VB-97.10.samba</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-110.shtml">H-110</ref></refs><vuln_soft><prod name="Samba" vendor="Samba"><vers num="1.9.17 p2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0183" published="1997-09-01" seq="1999-0183" severity="Medium" type="CVE"><desc><descript source="cve">Linux implementations of TFTP would allow access to files outside the restricted directory.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/308.php">linux-tftp(308)</ref></refs><vuln_soft><prod name="TFTP" vendor="TFTP"><vers num=""/></prod><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0184" published="1997-07-01" seq="1999-0184" severity="Medium" type="CVE"><desc><descript source="cve">When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</descript></desc><loss_types><avail/><int/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/196.php">dns-updates(196)</ref><ref adv="1" source="ISC" url="http://www.isc.org/products/BIND/bind-security-19991108.html">nxt bug</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-14-bind.html">CA-99-14-bind.html</ref></refs><vuln_soft><prod name="BIND" vendor="ISC"><vers num="9.4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0185" published="1997-10-01" seq="1999-0185" severity="High" type="CVE"><desc><descript source="cve">In SunOS or Solaris, a remote user could connect from an FTP server&apos;s data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/607.php">sun-ftpd/logind(607)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156">00156</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.4"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0186" published="1998-10-01" seq="1999-0186" severity="High" type="CVE"><desc><descript source="cve">In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1336.php">snmp-backdoor-access</ref><ref source="" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm"></ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/></prod></vuln_soft></entry><entry modified="2005-10-20" name="CVE-1999-0187" published="1999-01-01" reject="1" seq="1999-0187" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0022.  Reason: This candidate is a duplicate of CVE-1999-0022.  Notes: All CVE users should reference CVE-1999-0022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0188" published="1998-12-17" seq="1999-0188" severity="High" type="CVE"><desc><descript source="cve">The passwd command in Solaris can be subjected to a denial of service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/174">bugtraq id 174</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1442.php">sun-passwd-dos(1442)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182">00182</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0189" published="1997-06-04" seq="1999-0189" severity="High" type="CVE"><desc><descript source="cve">Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Sun Sunsolve" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142&amp;type=0&amp;nav=sec.sba">#00142</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/330.php">rpc-32771(330)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142">00142</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0190" published="1998-04-08" seq="1999-0190" severity="High" type="CVE"><desc><descript source="cve">Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/67">bugtraq id 67</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/894.php">sun-rpcbind</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167">00167</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0191" published="1997-09-01" seq="1999-0191" severity="Medium" type="CVE"><desc><descript source="cve">IIS newdsn.exe CGI script allows remote users to overwrite files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1530.php">http-cgi-newdsn(1530)</ref><ref source="OSVDB" url="http://www.osvdb.org/275">275</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0192" published="1997-10-18" seq="1999-0192" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/588">BID 588</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/610.php">bsd-tel-tgetent(610)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="6.0"/><vers edition="i386" num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="4.0"/><vers num="3.9"/><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0193" published="1997-12-01" seq="1999-0193" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="ISS X-Force" url="http://xforce.iss.net/static/614.php">ascend-kill</ref></refs><vuln_soft><prod name="CascadeView_UX" vendor="Ascend"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0194" published="1999-05-01" seq="1999-0194" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in in.comsat allows attackers to generate messages.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1884.php">comsat(1884)</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0195" published="1997-07-01" seq="1999-0195" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2308.php">pmap-sset(2308)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0196" published="1997-07-08" seq="1999-0196" severity="Medium" type="CVE"><desc><descript source="cve">websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/296.php">http-webgais-smail(296)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2077">2077</ref><ref source="OSVDB" url="http://www.osvdb.org/237">237</ref></refs><vuln_soft><prod name="WebGAIS" vendor="WebGAIS Development Team"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0197" published="1999-01-01" seq="1999-0197" severity="High" type="CVE"><desc><descript source="cve">finger 0@host on some systems may print information on some user accounts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0198" published="1999-01-01" seq="1999-0198" severity="High" type="CVE"><desc><descript source="cve">finger .@host on some systems may print information on some user accounts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0200" published="1999-01-01" seq="1999-0200" severity="High" type="CVE"><desc><descript source="cve">Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0201" published="1997-01-01" seq="1999-0201" severity="Medium" type="CVE"><desc><descript source="cve">A quote cwd command on FTP servers can reveal the full path of the home directory of the &quot;ftp&quot; user.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/203.php">ftp-home(203)</ref></refs><vuln_soft><prod name="FTP" vendor="FTP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0202" published="1997-01-01" seq="1999-0202" severity="High" type="CVE"><desc><descript source="cve">The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/619.php">ftp-exectar(619)</ref></refs><vuln_soft><prod name="wu-ftpd" vendor="Washington University"><vers num="2.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0203" published="1995-08-17" seq="1999-0203" severity="High" type="CVE"><desc><descript source="cve">In Sendmail, attackers can gain root privileges via SMTP by specifying an improper &quot;mail from&quot; address and an invalid &quot;rcpt to&quot; address that would cause the mail to bounce to a program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.08.sendmail.v.5.vulnerability.html">CA-95.08.sendmail.v.5.vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/518.php">smtp-sendmail-version5(518)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.6.10"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0204" published="1997-01-01" seq="1999-0204" severity="High" type="CVE"><desc><descript source="cve">Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/627.php">ident-bo(627)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.6.9"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0205" published="1999-01-01" seq="1999-0205" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Sendmail 8.6.11 and 8.6.12.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/SM%208.6.12">19990708 SM 8.6.12</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.6.12"/><vers num="8.6.11"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0206" published="1996-10-01" seq="1999-0206" severity="High" type="CVE"><desc><descript source="cve">MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1836.php">sendmail-mime-bo(1836)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.8"/><vers num="8.8.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0207" published="1994-06-09" seq="1999-0207" severity="High" type="CVE"><desc><descript source="cve">Remote attacker can execute commands through Majordomo using the Reply-To field and a &quot;lists&quot; command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.11.majordomo.vulnerabilities.html">CERT:CA-94.11.majordomo.vulnerabilities</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/510.php">majordomo-exe(510)</ref></refs><vuln_soft><prod name="Majordomo" vendor="Great Circle Associates"><vers num="1.90"/><vers num="1.91"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-16" name="CVE-1999-0208" published="1995-12-12" seq="1999-0208" severity="High" type="CVE"><desc><descript source="cve">rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.17.rpc.ypupdated.vul.html">CA-95.17.rpc.ypupodated.vul</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/110.php">rpc-update(110)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4.1"/><vers num="3.2"/></prod><prod name="EWS-UX_V" vendor="NEC"><vers num=""/></prod><prod name="UP-UX_V" vendor="NEC"><vers num=""/></prod><prod name="IRIX" vendor="SGI"><vers num="3"/><vers num="4"/><vers num="5.0"/><vers num="5.1"/><vers num="5.2"/></prod><prod name="UX_4800" vendor="NEC"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0209" published="1990-08-14" seq="1999-0209" severity="Medium" type="CVE"><desc><descript source="cve">The SunView (SunTools) selection_svc facility allows remote users to read files.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-90.05.sunselection.vulnerability.html">CA-90.05.sunselection.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/122.php">selsvc(122)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/8">bugtraq id 8</ref><ref source="BID" url="http://www.securityfocus.com/bid/8">8</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/><vers num="4.1"/><vers num="4.0.3"/><vers num="4.0.2"/><vers num="4.0.1"/><vers num="4.0"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0210" published="1997-11-26" seq="1999-0210" severity="High" type="CVE"><desc><descript source="cve">Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/235">bugtraq id 235</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05-statd-automountd</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88053459921223&amp;w=2">19971126 Solaris 2.5.1 automountd exploit (fwd)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104">HPSBUX9910-104</ref><ref source="BID" url="http://www.securityfocus.com/bid/235">235</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0211" published="1994-02-14" seq="1999-0211" severity="Medium" type="CVE"><desc><descript source="cve">Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability.html">CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/24">24</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.3c"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0212" published="1998-04-29" seq="1999-0212" severity="High" type="CVE"><desc><descript source="cve">Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Sun Sunsolve" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/168&amp;type=0&amp;nav=sec.sba">#00168</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/967.php">sun-mountd(967)</ref><ref patch="1" source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-048.shtml">I-048</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod><prod name="SunOS" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0213" published="1998-07-15" seq="1999-0213" severity="High" type="CVE"><desc><descript source="cve">libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-2_num-8.phpSun-libnsl">sun-libnsl</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0214" published="1992-07-21" seq="1999-0214" severity="High" type="CVE"><desc><descript source="cve">Denial of service by sending forged ICMP unreachable packets.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/50">bugtraq id 50</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1883.php">icmp-unreachable(1883)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0215" published="1998-10-26" seq="1999-0215" severity="Medium" type="CVE"><desc><descript source="cve">Routed allows attackers to append data to files.</descript></desc><loss_types><conf/><int/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/320.php">ripapp(320)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX">19981004-01-PX</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-012.shtml">J-012</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="3"/><vers num="4"/><vers num="5"/><vers num="6.0.1"/><vers num="6.1"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0216" published="1997-11-01" seq="1999-0216" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service of inetd on Linux through SYN and RST packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2013.php">linux-inutid-dos</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-2_num-4.phpHP-inetd">hp-inetd</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num="10"/></prod><prod name="inet" vendor="GNU"><vers num="5.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0217" published="1997-01-01" seq="1999-0217" severity="Medium" type="CVE"><desc><descript source="cve">Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/143.php">udp-bomb(143)</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.0.3"/><vers num="4.0.3c"/><vers num="4.1"/><vers num="4.1PSR_A"/><vers num="4.1.1"/><vers num="4.1.2"/><vers num="4.1.3"/><vers num="4.1.3a1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0218" published="1995-10-01" seq="1999-0218" severity="Medium" type="CVE"><desc><descript source="cve">Livingston portmaster machines could be rebooted via a series of commands.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1885.php">portmaster-reboot(1885)</ref></refs><vuln_soft><prod name="Portmaster" vendor="Livingston Portmaster"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0219" published="1997-07-01" seq="1999-0219" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/269">bugtraq id 269</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/205.php">ftp-servu</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2">19990503 Buffer overflows in FTP Serv-U 2.5</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref><ref source="BID" url="http://www.securityfocus.com/bid/269">269</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/205">ftp-servu(205)</ref></refs><vuln_soft><prod name="Serv-U" vendor="Cat Soft"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0220" published="1999-01-01" seq="1999-0220" severity="High" type="CVE"><desc><descript source="cve">Attackers can do a denial of service of IRC by crashing the server.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0221" published="1999-03-01" seq="1999-0221" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service of Ascend routers through port 150 (remote administration).</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1881.php">ascend-150-kill(1881)</ref></refs><vuln_soft><prod name="Ascend Routers" vendor="Lucent"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0222" published="1999-03-01" seq="1999-0222" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1886.php">cisco-web-crash</ref></refs><vuln_soft><prod name="Cisco router" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0223" published="1999-03-01" seq="1999-0223" severity="Low" type="CVE"><desc><descript source="cve">Solaris syslogd crashes when receiving a message from a host that doesn&apos;t have an inverse DNS entry.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1887.php">sol-syslogd-crash(1887)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/bid/Syslogd%20and%20Solaris%202.4">Syslogd and Solaris 2.4</ref><ref source="" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches"></ref><ref source="BID" url="http://www.securityfocus.com/bid/1878">1878</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0224" published="1999-07-23" seq="1999-0224" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Windows NT messenger service through a long username.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/465">bugtraq id 465</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0225" published="1998-02-14" seq="1999-0225" severity="Medium" type="CVE"><desc><descript source="cve">Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/342.php">nt-logondos(342)</ref><ref adv="1" patch="1" source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp"></ref><ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=180963">Q180963</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0226" published="1999-01-01" seq="1999-0226" severity="High" type="CVE"><desc><descript source="cve">Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0227" published="1997-06-01" seq="1999-0227" severity="Medium" type="CVE"><desc><descript source="cve">Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1892.php">nt-lsass-crash(1892)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154087">Q154087</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0228" published="1997-02-07" seq="1999-0228" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/688">bugtraq id 688</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/17.php">nt-rpc-ver(17)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q162567">Q162567</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0229" published="1999-05-12" seq="1999-0229" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Windows NT IIS server using ..\..</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-10.php">http-alibaba-dotdot</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0230" published="1997-12-15" seq="1999-0230" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Cisco 7xx routers through the telnet service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/pwbuf-pub.shtml">7xx Router Password Buffer Overflow</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/704">bugtraq id 704</ref><ref source="OSVDB" url="http://www.osvdb.org/1102">1102</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="4.1.2"/><vers num="4.1.1"/><vers num="4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0231" published="1999-01-01" seq="1999-0231" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="SLMail" vendor="Seattle Lab Software"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0232" published="1995-02-01" seq="1999-0232" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/517.php">http-ncsa-longurl</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0233" published="1996-02-25" seq="1999-0233" severity="High" type="CVE"><desc><descript source="cve">IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/63.php">http-iis-cmd(63)</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q148/1/88.asp"></ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q148188">Q148188</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q155056">Q155056</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0234" published="1996-10-08" seq="1999-0234" severity="Medium" type="CVE"><desc><descript source="cve">Bash treats any character with a value of 255 as a command separator.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.22.bash_vuls.html">CA-96.22.bash_vuls</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="4.2"/></prod><prod name="Linux" vendor="Red Hat"><vers num="3.0.3"/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod><prod name="Linux" vendor="Yggdrasil"><vers num=""/></prod><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0235" published="1995-02-17" seq="1999-0235" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1995-04.html">CERT:CA-95:04</ref></refs><vuln_soft><prod name="NCSA Web Server" vendor="NCSA"><vers num="1.3"/><vers num="1.4"/><vers num="1.4.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2007-02-08" name="CVE-1999-0236" published="1997-01-01" seq="1999-0236" severity="High" type="CVE"><desc><descript source="cve">ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/332.php">http-scriptalias(332)</ref></refs><vuln_soft><prod name="Servers" vendor="NCSA"><vers num=""/></prod><prod name="Apache HTTP Server" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0237" published="1997-09-01" seq="1999-0237" severity="High" type="CVE"><desc><descript source="cve">Remote execution of arbitrary commands through Guestbook CGI program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/321.php">http-cgi-guestbook(321)</ref><ref adv="1" patch="1" source="CERT" url="ftp://info.cert.org/pub/cert_bulletins/VB-97.02.sol_guestbook">VB-97.02.sol_questday</ref></refs><vuln_soft><prod name="CGI Guestbook" vendor="Webcom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0238" published="1997-08-01" seq="1999-0238" severity="High" type="CVE"><desc><descript source="cve">php.cgi allows attackers to read any file on the system.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/292.php">http-cgi-phpfileread</ref></refs><vuln_soft><prod name="PHP_FI" vendor="PHP"><vers num="1.0"/><vers num="2.0"/><vers num="2.0b10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0239" published="1998-01-01" seq="1999-0239" severity="Medium" type="CVE"><desc><descript source="cve">Netscape FastTrack Web server lists files when a lowercase &quot;get&quot; command is used instead of an uppercase GET.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/481">bugtraq id 481</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1731.php">fastrack-get-directory-list(1731)</ref><ref source="OSVDB" url="http://www.osvdb.org/122">122</ref></refs><vuln_soft><prod name="FastTrack" vendor="Netscape"><vers num="3.01"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0240" published="1999-01-01" seq="1999-0240" severity="High" type="CVE"><desc><descript source="cve">Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0241" published="1995-11-01" seq="1999-0241" severity="High" type="CVE"><desc><descript source="cve">Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/334.php">http-xguess-cookie</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1429.php">sol-mkcookie(1429)</ref></refs><vuln_soft><prod name="X11R6" vendor="XFree86 Project"><vers num=""/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.6"/><vers edition="x86" num="7.0"/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0242" published="1995-03-01" seq="1999-0242" severity="High" type="CVE"><desc><descript source="cve">Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/418.php">linux-pop3d</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0243" published="1999-01-01" seq="1999-0243" severity="High" type="CVE"><desc><descript source="cve">Linux cfingerd could be exploited to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0244" published="1997-12-01" seq="1999-0244" severity="High" type="CVE"><desc><descript source="cve">Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1891.php">radius-accounting-overflow(1891)</ref></refs><vuln_soft><prod name="RADIUS" vendor="Livingston"><vers num="1.x"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0245" published="1995-09-07" seq="1999-0245" severity="Medium" type="CVE"><desc><descript source="cve">Some configurations of NIS+ in Linux allowed attackers to log in as the user &quot;+&quot;.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/307.php">linux-plus(307)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0246" published="1996-10-01" seq="1999-0246" severity="High" type="CVE"><desc><descript source="cve">HP Remote Watch allows a remote user to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://xforce.iss.net/static/620.php">hp-remote</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0247" published="1997-07-21" seq="1999-0247" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in nnrpd program in INN up to version 1.6 allows remote users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1443">1443</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/623.php">inn-bo</ref><ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/17_inn_avd.asp">19970721 INN news server vulnerabilities</ref></refs><vuln_soft><prod name="INN" vendor="ISC"><vers num="1.4"/><vers num="1.4sec"/><vers num="1.4sec2"/><vers num="1.4unoff3"/><vers num="1.4unoff4"/><vers num="1.5"/><vers num="1.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0248" published="1999-01-01" seq="1999-0248" severity="High" type="CVE"><desc><descript source="cve">A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user&apos;s credentials.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="MISC" url="http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html">http://oliver.efri.hr/~crv/security/bugs/mUNIXes/ssh2.html</ref><ref source="CONFIRM" url="http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1">http://www.uni-karlsruhe.de/~ig25/ssh-faq/ssh-faq-6.html#ss6.1</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.27"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0249" published="1997-01-01" seq="1999-0249" severity="High" type="CVE"><desc><descript source="cve">Windows NT RSHSVC program allows remote users to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/114.php">rsh-svc</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0250" published="1997-07-01" seq="1999-0250" severity="High" type="CVE"><desc><descript source="cve">Denial of service in Qmail through long SMTP commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/207.php">qmail-leng</ref><ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref><ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref></refs><vuln_soft><prod name="Qmail" vendor="Dan Bernstein"><vers num="1.01" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0251" published="1997-01-01" seq="1999-0251" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in talk program allows remote attackers to disrupt a user&apos;s display.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/615.php">talkd-flash(615)</ref></refs><vuln_soft><prod name="talkd" vendor="talkd"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0252" published="1997-01-01" seq="1999-0252" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in listserv allows arbitrary command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/617.php">smtp-listserv(617)</ref></refs><vuln_soft><prod name="Listserv" vendor="L-Soft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0253" published="1997-01-01" seq="1999-0253" severity="High" type="CVE"><desc><descript source="cve">IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/621.php">http-iis-2e</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="1.0"/><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0254" published="1998-11-02" seq="1999-0254" severity="High" type="CVE"><desc><descript source="cve">A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-2.phpHPOV-hidden-SNMP-comm">hpov-hidden-snmp-comm</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0255" published="1999-01-01" seq="1999-0255" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in ircd allows arbitrary command execution.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0256" published="1998-02-01" seq="1999-0256" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in War FTP allows remote execution of commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/345.php">war-ftpd(345)</ref><ref source="OSVDB" url="http://www.osvdb.org/875">875</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod><prod name="WarFTPd" vendor="Jgaa"><vers num="1.66" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0257" published="1998-04-01" seq="1999-0257" severity="Medium" type="CVE"><desc><descript source="cve">Nestea variation of teardrop IP fragmentation denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/897.php">nestea-linux-dos(897)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0258" published="1998-02-13" seq="1999-0258" severity="Medium" type="CVE"><desc><descript source="cve">Bonk variation of teardrop IP fragmentation denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/343.php">teardrop-mod</ref><ref adv="1" source="CERT" url="ftp://ftp.cert.org/pub/cert_summaries/CS-98.02">Denial of Service attack (broad)</ref><ref adv="1" source="CERT" url="ftp://ftp.cert.org/pub/cert_summaries/CS-98.01">Denial of Service Attacks (Broad)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0259" published="1997-05-23" seq="1999-0259" severity="Medium" type="CVE"><desc><descript source="cve">cfingerd lists all users on a system via search.**@target.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1811.php">cfinger-user-enumeration(1811)</ref><ref adv="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9705D&amp;L=bugtraq&amp;P=R1300"></ref></refs><vuln_soft><prod name="cfingerd" vendor="Infodrom"><vers num="1.2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0260" published="1996-12-24" seq="1999-0260" severity="High" type="CVE"><desc><descript source="cve">The jj CGI program allows command execution via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1808.php">http-cgi-jj(1808)</ref></refs><vuln_soft><prod name="jj" vendor="Renaud Deraison"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0261" published="1999-03-01" seq="1999-0261" severity="Medium" type="CVE"><desc><descript source="cve">Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1987.php">chameleon-smtp-dos(1987)</ref><ref source="MISC" url="http://www.insecure.org/sploits/netmanage.chameleon.overflows.html">http://www.insecure.org/sploits/netmanage.chameleon.overflows.html</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0262" published="1998-08-04" seq="1999-0262" severity="High" type="CVE"><desc><descript source="cve">Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1532.php">http-cgi-faxsurvey(1532)</ref><ref source="BID" url="http://www.securityfocus.com/bid/2056">2056</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1532">http-cgi-faxsurvey(1532)</ref></refs><vuln_soft><prod name="faxsurvey" vendor="Renaud Deraison"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0263" published="1998-07-16" seq="1999-0263" severity="Medium" type="CVE"><desc><descript source="cve">Solaris SUNWadmap can be exploited to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/430">bugtraq id 430</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1200.php">sun-sunwadmap(1200)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/173">00173</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86HW5" num="2.6"/><vers edition="x86HW3" num="2.6"/><vers edition="HW5" num="2.6"/><vers edition="HW3" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-10-06" name="CVE-1999-0264" published="1998-01-27" seq="1999-0264" severity="Medium" type="CVE"><desc><descript source="cve">htmlscript CGI program allows remote read access to files.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1466.php">http-htmlscript-file-access(1466)</ref></refs><vuln_soft><prod name="htmlscript" vendor="Miva"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0265" published="1997-01-01" seq="1999-0265" severity="Medium" type="CVE"><desc><descript source="cve">ICMP redirect messages may crash or lock up a host.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/285.php">icmp-redirect(285)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q154174">Q154174</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="3.12"/></prod><prod name="OS-9" vendor="Microware"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0266" published="1998-03-01" seq="1999-0266" severity="High" type="CVE"><desc><descript source="cve">The info2www CGI script allows remote file access or remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1732.php">http-cgi-info2www(1732)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1995">1995</ref></refs><vuln_soft><prod name="info2www" vendor="Roar Smith"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-31" name="CVE-1999-0267" published="1997-09-23" seq="1999-0267" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-95.04.NCSA.http.daemon.for.unix.vulnerability.html">CA-95.04.NCSA.http.daemon.for.unix.vulnerability</ref></refs><vuln_soft><prod name="NCSA httpd" vendor="NCSA"><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0268" published="1999-01-01" seq="1999-0268" severity="High" type="CVE"><desc><descript source="cve">MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/Security%20vulnerabilities%20in%20MetaInfo%20products">Security vulnerabilities in Metalinfo products</ref><ref source="OSVDB" url="http://www.osvdb.org/110">110</ref><ref source="OSVDB" url="http://www.osvdb.org/3969">3969</ref></refs><vuln_soft><prod name="MetaWeb" vendor="Metainfo"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0269" published="1998-08-01" seq="1999-0269" severity="Medium" type="CVE"><desc><descript source="cve">Netscape Enterprise servers may list files through the PageServices query.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1810.php">netscape-server-pageservices(1810)</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0270" published="1998-04-03" seq="1999-0270" severity="Medium" type="CVE"><desc><descript source="cve">Directory traversal vulnerability in pfdispaly.cgi program (sometimes referred to as &quot;pfdisplay&quot;) for SGI&apos;s Performer API Search Tool (performer_tools) allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/i-041.shtml">Performer API Search Tool 2.2 pfdispaly.cgi Vulnerability</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/810.php">sgi-pfdispaly(810)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-03-15&amp;msg=199803162306.AAA25015@gtc1.cps.unizar.es"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980401-01-P">19980401-01-P</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-041.shtml">I-041</ref><ref source="BID" url="http://www.securityfocus.com/bid/64">64</ref><ref source="OSVDB" url="http://www.osvdb.org/134">134</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/810">sgi-pfdispaly(810)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0271" published="1998-01-15" seq="1999-0271" severity="Medium" type="CVE"><desc><descript source="cve">Progressive Networks Real Video server (pnserver) can be crashed remotely.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-24" name="CVE-1999-0272" published="1997-10-01" seq="1999-0272" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Slmail v2.5 through the POP3 port.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/221">BID 221</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1662.php">slmail-username-bo(1662)</ref></refs><vuln_soft><prod name="Slmail" vendor="Slmail"><vers num="3.0.2421"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0273" published="1998-01-01" seq="1999-0273" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service through Solaris 2.5.1 telnet by sending ^D characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1464.php">sun-telnet-kill(1464)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0274" published="1997-01-01" seq="1999-0274" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Windows NT DNS servers through malicious packet which contains a response to a query that wasn&apos;t made.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3106.php">nt-dns-dos(3106)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0275" published="1997-06-10" seq="1999-0275" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Windows NT DNS servers by flooding port 53 with too many characters.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/186.php">nt-dnscrash(186)</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/Q142/0/47.asp"></ref><ref adv="1" source="Insecure.org" url="http://www.insecure.org/sploits/NT.DNS.character_flood.html"></ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0276" published="1999-01-01" seq="1999-0276" severity="High" type="CVE"><desc><descript source="cve">mSQL v2.0.1 and below allows remote execution through a buffer overflow.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2143.php">msql-debug-bo(2143)</ref></refs><vuln_soft><prod name="mSQL" vendor="Hughes"><vers num="2.0.1"/><vers num="2.0."/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0277" published="1996-10-28" seq="1999-0277" severity="High" type="CVE"><desc><descript source="cve">The WorkMan program can be used to overwrite any file to get root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.23.workman_vul.html">CA-96.23.workman_vul</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/435.php">workman(435)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0278" published="1998-06-01" seq="1999-0278" severity="Medium" type="CVE"><desc><descript source="cve">In IIS, remote attackers can obtain source code for ASP files by appending &quot;::$DATA&quot; to the URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/149">BID 149</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1125.php">iis-asp-data-check(1135)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-003.mspx">MS98-003</ref><ref sig="1" source="OVAL" url="http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:913">oval:org.mitre.oval:def:913</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0279" published="1998-01-01" seq="1999-0279" severity="High" type="CVE"><desc><descript source="cve">Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1418.php">excite-cgi-search-vuln(1418)</ref><ref adv="1" patch="1" source="CERT" url="ftp://ftp.cert.org/pub/cert_bulletins/VB-98.01.excite">VB-98.01.excite-cgi-search-vuln</ref></refs><vuln_soft><prod name="EWS" vendor="Excite"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0280" published="1997-04-01" seq="1999-0280" severity="High" type="CVE"><desc><descript source="cve">Remote command execution in Microsoft Internet Explorer using .lnk and .url files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/463.php">http-ie-lnkurl(463)</ref><ref patch="1" source="Microsoft" url="http://www.microsoft.com/windows/ie/security/download.asp"></ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0"/><vers num="3.0.01"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0281" published="1997-06-01" seq="1999-0281" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in IIS using long URLs.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/531.php">http-iis-longurl(531)</ref><ref adv="1" patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q143/4/84.asp"></ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="2.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry modified="2005-10-31" name="CVE-1999-0282" published="1997-09-23" reject="1" seq="1999-0282" type="CVE"><desc><descript source="cve">** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-1584, CVE-1999-1586.  Reason: This candidate combined references from one issue with the description from another issue.  Notes: Users should consult CVE-1999-1584 and CVE-1999-1586 to obtain the appropriate name.  All references and descriptions in this candidate have been removed to prevent accidental usage.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0283" published="1999-01-01" seq="1999-0283" severity="High" type="CVE"><desc><descript source="cve">The Java Web Server would allow remote users to obtain the source code for CGI programs.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88256790401004&amp;w=2">19970716 Viewable .jhtml source with JavaWebServer</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0284" published="1998-01-01" seq="1999-0284" severity="High" type="CVE"><desc><descript source="cve">Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1834.php">mdaemon-helo-bo</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1813.php">lotus-notes-helo-crash</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/344.php">smtp-exchangedos(344)</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="4.0"/><vers num="5.0"/></prod><prod name="Lotus Domino Mail Server" vendor="IBM"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0285" published="1999-01-01" seq="1999-0285" severity="High" type="CVE"><desc><descript source="cve">Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0286" published="1999-01-01" seq="1999-0286" severity="High" type="CVE"><desc><descript source="cve">In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0287" published="1999-04-09" seq="1999-0287" severity="High" type="CVE"><desc><descript source="cve">Vulnerability in the Wguest CGI program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2072.php">http-cgi-webcom-guestbook(2072)</ref><ref adv="1" source="NT Bugtraq" url="http://www.ntbugtraq.com/default.asp?pid=36&amp;sid=1&amp;A2=ind9904&amp;L=ntbugtraq&amp;F=P&amp;S=&amp;P=2194">CGI Webcom guestbook</ref></refs><vuln_soft><prod name="CGI Guestbook" vendor="Webcom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0288" published="1998-08-01" seq="1999-0288" severity="Medium" type="CVE"><desc><descript source="cve">The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/298">BID 298</ref><ref source="" url="http://safenetworks.com/Windows/wins.html"></ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1233">nt-winsupd-fix(1233)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0289" published="1999-12-12" seq="1999-0289" severity="Medium" type="CVE"><desc><descript source="cve">The Apache web server for Win32 may provide access to restricted files when a . (dot) is appended to a requested URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs/><vuln_soft><prod name="Apache" vendor="Apache Software Foundation"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0290" published="1998-02-21" seq="1999-0290" severity="Medium" type="CVE"><desc><descript source="cve">The WinGate telnet proxy allows remote attackers to cause a denial of service via a large number of connections to localhost.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2003.php">wingate-dos(2003)</ref><ref adv="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9802D&amp;L=bugtraq&amp;P=R56"></ref></refs><vuln_soft><prod name="WinGate" vendor="Qbik"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0291" published="1999-02-01" seq="1999-0291" severity="High" type="CVE"><desc><descript source="cve">The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1849.php">wingate-unpassworded(1849)</ref></refs><vuln_soft><prod name="WinGate" vendor="Qbik"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0292" published="1997-04-01" seq="1999-0292" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service through Winpopup using large user names.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/538.php">nt-winpopup(538)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP1"/><vers num="4.0 SP2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0293" published="1998-01-01" seq="1999-0293" severity="High" type="CVE"><desc><descript source="cve">AAA authentication on Cisco systems allows attackers to execute commands without authorization.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/770/aaapair-pub.shtml">Cisco IOS 11.3(1.2) and 11.3(1.2)T AAA Failure</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1245.php">cisco-ios-aaa-auth(1245)</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0294" published="1997-10-01" seq="1999-0294" severity="Medium" type="CVE"><desc><descript source="cve">All records in a WINS database can be deleted through SNMP for a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/982.php">nt-wins-snmp2(982)</ref></refs><vuln_soft><prod name="WINS" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0295" published="1997-10-01" seq="1999-0295" severity="High" type="CVE"><desc><descript source="cve">Solaris sysdef command allows local users to read kernel memory, potentially leading to root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/241">bugtraq id 241</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/608.php">sun-sysdef(608)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/157">00157</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0296" published="1998-02-01" seq="1999-0296" severity="High" type="CVE"><desc><descript source="cve">Solaris volrmmount program allows attackers to read any file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/708.php">sun-volrmmount(708)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/162">00162</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.6"/><vers edition="x86" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-30" name="CVE-1999-0297" published="1996-12-12" seq="1999-0297" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3124.php">vixie-cron(3124)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0"/></prod><prod name="Linux" vendor="Red Hat"><vers num=""/></prod><prod name="Vixie Cron" vendor="Paul Vixie"><vers num="3.0"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0298" published="1997-02-05" seq="1999-0298" severity="High" type="CVE"><desc><descript source="cve">ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/1441">BID 1441</ref><ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp">19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme</ref></refs><vuln_soft><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.4"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="2.1"/><vers num="2.2"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0299" published="1997-03-05" seq="1999-0299" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in FreeBSD lpd through long DNS hostnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref source="OSVDB" url="http://www.osvdb.org/6093">6093</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="6.2 Stable"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0300" published="1997-10-01" seq="1999-0300" severity="High" type="CVE"><desc><descript source="cve">nis_cachemgr for Solaris NIS+ allows attackers to add malicious NIS+ servers.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/239">BID 239</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/606.php">sun-niscache(606)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/155">00155</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0301" published="1997-08-01" seq="1999-0301" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in SunOS/Solaris ps command.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/220">BID 220</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/484.php">sun-ps2bo(484)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/149">00149</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0302" published="1998-09-01" seq="1999-0302" severity="High" type="CVE"><desc><descript source="cve">SunOS/Solaris FTP clients can be forced to execute arbitrary commands from a malicious FTP server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1370.php">sun-ftp-server(1370)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/176">00176</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-02-20" name="CVE-1999-0303" published="1998-05-21" seq="1999-0303" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1395.php">bnu-uucpd-bo(1395)</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.1"/><vers num="2.2"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3"/><vers num="1.3.1"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers edition="x86" num="2.5"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers edition="JL" num="1.1.4"/><vers num="1.1.4"/><vers edition="U1" num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1a"/><vers num="1.1"/><vers edition="x86" num="Any"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.3"/><vers num="4.1.4"/></prod><prod name="OSF_1" vendor="Digital"><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0304" published="1998-02-01" seq="1999-0304" severity="High" type="CVE"><desc><descript source="cve">mmap function in BSD allows local attackers in the kmem group to modify memory through devices.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/735.php">bsd-mmap(735)</ref><ref adv="1" source="FreeBSD AUSCERT" url="ftp://ftp.auscert.org.au/pub/auscert/ESB/ESB-98.087"></ref><ref adv="1" source="Insecure.org" url="http://www.insecure.org/sploits/bsd.mmap.chardevice.html"></ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0305" published="1998-02-01" seq="1999-0305" severity="Medium" type="CVE"><desc><descript source="cve">The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are set, which allows remote attackers to spoof TCP connections.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/736.php">bsd-sourceroute(736)</ref><ref source="" url="http://www.openbsd.org/advisories/sourceroute.txt"></ref><ref source="OSVDB" url="http://www.osvdb.org/11502">11502</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/736">bsd-sourceroute(736)</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2"/><vers num="2.2.5"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.1"/><vers num="2.2"/><vers num="2.0"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0306" published="1997-11-04" seq="1999-0306" severity="High" type="CVE"><desc><descript source="cve">buffer overflow in HP xlock program.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-1_num-7.phpHP-xlock">hp-xlock</ref><ref adv="1" source="CERT" url="http://www.cert.org/advisories/CA-97.13.xlock.html">Vulnerability in xlock</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers edition="VVOS" num="10.24"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0307" published="2000-12-20" seq="1999-0307" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in HP-UX cstm program allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1440.php">hpux-cstm-bo</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9.0"/><vers num="10.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0308" published="1996-10-01" seq="1999-0308" severity="Medium" type="CVE"><desc><descript source="cve">HP-UX gwind program allows users to modify arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1414.php">hpux-gwind-overwrite(1414)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9410-018">HPSBUX9410-018</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="8"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0309" published="1997-02-01" seq="1999-0309" severity="High" type="CVE"><desc><descript source="cve">HP-UX vgdisplay program gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1415.php">hpux-vgdisplay(1415)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-056">HPSBUX9702-056</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.24"/><vers num="10.0"/><vers num="10.1"/><vers num="10.10"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0310" published="1998-09-01" seq="1999-0310" severity="High" type="CVE"><desc><descript source="cve">SSH 1.2.25 on HP-UX allows access to new user accounts.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1423.php">ssh-1225(1423)</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.25"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0311" published="1996-11-01" seq="1999-0311" severity="High" type="CVE"><desc><descript source="cve">fpkg2swpk in HP-UX allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1437.php">hpux-fpkg2swpk(1437)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9612-042">HPSBUX9612-042</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0312" published="1993-01-13" seq="1999-0312" severity="Medium" type="CVE"><desc><descript source="cve">HP ypbind allows attackers with root privileges to modify NIS data.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-93.01.REVISED.HP.NIS.ypbind.vulnerability.html">CA-93:01.REVISED.HP.NIS.ypbind.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/519.php">nis-ypbind(519)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/52">bugtraq id 52</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0313" published="1998-07-01" seq="1999-0313" severity="High" type="CVE"><desc><descript source="cve">disk_bandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/214">bugtraq id 214</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1441.php">sgi-disk-bandwidth(1441)</ref><ref source="" url="http://www.securityfocus.com/bid/213/exploit"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref><ref source="BID" url="http://www.securityfocus.com/bid/214">214</ref><ref source="OSVDB" url="http://www.osvdb.org/936">936</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1441">sgi-disk-bandwidth(1441)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4 S2MP"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0314" published="1998-07-01" seq="1999-0314" severity="High" type="CVE"><desc><descript source="cve">ioconfig on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1199.php">sgi-ioconfig(1199)</ref><ref source="" url="http://www.securityfocus.com/bid/213/exploit"></ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980701-01-P">19980701-01-P</ref><ref source="BID" url="http://www.securityfocus.com/bid/213">213</ref><ref source="OSVDB" url="http://www.osvdb.org/6788">6788</ref><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1199">sgi-ioconfig(1199)</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0315" published="1997-04-01" seq="1999-0315" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris fdformat command gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/875.php">fdformat-bo(875)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/138">00138</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.3"/><vers num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers num="2.6"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.5.1"/><vers edition="x86" num="2.4"/><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0316" published="1995-12-01" seq="1999-0316" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux splitvt command gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/430.php">linux-splitvt(430)</ref></refs><vuln_soft><prod name="Splitvt" vendor="Sam Lantinga"><vers num="1.6.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0317" published="1999-11-25" seq="1999-0317" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux su command gives root access to local users.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/734.php">su-bo(734)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-4_num-10.phpunixware-su-username-bo">unixware-su-username-bo</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0318" published="1997-03-01" seq="1999-0318" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in xmcd 2.0p12 allows local users to gain access through an environmental variable.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/436.php">xmcd-envbo(436)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="4"/></prod><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers num="2.6"/><vers num="7.0"/><vers num="8.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0319" published="1996-10-01" seq="1999-0319" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/437.php">xmcd-tiflestr(437)</ref></refs></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0320" published="1998-03-01" seq="1999-0320" severity="High" type="CVE"><desc><descript source="cve">SunOS rpc.cmsd allows attackers to obtain root access by overwriting arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/428">BID 428</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/818.php">sun-rpc.cmsd(818)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod><prod name="SunOS" vendor="Sun"><vers num="4.1.4"/><vers num="4.1.3u1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0321" published="1998-12-01" seq="1999-0321" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Solaris kcms_configure command allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1473.php">sun-kcms-configure-bo(1473)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0322" published="1997-10-29" seq="1999-0322" severity="Low" type="CVE"><desc><descript source="cve">The open() function in FreeBSD allows local attackers to write to arbitrary files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/591.php">freebsd-open(591)</ref><ref adv="1" source="FreeBSD" url="ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-97:05.open.asc">FreeBSD-SA-97:05</ref><ref source="OSVDB" url="http://www.osvdb.org/6092">6092</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.1.0"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0323" published="1998-02-20" seq="1999-0323" severity="High" type="CVE"><desc><descript source="cve">FreeBSD mmap function allows users to modify append-only or immutable files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/735.php">bsd-mmap(735)</ref><ref source="NETBSD" url="ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1998-003.txt.asc">1998-003</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="2.0.4"/></prod><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.2"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0324" published="1996-09-01" seq="1999-0324" severity="High" type="CVE"><desc><descript source="cve">ppl program in HP-UX allows local users to create root files through symlinks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/419.php">hp-ppllog(419)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9702-053">HPSBUX9702-053</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.0"/><vers num="9"/><vers num="10.1"/><vers num="10.10"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0325" published="1995-12-01" seq="1999-0325" severity="High" type="CVE"><desc><descript source="cve">vhe_u_mnt program in HP-UX allows local users to create root files through symlinks.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/433.php">hp-vhe(433)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9406-013">HPSBUX9406-013</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="8"/><vers num="9"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0326" published="1997-10-01" seq="1999-0326" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in HP-UX mediainit program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/567.php">hp-mediainit(567)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9710-071">HPSBUX9710-071</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="9"/><vers num="10.1"/><vers num="10.10"/><vers num="10.20"/><vers num="10.30"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0327" published="1997-11-01" seq="1999-0327" severity="Low" type="CVE"><desc><descript source="cve">SGI syserr program allows local users to corrupt files.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/85">bugtraq id 85</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/691.php">sgi-syserr</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0328" published="1997-11-01" seq="1999-0328" severity="High" type="CVE"><desc><descript source="cve">SGI permissions program allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/417">BID 417</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/692.php">sgi-permtool(692)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX">19971103-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/><vers num="5.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0329" published="1998-06-01" seq="1999-0329" severity="High" type="CVE"><desc><descript source="cve">SGI mediad program allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/394">BID 394</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1122.php">sgi-mediad(1122)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980602-01-PX">19980602-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="6.4"/><vers num="6.3"/><vers num="6.2"/><vers num="6.1"/><vers num="6.0.1 XFS"/><vers num="6.0.1"/><vers num="6.0"/><vers num="5.3 XFS"/><vers num="5.2"/><vers num="5.1.1"/><vers num="5.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0330" published="1998-03-01" seq="1999-0330" severity="High" type="CVE"><desc><descript source="cve">Linux bdash game has a buffer overflow that allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/821.php">bdash-bo(821)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0331" published="1998-01-01" seq="1999-0331" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Internet Explorer 4.0(1).</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/917.php">iemk-bug(917)</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="3.0.02"/><vers num="4.0.0"/><vers num="4.0.0.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0332" published="1998-12-01" seq="1999-0332" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in NetMeeting allows denial of service and remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/171">BID 171</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1222.php">nt-netmeeting(1222)</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q184346">Q184346</ref></refs><vuln_soft><prod name="NetMeeting" vendor="Microsoft"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0333" published="1998-08-01" seq="1999-0333" severity="High" type="CVE"><desc><descript source="cve">HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1396.php">omniback-remote(1396)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0334" published="1993-12-16" seq="1999-0334" severity="High" type="CVE"><desc><descript source="cve">In Solaris 2.2 and 2.3, when fsck fails on startup, it allows a local user with physical access to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-93.19.Solaris.Startup.vulnerability.html">CA-93.19.Solaris.Startup.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/552.php">sol-startup(552)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="x86"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0335" published="1996-08-01" seq="1999-0335" severity="High" type="CVE"><desc><descript source="cve">DEPRECATED.  This entry has been deprecated.  It is a duplicate of CVE-1999-0032.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="ftp://info.cert.org/pub/cert_advisories/CA-97.19.bsdlp">CA-97.19.bsdlp</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/409.php">bsd-lprbo(409)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="BSD_OS" vendor="BSDI"><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0336" published="1996-11-01" seq="1999-0336" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in mstm in HP-UX allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1439.php">hpux-mstm-bo(1439)</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0337" published="1994-06-03" seq="1999-0337" severity="High" type="CVE"><desc><descript source="cve">AIX batch queue (bsh) allows local and remote users to gain additional privileges when network printing is enabled.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.10.IBM.AIX.bsh.vulnerability.html">CA-94.10.IBM.AIX.bsh.vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/509.php">ibm-bsh(509)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/349">bugtraq id 349</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="3.1"/><vers num="2.2.1"/><vers num="1.3"/><vers num="1.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0338" published="1994-02-24" seq="1999-0338" severity="High" type="CVE"><desc><descript source="cve">AIX Licensed Program Product performance tools allow local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-94.03.AIX.performance.tools.html">CA-94.03.AIX.performance.tools</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/504.php">ibm-perf-tools(504)</ref></refs><vuln_soft><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="3.2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0339" published="1998-08-01" seq="1999-0339" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the libauth library in Solaris allows local users to gain additional privileges, possibly root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/442">bugtraq id 442</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1219.php">sol-sun-libauth(1219)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0340" published="1997-12-01" seq="1999-0340" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Linux Slackware crond program allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/695.php">linux-crond(695)</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0341" published="1998-01-01" seq="1999-0341" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Linux mail program &quot;deliver&quot; allows local users to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/226">bugtraq id 226</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/702.php">linux-deliver(702)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="1.3.1"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0342" published="1998-12-01" seq="1999-0342" severity="Medium" type="CVE"><desc><descript source="cve">Linux PAM modules allow local users to gain root access using temporary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1474.php">linux-pam-passwd-tmprace(1474)</ref><ref adv="1" patch="1" source="RedHat" url="http://www.redhat.com/corp/support/errata/rh42-errata-general.htmlpam">pam</ref><ref source="REDHAT" url="http://www.redhat.com/corp/support/errata/rh42-errata-general.html#pam">http://www.redhat.com/corp/support/errata/rh42-errata-general.html#pam</ref></refs><vuln_soft><prod name="pam" vendor="pam"><vers num="0.64" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0343" published="1998-10-02" seq="1999-0343" severity="Medium" type="CVE"><desc><descript source="cve">A malicious Palace server can force a client to execute arbitrary programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><network/><user_init/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1631.php">palace-malicious-servers-vuln(1631)</ref><ref adv="1" source="Netscape" url="http://www.netspace.org/cgi-bin/wa?A2=ind9810A&amp;L=bugtraq&amp;P=R886"></ref></refs><vuln_soft><prod name="Palace Client" vendor="Palace"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0344" published="1998-08-01" seq="1999-0344" severity="Medium" type="CVE"><desc><descript source="cve">NT users can gain debug-level access on a system process using the Sechole exploit.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1231.php">nt-priv-fix(1231)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-009.mspx">MS98-009</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q190288">Q190288</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="3.5"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0345" published="1997-01-01" seq="1999-0345" severity="Medium" type="CVE"><desc><descript source="cve">Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/95.php">ping-death(95)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.26.ping.html">CA-96.26</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="1.0"/><vers num="1.1"/><vers num="1.1.5.1"/><vers num="1.2"/><vers num="2.0"/><vers num="2.0.5"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2"/><vers num="4.1"/><vers num="4.2"/></prod><prod name="Open Desktop" vendor="SCO"><vers num="3"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5"/></prod><prod name="SunOS" vendor="Sun"><vers num=""/></prod><prod name="Internet FastStart" vendor="SCO"><vers num="1.0"/><vers num="1.1"/></prod><prod name="SNG" vendor="IBM"><vers num="2.1"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0346" published="1997-10-16" seq="1999-0346" severity="Medium" type="CVE"><desc><descript source="cve">CGI PHP mlog script allows an attacker to read any file on the target server.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1505.php">http-cgi-php-mlog(1505)</ref><ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref><ref source="OSVDB" url="http://www.osvdb.org/3397">3397</ref></refs><vuln_soft><prod name="PHP_FI" vendor="PHP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-11-02" name="CVE-1999-0347" published="1999-01-26" seq="1999-0347" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a &quot;%01&quot; character in an &quot;about:&quot; Javascript URL, which causes Internet Explorer to use the domain specified after the character.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91745430007021&amp;w=2">19990126 Javascript ecurity bug in Internet Explorer</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91756771207719&amp;w=2">19990126 Javascript ecurity bug in Internet Explorer</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0348" published="1999-01-27" seq="1999-0348" severity="Medium" type="CVE"><desc><descript source="cve">IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/195">bugtraq id 195</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q197003">Q197003</ref><ref source="OSVDB" url="http://www.osvdb.org/930">930</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0349" published="1999-01-27" seq="1999-0349" severity="High" type="CVE"><desc><descript source="cve">A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/192">bugtraq id 192</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1654.php">iis-remote-ftp(1654)</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/IIS Remote FTP Exploit/DoS Attack.html">IIS Remote FTP Exploit/DoS Attack</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-003.mspx">MS99-003</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q188348">Q188348</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="10.0" CVSS_score="6.2" CVSS_vector="(AV:L/AC:H/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0350" published="1999-02-08" seq="1999-0350" severity="Medium" type="CVE"><desc><descript source="cve">Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/538">BID 538</ref><ref adv="1" patch="1" source="CERT" url="http://xforce.iss.net/static/1718.php">clearcase-temp-race(1718)</ref></refs><vuln_soft><prod name="ClearCase" vendor="Rational Software"><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0351" published="1999-02-01" seq="1999-0351" severity="Medium" type="CVE"><desc><descript source="cve">FTP PASV &quot;Pizza Thief&quot; denial of service and unauthorized data access.  Attackers can steal data by connecting to a port that was intended for use by a client.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref source="XF" url="http://xforce.iss.net/xforce/xfdb/3389">FTP PASV Pizza Thief denial of service</ref><ref source="" url="http://attrition.org/security/advisory/misc/infowar/iw_sec_01.txt"></ref></refs><vuln_soft><prod name="FTP PASV" vendor="FTP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0352" published="1999-01-25" seq="1999-0352" severity="High" type="CVE"><desc><descript source="cve">ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1651.php">controlit-passwd-encrypt(1651)</ref></refs></entry><entry CVSS_base_score="9.3" CVSS_exploit_subscore="8.6" CVSS_impact_subscore="10.0" CVSS_score="9.3" CVSS_vector="(AV:N/AC:M/Au:N/C:C/I:C/A:C)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0353" published="1999-02-10" seq="1999-0353" severity="High" type="CVE"><desc><descript source="cve">rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1699.php">pcnfsd-world-write(1699)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9902-091">HPSBUX9902-091</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-026.shtml">J-026</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.1"/><vers num="10.10"/><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0354" published="1999-11-01" seq="1999-0354" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn&apos;t warn the user that the template contains executable content.  Also applies to Outlook when the client views a malicious email message.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3498.php">word97-template-macro(3498)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-002.asp">MS99-002</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/></prod><prod name="Word" vendor="Microsoft"><vers num="97"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0355" published="1999-01-01" seq="1999-0355" severity="Medium" type="CVE"><desc><descript source="cve">Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise18.php"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1653.php">controlit-reboot(1653)</ref></refs><vuln_soft><prod name="ControlIT" vendor="Computer Associates"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0356" published="1999-01-25" seq="1999-0356" severity="High" type="CVE"><desc><descript source="cve">ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-5.phpcontrolit-bookfile-access">controlit-bookfile-access</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0357" published="1999-01-25" seq="1999-0357" severity="Medium" type="CVE"><desc><descript source="cve">Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted &quot;oshare&quot; packets, possibly involving invalid fragmentation offsets.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2228.php">win98-oshare-dos(2228)</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0358" published="1999-02-01" seq="1999-0358" severity="High" type="CVE"><desc><descript source="cve">Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3137.php">du-inc(3137)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/12121">19990125 Digital Unix 4.0 exploitable buffer overflows</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-027.shtml">J-027</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num="4.0"/><vers num="4.0A"/><vers num="4.0B"/><vers num="4.0C"/><vers num="4.0D"/><vers num="4.0e"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0359" published="2001-03-12" seq="1999-0359" severity="High" type="CVE"><desc><descript source="cve">ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1" user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Bugtraq" url="http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26start%3D1999-01-27%26mid%3D12179%26end%3D1999-02-02%26fromthread%3D0%26threads%3D0%26">19990127 UNIX shell modem access vulnerabilities</ref></refs><vuln_soft><prod name="ptylogin" vendor="Marc Schaefer"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0360" published="1999-01-30" seq="1999-0360" severity="High" type="CVE"><desc><descript source="cve">MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="NT Bugtraq" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91763097004101&amp;w=2">IIS/MS Site Server</ref></refs><vuln_soft><prod name="Site Server" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0361" published="1999-01-01" seq="1999-0361" severity="High" type="CVE"><desc><descript source="cve">NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0362" published="1999-02-02" seq="1999-0362" severity="Medium" type="CVE"><desc><descript source="cve">WS_FTP server remote denial of service through cwd command.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/217">bugtraq id 217</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1694.php">wsftp-remote-dos(1694)</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02021999.html">AD02021999</ref><ref source="BID" url="http://www.securityfocus.com/bid/217">217</ref></refs><vuln_soft><prod name="WS_FTP Server" vendor="Ipswitch"><vers num="1.0.2EVAL"/><vers num="1.0.1EVAL"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0363" published="1999-02-02" seq="1999-0363" severity="High" type="CVE"><desc><descript source="cve">SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1738.php">plp-lpc-bo(1738)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/328">BID 328</ref><ref source="BID" url="http://www.securityfocus.com/bid/328">328</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="5.2"/></prod><prod name="Line Printer Control" vendor="PLP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0364" published="1999-01-01" seq="1999-0364" severity="High" type="CVE"><desc><descript source="cve">Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91816470220259&amp;w=2">19990204 Microsoft Access 97 Stores Database Password as Plaintext</ref></refs><vuln_soft><prod name="Access" vendor="Microsoft"><vers num="97"/></prod><prod name="Total VB SourceBook" vendor="FMS Inc."><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0365" published="1999-02-04" seq="1999-0365" severity="High" type="CVE"><desc><descript source="cve">The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/110">BID 110</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1676.php">metamail-header-commands(1676)</ref></refs><vuln_soft><prod name="Sendmail" vendor="Metainfo"><vers num="2.5"/><vers num="2.0"/></prod><prod name="MetaIP" vendor="Metainfo"><vers num="3.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0366" published="1999-02-08" seq="1999-0366" severity="High" type="CVE"><desc><descript source="cve">In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/227">BID 227</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1719.php">nt-sp4-auth-error(1719)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-004.mspx">MS99-004</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q214840">Q214840</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP4"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0367" published="1999-02-09" seq="1999-0367" severity="Low" type="CVE"><desc><descript source="cve">NetBSD netstat command allows local users to access kernel memory.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" source="NetBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-002.txt.asc">1999-002</ref><ref source="OSVDB" url="http://www.osvdb.org/7571">7571</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-20" name="CVE-1999-0368" published="1999-02-09" seq="1999-0368" severity="High" type="CVE"><desc><descript source="cve">Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-03-FTP-Buffer-Overflows.html">CA-99-03-FTP-Buffer-Overflows</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1728.php">palmetto-ftpd-bo(1728)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/113">BID 113</ref></refs><vuln_soft><prod name="ProFTPD" vendor="ProFTPD Project"><vers num="1.2 pre1"/></prod><prod name="Linux" vendor="Red Hat"><vers num="5.1"/><vers num="5.0"/></prod><prod name="wu-ftpd" vendor="Washington University"><vers num="2.4.2 Beta18 VR9"/><vers num="2.4.2 Beta18"/></prod><prod name="OpenServer" vendor="SCO"><vers num="5.0.5"/><vers num="5.0.4"/><vers num="5.0.3"/><vers num="5.0.2"/><vers num="5.0"/></prod><prod name="Unixware" vendor="SCO"><vers num="7.0.1"/><vers num="7.0"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.3"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0369" published="1997-02-01" seq="1999-0369" severity="High" type="CVE"><desc><descript source="cve">The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1729.php">sun-sdtcm-convert-bo(1729)</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/183">00183</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/><vers num="2.2"/><vers num="2.1"/><vers num="2.0"/><vers num="1.2"/><vers edition="JL" num="1.1.4"/><vers num="1.1.4"/><vers edition="U1" num="1.1.3"/><vers num="1.1.2"/><vers num="1.1.1a"/><vers num="1.1"/><vers edition="x86" num="Any"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0370" published="1999-02-10" seq="1999-0370" severity="Medium" type="CVE"><desc><descript source="cve">In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-5.phpsun-man">sun-man</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D165">Solaris/SunOS man/catman Vulnerability</ref><ref source="BID" url="http://www.securityfocus.com/bid/165">165</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.4"/><vers edition="x86" num="2.4"/><vers num="2.5"/><vers num="2.5.1"/><vers edition="x86" num="2.5.1"/><vers num="2.6"/><vers edition="x86" num="2.6"/><vers num="7.0"/><vers edition="x86" num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-04" name="CVE-1999-0371" published="1999-02-11" seq="1999-0371" severity="Low" type="CVE"><desc><descript source="cve">Lynx allows a local user to overwrite sensitive files through /tmp symlinks.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1665.php">lynx-temp-files-race(1665)</ref></refs><vuln_soft><prod name="Lynx" vendor="University of Kansas"><vers num="2.7.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0372" published="1999-02-12" seq="1999-0372" severity="Low" type="CVE"><desc><descript source="cve">The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.</descript></desc><loss_types><conf/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1736.php">nt-backoffice-setup(1736)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-005.asp">MS99-005</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-005.mspx">MS99-005</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q217004">Q217004</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="BackOffice" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0373" published="1999-02-01" seq="1999-0373" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the &quot;Super&quot; utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/341">bugtraq id 341</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1723.php">linux-super-bo(1723)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1832.php">linux-super-logging-bo(1832)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0374" published="1999-02-16" seq="1999-0374" severity="Low" type="CVE"><desc><descript source="cve">Debian GNU/Linux cfengine package is susceptible to a symlink attack.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/314">bugtraq id 314</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1802.php">linux-cfengine-symlinks(1802)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0375" published="1999-02-16" seq="1999-0375" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1775.php">nfr-webd-overflow(1775)</ref></refs><vuln_soft><prod name="Network Flight Recorder" vendor="Network Flight Recorder"><vers num="2.0.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0376" published="1999-02-20" seq="1999-0376" severity="Medium" type="CVE"><desc><descript source="cve">Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious programs.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/234">BID 234</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1820.php">nt-knowndlls-list(1820)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-006.asp">MS99-006</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-006.mspx">MS99-006</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/><vers num="3.5.1"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-21" name="CVE-1999-0377" published="1999-02-22" seq="1999-0377" severity="Medium" type="CVE"><desc><descript source="cve">Process table attack in Unix systems allows a remote attacker to perform a denial of service by filling a machine&apos;s process tables through multiple connections to network services.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref source="remote assessment" url="http://remoteassessment.com/?op=varchive&amp;vulnid=5026">unix-process-table-dos</ref><ref source="CA" url="http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=1459">Kernel process-table DoS</ref></refs><vuln_soft><prod name="Unix" vendor="Unix"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0378" published="1999-02-22" seq="1999-0378" severity="Medium" type="CVE"><desc><descript source="cve">InterScan VirusWall for Solaris doesn&apos;t scan files for viruses when a single HTTP request includes two GET commands.</descript></desc><loss_types><conf/></loss_types><vuln_types><input bound="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3280.php">viruswall-http-request(3280)</ref><ref source="OSVDB" url="http://www.osvdb.org/6167">6167</ref></refs><vuln_soft><prod name="InterScan VirusWall" vendor="Trend Micro"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0379" published="1999-02-22" seq="1999-0379" severity="High" type="CVE"><desc><descript source="cve">Microsoft Taskpads allows remote web sites to execute commands on the visiting user&apos;s machine via certain methods that are marked as Safe for Scripting.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/498">bugtraq id 498</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1821.php">win-resourcekit-taskpads(1821)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-007.asp">MS99-007</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-007.mspx">MS99-007</ref><ref source="BID" url="http://www.securityfocus.com/bid/498">498</ref><ref source="OSVDB" url="http://www.osvdb.org/1019">1019</ref></refs><vuln_soft><prod name="BackOffice Resource Kit" vendor="Microsoft"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0380" published="1999-02-25" seq="1999-0380" severity="Medium" type="CVE"><desc><descript source="cve">SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user&apos;s Finger File to point to the target file, then running finger on the user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/frames/?content=/vdb/bottom.html%3Fvid%3D497">NT SLMail Remote Administration Service Vulnerability</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=91999015212415&amp;w=2">199902225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91996412724720&amp;w=2">19990225 ALERT: SLMail 3.2 (and 3.1) with the Remote Administration Service</ref><ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92110501504997&amp;w=2">SLmail 3.2 Build 3113 (Web Administration Security Fix)</ref><ref source="BID" url="http://www.securityfocus.com/bid/497">497</ref><ref source="XF" url="http://xforce.iss.net/static/5392.php">slmail-ras-ntfs-bypass(5392)</ref></refs><vuln_soft><prod name="SLMail" vendor="Seattle Lab Software"><vers num="3.0.2421"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0381" published="1999-02-26" seq="1999-0381" severity="High" type="CVE"><desc><descript source="cve">super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1832.php">linux-super-logging-bo(1832 )</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/342">Debian Super Syslog Buffer Overflow Vulnerability</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.96.990225011801.12757A-100000@eleet">19990225 SUPER buffer overflow</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.6.20.1"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0382" published="1999-03-12" seq="1999-0382" severity="High" type="CVE"><desc><descript source="cve">The screen saver in Windows NT does not verify that its security context has been changed properly, allowing attackers to run programs with elevated privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/474">BID 474</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1946.php">nt-screen-saver(1946)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-008.asp">MS99-008</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-008.mspx">MS99-008</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="4.0"/><vers num="3.5.1 SP5"/><vers num="3.5.1 SP4"/><vers num="3.5.1 SP3"/><vers num="3.5.1 SP2"/><vers num="3.5.1 SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0383" published="1999-02-02" seq="1999-0383" severity="High" type="CVE"><desc><descript source="cve">ACC Tigris allows public access without a login.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/183">BID 183</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1571.php">acc-tigris-login(1571)</ref><ref source="BID" url="http://www.securityfocus.com/bid/183">183</ref><ref source="OSVDB" url="http://www.osvdb.org/267">267</ref></refs><vuln_soft><prod name="Tigris" vendor="ACC"><vers num="10.5.8"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0384" published="1999-01-01" seq="1999-0384" severity="Medium" type="CVE"><desc><descript source="cve">The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user&apos;s clipboard when the user accesses documents with ActiveX content.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1659.php">forms-vuln-patch(1659)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-001.asp">MS99-001</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-001.mspx">MS99-001</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Office" vendor="Microsoft"><vers edition="Mac" num="98"/></prod><prod name="Outlook" vendor="Microsoft"><vers num="98"/></prod><prod name="Visual Basic" vendor="Microsoft"><vers num="5.0"/></prod><prod name="Project" vendor="Microsoft"><vers num="98"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-09-01" name="CVE-1999-0385" published="1998-12-01" seq="1999-0385" severity="High" type="CVE"><desc><descript source="cve">The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/503">bugtraq id 503</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1969.php">ldap-mds-dos(1969)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-009.asp">MS99-009</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-009.mspx">MS99-009</ref></refs><vuln_soft><prod name="exchange srv" vendor="Microsoft"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0386" published="1999-03-01" seq="1999-0386" severity="Medium" type="CVE"><desc><descript source="cve">Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read files on the server by using a nonstandard URL.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2036.php">pws-file-access(2036)</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-010.asp">MS99-010</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-010.mspx">MS99-010</ref><ref source="OSVDB" url="http://www.osvdb.org/111">111</ref></refs><vuln_soft><prod name="Personal Web Server" vendor="Microsoft"><vers num="4.0"/></prod><prod name="Frontpage" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0387" published="1999-11-29" seq="1999-0387" severity="High" type="CVE"><desc><descript source="cve">A legacy credential caching mechanism used in Windows 95 and Windows 98 systems allows attackers to read plaintext network passwords.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/TechNet/security/bulletin/ms99-052.asp">MS99-052</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/fq99-052.asp">MS99-052</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3574.php">9x-plaintext-pwd(3574)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/829">Bugtraq id 829</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q168115">Q168115</ref><ref source="BID" url="http://www.securityfocus.com/bid/829">829</ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0388" published="1999-01-01" seq="1999-0388" severity="Medium" type="CVE"><desc><descript source="cve">DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/186">bugtraq id 186</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1543.php">datalynx-suguard-relative-paths(1543)</ref><ref source="OSVDB" url="http://www.osvdb.org/3186">3186</ref></refs><vuln_soft><prod name="suGuard" vendor="DataLynx"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0389" published="1999-01-03" seq="1999-0389" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the bootp server in the Debian Linux netstd package.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/324">Debian GNU/Linux netstd Vulnerabilities</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4099.php">debian-netstd-bo(4099)</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/><vers num="1.3.1"/><vers num="1.3"/><vers num="1.2"/><vers num="1.1"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0390" published="1999-01-04" seq="1999-0390" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in Dosemu Slang library in Linux.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-12-29&amp;msg=Pine.LNX.3.96.990104062606.4420B-100000@bufh.bbs.is"></ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/187">Bugtraq id 187</ref><ref source="CALDERA" url="ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-1999-006.1.txt">CSSA-1999-006.1</ref><ref source="BID" url="http://www.securityfocus.com/bid/187">187</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.2"/><vers num="4.1"/><vers num="4.0"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="5.1"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-04-19" name="CVE-1999-0391" published="1999-01-05" seq="1999-0391" severity="High" type="CVE"><desc><descript source="cve">The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/233">BID 233</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/><vers num="4.0 SP5"/><vers num="4.0 SP4"/><vers num="4.0 SP3"/><vers num="4.0 SP2"/><vers num="4.0 SP1"/><vers num="3.5.1 SP5"/><vers num="3.5.1 SP4"/><vers num="3.5.1 SP3"/><vers num="3.5.1 SP2"/><vers num="3.5.1 SP1"/></prod><prod name="Terminal Server" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0392" published="1999-01-10" seq="1999-0392" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in Thomas Boutell&apos;s cgic library version up to 1.05.</descript></desc><loss_types><conf/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1603.php">http-cgic-library-bo(1603)</ref></refs><vuln_soft><prod name="cgic library" vendor="Thomas Boutell"><vers num="1.05" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0393" published="1999-01-01" seq="1999-0393" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3477.php">sendmail-parsing-redirection(3477)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91694391227372&amp;w=2">19990121 Sendmail 8.8.x/8.9.x bugware</ref></refs><vuln_soft><prod name="Sendmail" vendor="Eric Allman"><vers num="8.9.2"/><vers num="8.8"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0394" published="1999-01-01" seq="1999-0394" severity="High" type="CVE"><desc><descript source="cve">DPEC Online Courseware allows an attacker to change another user&apos;s password without knowing the original password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.1" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="6.4" CVSS_score="5.1" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0395" published="1999-01-01" seq="1999-0395" severity="Medium" type="CVE"><desc><descript source="cve">A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1611.php">backweb-polite-agent-protocol(1611)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise17.php">backweb-polite-agent-protocol</ref></refs><vuln_soft><prod name="BackWeb Polite Agent Protocol" vendor="BackWeb Technologies"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0396" published="1999-02-17" seq="1999-0396" severity="Low" type="CVE"><desc><descript source="cve">A race condition between the select() and accept() calls in NetBSD TCP servers allows remote attackers to cause a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1658.php">netbsd-tcp-race(1658)</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0397" published="1999-01-01" seq="1999-0397" severity="High" type="CVE"><desc><descript source="cve">The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0398" published="1999-01-01" seq="1999-0398" severity="Medium" type="CVE"><desc><descript source="cve">In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3493.php">ssh-exp-account-access(3493)</ref></refs><vuln_soft><prod name="SSH daemon" vendor="SSH Communications Security"><vers num="1.2.27"/></prod><prod name="SSH2" vendor="SSH Communications Security"><vers num="2.0.11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0399" published="1999-01-01" seq="1999-0399" severity="High" type="CVE"><desc><descript source="cve">The DCC server command in the Mirc 5.5 client doesn&apos;t filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3495.php">mirc-dcc-metachar-filename</ref></refs><vuln_soft><prod name="mIRC" vendor="Khaled Mardam-Bey"><vers num="5.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0400" published="1999-01-26" seq="1999-0400" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in Linux 2.2.0 running the ldd command on a core file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><exception/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/344">Linux ldd core Vulnerability</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="3.7" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="6.4" CVSS_score="3.7" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0401" published="1999-01-01" seq="1999-0401" severity="Low" type="CVE"><desc><descript source="cve">A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3497.php">linux-race-condition-proc(3497)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.2.1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-22" name="CVE-1999-0402" published="1999-01-02" seq="1999-0402" severity="Medium" type="CVE"><desc><descript source="cve">wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1805.php">wget-permissions(1805)</ref></refs><vuln_soft><prod name="wget" vendor="GNU"><vers num="1.5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0403" published="1999-02-01" seq="1999-0403" severity="Medium" type="CVE"><desc><descript source="cve">A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1716.php">cyrix-hang(1716)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91821080015725&amp;w=2">19990204 Cyrix bug: freeze in hell, badboy</ref></refs><vuln_soft><prod name="Linux" vendor="Cyrix"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0404" published="1999-02-14" seq="1999-0404" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1773.php">mailmax-bo(1773)</ref></refs><vuln_soft><prod name="MailMax" vendor="SmartMax Software"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0405" published="1999-02-18" seq="1999-0405" severity="High" type="CVE"><desc><descript source="cve">A buffer overflow in lsof allows local users to obtain root privilege.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/496">bugtraq id 496</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1791.php">lsof-bo(1791)</ref><ref source="OSVDB" url="http://www.osvdb.org/3163">3163</ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="3.2"/><vers num="3.1"/><vers num="3.0"/><vers num="2.2.8"/><vers num="2.2.6"/><vers num="2.2.5"/><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.1.7.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="2.0"/></prod><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="5.2"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.1"/><vers num="6.0"/><vers num="5.3"/><vers num="5.2"/><vers num="5.1"/><vers num="5.0"/><vers num="4.4.1"/><vers num="4.4"/><vers num="4.3"/><vers num="4.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0.5"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0406" published="1999-02-19" seq="1999-0406" severity="High" type="CVE"><desc><descript source="cve">Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1807.php">digital-networker-bo(1807)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-6.phpdigital-networker-bo">digital-networker-bo(1807)</ref></refs><vuln_soft><prod name="UNIX" vendor="Digital"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0407" published="1999-02-09" seq="1999-0407" severity="High" type="CVE"><desc><descript source="cve">By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91983486431506&amp;w=2">19990209 ALERT: IIS4 allows proxied password attacks over NetBIOS</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92000623021036&amp;w=2">19990209 Re: IIS4 allows proxied password attacks over NetBIOS</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-08-28" name="CVE-1999-0408" published="1999-02-25" seq="1999-0408" severity="High" type="CVE"><desc><descript source="cve">Files created from interactive shell sessions in Cobalt RaQ microservers (e.g. .bash_history) are world readable, and thus are accessible from the web server.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="Wired" url="http://www.wired.com/news/news/technology/story/18109.html"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1831.php">cobalt-raq-history-exposure(1831)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/337">bugtraq id 337</ref><ref source="BID" url="http://www.securityfocus.com/bid/337">337</ref></refs><vuln_soft><prod name="Cobalt RaQ" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0409" published="1999-03-04" seq="1999-0409" severity="Medium" type="CVE"><desc><descript source="cve">Buffer overflow in gnuplot in Linux version 3.5 allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1888.php">gnuplot-home-overflow(1888)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/319">BID 319</ref><ref source="BID" url="http://www.securityfocus.com/bid/319">319</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="5.2"/><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0410" published="1999-03-05" seq="1999-0410" severity="High" type="CVE"><desc><descript source="cve">The cancel command in Solaris 2.6 (i386) has a buffer overflow that allows local users to obtain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/293">bugtraq id 293</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1900.php">sol-cancel(1900)</ref><ref source="BID" url="http://www.securityfocus.com/bid/293">293</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0411" published="1999-03-07" seq="1999-0411" severity="High" type="CVE"><desc><descript source="cve">Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1930.php">sco-startup-scripts(1930)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-7.phpsco-startup-scripts">sco-startup-scripts</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num="3.0"/><vers num="5"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0412" published="1999-02-19" seq="1999-0412" severity="High" type="CVE"><desc><descript source="cve">In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/501">bugtraq id 501</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1950.php">iis-isapi-execute(1950)</ref><ref source="BID" url="http://www.securityfocus.com/bid/501">501</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0413" published="1999-03-01" seq="1999-0413" severity="High" type="CVE"><desc><descript source="cve">A buffer overflow in the SGI X server allows local users to gain root access through the X server font path.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1929.php">irix-font-path-overflow(1929)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19990301-01-PX">19990301-01-PX</ref></refs><vuln_soft><prod name="IRIX" vendor="SGI"><vers num="5.3"/><vers num="6.2"/><vers num="6.3"/><vers num="6.4"/><vers num="6.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0414" published="1999-03-01" seq="1999-0414" severity="Medium" type="CVE"><desc><descript source="cve">In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer before fully establishing the connection.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/580">bugtraq id 580</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1932.php">linux-blind-spoof(1932)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0.37"/><vers num="2.0.36"/><vers num="2.0.35"/><vers num="2.0.30"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0415" published="1999-03-11" seq="1999-0415" severity="High" type="CVE"><desc><descript source="cve">The HTTP server in Cisco 7xx series routers 3.2 through 4.2 is enabled by default, which allows remote attackers to change the router&apos;s configuration.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS" url="http://xforce.iss.net/alerts/vol-3_num-7.php">cisco-router-commands</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1951.php">cisco-router-commands(1951)</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref></refs><vuln_soft><prod name="Cisco 7xx Routers" vendor="Cisco"><vers num="4.2" prev="1"/><vers num="3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0416" published="1999-03-11" seq="1999-0416" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in Cisco 7xx series routers allows a remote attacker to cause a system reload via a TCP connection to the router&apos;s TELNET port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/><exception/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS" url="http://xforce.iss.net/alerts/vol-3_num-7.php">cisco-router-dos</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1886.php">cisco-web-crash(1886)</ref><ref source="CISCO" url="http://www.cisco.com/warp/public/770/7xxconn-pub.shtml">19990311 Cisco 7xx TCP and HTTP Vulnerabilities</ref><ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/j-034.shtml">J-034</ref></refs><vuln_soft><prod name="Cisco 7xx Routers" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0417" published="1999-03-09" seq="1999-0417" severity="Low" type="CVE"><desc><descript source="cve">64 bit Solaris 7 procfs allows local users to perform a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1935.php">solaris-psinfo-crash(1935)</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/448.com">BID 448</ref><ref source="BID" url="http://www.securityfocus.com/bid/448">448</ref><ref source="OSVDB" url="http://www.osvdb.org/1001">1001</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="7.0"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0418" published="1999-03-08" seq="1999-0418" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many &quot;RCPT TO&quot; commands in the same connection.</descript></desc><loss_types><avail/><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100018214316&amp;w=2">19990308 SMTP server account probing</ref></refs></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0419" published="1999-03-01" seq="1999-0419" severity="Medium" type="CVE"><desc><descript source="cve">When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3499.php">smtp-4xx-error-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/12874"></ref></refs></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0420" published="1999-03-17" seq="1999-0420" severity="High" type="CVE"><desc><descript source="cve">umapfs allows local users to gain root privileges by changing their uid through a malicious mount_umap program.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="NetBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-006.txt.asc"></ref></refs><vuln_soft><prod name="umapfs" vendor="NetBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0421" published="1999-03-17" seq="1999-0421" severity="High" type="CVE"><desc><descript source="cve">During a reboot after an installation of Linux Slackware 3.6, a remote attacker can obtain root access by logging in to the root account without a password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/338">BID 338</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2040.php">linux-slackware-install(2040)</ref><ref source="OSVDB" url="http://www.osvdb.org/981">981</ref></refs><vuln_soft><prod name="Slackware Linux" vendor="Slackware"><vers num="3.6"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0422" published="1999-03-17" seq="1999-0422" severity="Medium" type="CVE"><desc><descript source="cve">In some cases, NetBSD 1.3.3 mount allows local users to execute programs in some file systems that have the &quot;noexec&quot; flag set.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="NetBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-007.txt.asc"></ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0423" published="1994-06-01" seq="1999-0423" severity="Medium" type="CVE"><desc><descript source="cve">Vulnerability in hpterm on HP-UX 10.20 allows local users to gain additional privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2182.php">hp-hpterm-files(2182)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-093">HPSBUX9903-093</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0424" published="1999-03-18" seq="1999-0424" severity="Low" type="CVE"><desc><descript source="cve">talkback in Netscape 4.5 allows a local user to overwrite arbitrary files of another user whose Netscape crashes.</descript></desc><loss_types><conf/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2006.php">netscape-talkback-overwrite(2006)</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0425" published="1999-03-18" seq="1999-0425" severity="Medium" type="CVE"><desc><descript source="cve">talkback in Netscape 4.5 allows a local user to kill an arbitrary process of another user whose Netscape crashes.</descript></desc><loss_types><avail/><int/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2005.php">netscape-talkback-kill(2005)</ref><ref adv="1" source="SuSE Linux" url="http://www.suse.de/de/support/security/suse_security_announce_2.txt">19.03.1999</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0426" published="1999-03-01" seq="1999-0426" severity="High" type="CVE"><desc><descript source="cve">The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3500.php">linux-dev-kmem-spoof</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="6.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0427" published="2000-05-01" seq="1999-0427" severity="High" type="CVE"><desc><descript source="cve">Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4482.php">eudora-long-attachment-filename(4482)</ref><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/1210">BID 1210</ref></refs><vuln_soft><prod name="Eudora" vendor="Qualcomm"><vers num="4.3"/><vers num="4.2"/></prod><prod name="Eudora Light" vendor="Qualcomm"><vers num="3.0"/></prod><prod name="Eudora Pro" vendor="Qualcomm"><vers num="1.00"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0428" published="1999-03-22" seq="1999-0428" severity="High" type="CVE"><desc><descript source="cve">OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1991.php">ssl-session-reuse(1991)</ref><ref patch="1" source="OpenSSL" url="http://www.openssl.org/news/announce.html"></ref><ref adv="1" patch="1" source="Listserv at NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9903d&amp;L=bugtraq&amp;F=&amp;S=&amp;P=65">OpenSSL and SSLeay Security Alert</ref><ref source="OSVDB" url="http://www.osvdb.org/3936">3936</ref></refs><vuln_soft><prod name="OpenSSL" vendor="OpenSSL Project"><vers num=""/></prod><prod name="SSLeay" vendor="SSLeay"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0429" published="1999-03-01" seq="1999-0429" severity="High" type="CVE"><desc><descript source="cve">The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the &quot;Encrypt Saved Mail&quot; preference.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2047.php">lotus-client-encryption(2047)</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92221437025743&amp;w=2">19990323</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92241547418689&amp;w=2">19990324 Re: LNotes encryption</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92246997917866&amp;w=2">19990326 Lotus Notes Encryption Bug</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92249282302994&amp;w=2">19990326 Re: Lotus Notes security advisory</ref></refs><vuln_soft><prod name="Lotus Notes" vendor="IBM"><vers num="4.5"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0430" published="1999-03-01" seq="1999-0430" severity="Medium" type="CVE"><desc><descript source="cve">Cisco Catalyst LAN switches running Catalyst 5000 supervisor software allows remote attackers to perform a denial of service by forcing the supervisor module to reload.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/705">bugtraq id 705</ref><ref adv="1" patch="1" source="Cisco" url="http://securityfocus.com/templates/advisory.html?id=1770">CI-99.03</ref><ref adv="1" patch="1" source="Cisco" url="http://www.cisco.com/warp/public/707/sec_incident_response.shtml"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2019.php">cisco-catalyst-crash(2019)</ref><ref source="OSVDB" url="http://www.osvdb.org/1103">1103</ref></refs><vuln_soft><prod name="Catalyst 29xx supervisor software" vendor="Cisco"><vers num="2.1.502"/><vers num="2.1.501"/><vers num="2.1.5"/><vers num="1.0"/></prod><prod name="Catalyst 12xx supervisor software" vendor="Cisco"><vers num="4.29"/></prod><prod name="Catalyst 5xxx supervisor software" vendor="Cisco"><vers num="2.1.502"/><vers num="2.1.501"/><vers num="2.1.5"/><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0" modified="2007-07-09" name="CVE-1999-0431" published="1999-03-01" seq="1999-0431" severity="Medium" type="CVE"><desc><descript source="cve">Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.</descript></desc><sols><sol source="nvd">This problem was fixed in Linux kernel 2.2.4 and later releases.</sol></sols><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2041.php">linux-zerolength-fragment(2041)</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.1.89"/><vers num="2.2"/><vers num="2.2.10"/><vers num="2.2.12"/><vers num="2.2.13"/><vers num="2.2.14"/><vers num="2.2.15"/><vers num="2.2.15 pre16"/><vers num="2.2.15 pre20"/><vers num="2.2.16"/><vers num="2.2.16 pre6"/><vers num="2.2.3" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0432" published="1999-03-01" seq="1999-0432" severity="Medium" type="CVE"><desc><descript source="cve">ftp on HP-UX 11.00 allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2009.php">hp-ftp(2009)</ref><ref adv="1" source="HP.com" url="http://us-support.external.hp.com/index.html"></ref><ref adv="1" patch="1" source="HP.com" url="http://us-support.external.hp.com/cki/bin/doc.pl/sid=46ddf44e169cfc3383/screen=ckiDisplayDocument?docId=400000000240811">HPSBUX9903-094</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-094">HPSBUX9903-094</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0433" published="1999-03-21" seq="1999-0433" severity="Medium" type="CVE"><desc><descript source="cve">XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/326">BID 326</ref><ref patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.NEB.4.02.9903212108120.5403-100000@stinky"></ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=14075.60480.760010.181394@gargle.gargle.HOWL"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2032.php">xfree86-temp-directories(2032)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers edition="i386" num="5.2"/><vers num="5.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="6.1"/><vers num="6.0"/><vers num="5.2"/><vers num="5.1"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3"/><vers num="1.3.2"/></prod><prod name="X11R6" vendor="XFree86 Project"><vers num="3.3.3"/></prod><prod name="Slackware Linux" vendor="Slackware"><vers num="4.0"/><vers num="3.6"/><vers num="3.5"/><vers num="3.4"/><vers num="3.3"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0434" published="1999-03-30" seq="1999-0434" severity="High" type="CVE"><desc><descript source="cve">XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/359">Multiple Vendor xfs Symlink Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3502.php">xfree86-xfs-symlink-dos</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="5.1"/></prod><prod name="SuSE Linux" vendor="SuSE"><vers num="5.3"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num="1.2"/></prod><prod name="Debian Linux" vendor="Debian"><vers num="2.0r5"/><vers num="2.1"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0435" published="1999-03-01" seq="1999-0435" severity="High" type="CVE"><desc><descript source="cve">MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2046.php">hp-serviceguard(2046)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-8.php">hp-serviceguard</ref></refs><vuln_soft><prod name="HP-UX" vendor="HP"><vers num="10.0"/><vers num="10.0.1"/><vers num="10.1"/><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0436" published="1999-03-01" seq="1999-0436" severity="Medium" type="CVE"><desc><descript source="cve">Domain Enterprise Server Management System (DESMS) in HP-UX allows local users to gain privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2045.php">hp-desms-servers(2045)</ref><ref adv="1" source="HP.com" url="http://us-support.external.hp.com/index.html"></ref><ref adv="1" patch="1" source="HP.com" url="http://us-support.external.hp.com/cki/bin/doc.pl/sid=74be24a31db1e23efe/screen=ckiDisplayDocument?docId=400000000241129">HPSBUX9903-095</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-095">HPSBUX9903-095</ref></refs><vuln_soft><prod name="DESMS" vendor="HP"><vers num=""/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.20"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0437" published="1999-03-01" seq="1999-0437" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service in WebRamp systems by sending a malicious string to the HTTP port.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2050.php">webramp-device-crash(2050)</ref></refs><vuln_soft><prod name="WebRamp" vendor="Ramp Networks"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0438" published="1999-03-01" seq="1999-0438" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service in WebRamp systems by sending a malicious UDP packet to port 5353, changing its IP address.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/577">bugtraq id 577</ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.SUN.3.96.990803112821.17628B-100000@grex.cyberspace.org"></ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=000d01bee028$2fa68b30$9a65fdcf@slacky"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2051.php">webramp-ipchange(2051)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/advise25.php"></ref></refs><vuln_soft><prod name="WebRamp M3" vendor="Ramp Networks"><vers num="1.0"/></prod><prod name="WebRamp 200i" vendor="Ramp Networks"><vers num="1.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0439" published="1999-04-05" seq="1999-0439" severity="High" type="CVE"><desc><descript source="cve">Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2082.php">procmail-overflow(2082)</ref><ref patch="1" source="procmail.org" url="http://www.procmail.org/"></ref><ref adv="1" patch="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904a&amp;L=bugtraq&amp;D=0&amp;P=2003"></ref></refs><vuln_soft><prod name="procmail" vendor="procmail"><vers num="3.12" prev="1"/></prod><prod name="OpenLinux" vendor="Caldera"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0440" published="1999-03-01" seq="1999-0440" severity="High" type="CVE"><desc><descript source="cve">The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2025.php">java-unverified-code(2025)</ref><ref source="CONFIRM" url="http://java.sun.com/pr/1999/03/pr990329-01.html">http://java.sun.com/pr/1999/03/pr990329-01.html</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92333596624452&amp;w=2">19990405 Security Hole in Java 2 (and JDK 1.1.x)</ref><ref source="BID" url="http://www.securityfocus.com/bid/1939">1939</ref></refs><vuln_soft><prod name="Communicator" vendor="Netscape"><vers num="4.5"/></prod><prod name="Navigator" vendor="Netscape"><vers num="4.0"/><vers num="4.01"/><vers num="4.02"/><vers num="4.03"/><vers num="4.04"/><vers num="4.05"/><vers num="4.06"/><vers num="4.07"/><vers num="4.08"/><vers num="4.5"/><vers num="4.61"/></prod><prod name="Java" vendor="Sun"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0441" published="1999-02-22" seq="1999-0441" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/509">bugtraq id 509</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/advisory.html?id=1594">AD02221999</ref><ref patch="1" source="deerfield.com" url="http://wingate.deerfield.com/support/index.cfm"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2066.php">wingate-redirector-dos(2066)</ref><ref source="EEYE" url="http://www.eeye.com/html/Research/Advisories/AD02221999.html">AD02221999</ref><ref source="BID" url="http://www.securityfocus.com/bid/509">509</ref></refs><vuln_soft><prod name="WinGate" vendor="Qbik"><vers num="3.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0442" published="1999-01-07" seq="1999-0442" severity="Low" type="CVE"><desc><descript source="cve">Solaris ff.core allows local users to modify files.</descript></desc><loss_types><int/></loss_types><vuln_types><access/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/327">BID 327</ref><ref patch="1" source="SUN" url="http://sunsolve.sun.com/pub-cgi/show.pl?target=patches/patch-access"></ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.GSO.4.05.9901081235340.880-100000@naur.csee.wvu.edu"></ref><ref patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=199901151320.OAA11141@romulus"></ref><ref adv="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.OSF.4.05.9901070946310.11222-100000@osprey.unf.edu"></ref><ref source="BID" url="http://www.securityfocus.com/bid/327">327</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="7.0"/><vers num="7.0"/><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0443" published="1999-04-01" seq="1999-0443" severity="High" type="CVE"><desc><descript source="cve">Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2078.php">bmc-patrol-replay(2078)</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/archive/1/13204">19990409 Patrol security bugs</ref></refs><vuln_soft><prod name="PATROL Agent" vendor="BMC Software"><vers num="3.2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0444" published="1999-04-12" seq="1999-0444" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3328.php">windows-arp-dos</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/archive/1/13232"></ref></refs><vuln_soft><prod name="Windows 98" vendor="Microsoft"><vers num="a"/></prod><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0445" published="1999-04-01" seq="1999-0445" severity="Medium" type="CVE"><desc><descript source="cve">In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/706">BID 706</ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/templates/advisory.html?id=1429"></ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2071.php">cisco-natacl-leakage(2071)</ref><ref source="OSVDB" url="http://www.osvdb.org/1104">1104</ref></refs><vuln_soft><prod name="IOS" vendor="Cisco"><vers num="12.0.2XG"/><vers num="12.0.2XF"/><vers num="12.0.2XD"/><vers num="12.0.2XC"/><vers num="12.0.1XE"/><vers num="12.0.1XB"/><vers num="12.0.1XA3"/><vers num="12.0.1W"/><vers num="12.0T"/><vers num="12.0S"/><vers num="12.0DB"/><vers num="12.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0446" published="1999-04-12" seq="1999-0446" severity="Low" type="CVE"><desc><descript source="cve">Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2062.php">netbsd-vfslocking-panic(2062)</ref><ref adv="1" patch="1" source="NetBSD" url="ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-008.txt.asc">1999-008</ref><ref source="OSVDB" url="http://www.osvdb.org/7051">7051</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.1"/><vers num="1.3.3"/><vers num="1.3.2"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0447" published="1999-04-01" seq="1999-0447" severity="Medium" type="CVE"><desc><descript source="cve">Local users can gain privileges using the debug utility in the MPE/iX operating system.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2073.php">mpeix-debug(2073)</ref><ref adv="1" source="HP.com" url="http://us-support.external.hp.com/cki/bin/doc.pl/sid=22660f44193e555c40/screen=ckiDisplayDocument?docId=400000000241549">HPSBMP9904-006</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBMP9904-006">HPSBMP9904-006</ref></refs><vuln_soft><prod name="MPE iX" vendor="HP"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0448" published="1999-01-01" seq="1999-0448" severity="Medium" type="CVE"><desc><descript source="cve">IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.</descript></desc><loss_types><conf/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/191">bugtraq id 191</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1656.php">iis-http-request-logging(1656)</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.8" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.9" CVSS_score="7.8" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:C)" CVSS_version="2.0 incomplete approximation" modified="2006-11-16" name="CVE-1999-0449" published="1999-01-26" seq="1999-0449" severity="High" type="CVE"><desc><descript source="cve">The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/193">bugtraq id 193</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2229.php">iis-exair-dos(2229)</ref><ref source="BID" url="http://www.securityfocus.com/bid/193">193</ref><ref source="OSVDB" url="http://www.osvdb.org/2">2</ref><ref source="OSVDB" url="http://www.osvdb.org/3">3</ref><ref source="OSVDB" url="http://www.osvdb.org/4">4</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0450" published="1999-01-26" seq="1999-0450" severity="High" type="CVE"><desc><descript source="cve">In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe) .</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref source="BID" url="http://www.securityfocus.com/bid/194">194</ref></refs><vuln_soft><prod name="IIS" vendor="Microsoft"><vers num="5.0"/><vers num="4.0"/><vers num="3.0"/><vers num="2.0"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0451" published="1999-01-19" seq="1999-0451" severity="Low" type="CVE"><desc><descript source="cve">Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/343">Linux TCP port DoS Vulnerability</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0"/><vers num="2.2"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0452" published="1999-01-01" seq="1999-0452" severity="High" type="CVE"><desc><descript source="cve">A service or application has a backdoor password that was placed there by the developer.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0" modified="2008-08-20" name="CVE-1999-0453" published="1999-01-01" seq="1999-0453" severity="Medium" type="CVE"><desc><descript source="cve">An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).</descript></desc><loss_types><conf/></loss_types><range><network/></range><refs/><vuln_soft><prod name="Cisco router" vendor="Cisco"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0454" published="1999-01-01" seq="1999-0454" severity="High" type="CVE"><desc><descript source="cve">A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0455" published="1999-12-25" seq="1999-0455" severity="High" type="CVE"><desc><descript source="cve">The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1740.php">coldfusion-expression-evaluator(1740)</ref><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/115">Allaire ColdFusion Remote File Display, Deletion, Upload and Execution Vulnerability</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0457" published="1999-01-17" seq="1999-0457" severity="High" type="CVE"><desc><descript source="cve">Linux ftpwatch program allows local users to gain root privileges.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/317">bugtraq id 317</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.GSO.3.96.990217191538.18872B-100000@borg"></ref><ref patch="1" source="Debian" url="http://cgi.debian.org/www-master/debian.org/Packages/stable/net/ftpwatch"></ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1607.php">ftpwatch-vuln(1607)</ref><ref source="BID" url="http://www.securityfocus.com/bid/317">317</ref></refs><vuln_soft><prod name="Debian Linux" vendor="Debian"><vers num="2.0"/><vers num="1.3.1"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0458" published="1999-01-06" seq="1999-0458" severity="Low" type="CVE"><desc><descript source="cve">L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1606.php">l0phtcrack-temp-files(1606)</ref><ref patch="1" source="L0pht" url="http://www.l0pht.com/l0phtcrack/"></ref><ref adv="1" patch="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9901A&amp;L=bugtraq&amp;P=R7175"></ref><ref source="OSVDB" url="http://www.osvdb.org/915">915</ref></refs><vuln_soft><prod name="L0phtCrack" vendor="L0pht"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0459" published="1999-02-01" seq="1999-0459" severity="Medium" type="CVE"><desc><descript source="cve">Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1717.php">linux-milo-halt(1717)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/alerts/vol-3_num-5.php">linux-milo-halt(1717)</ref></refs></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0460" published="1999-02-19" seq="1999-0460" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="Security Focus" url="http://www.securityfocus.com/bid/312">Linux autofs Vulnerability</ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num="2.0"/><vers num="2.1"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0461" published="1999-01-28" seq="1999-0461" severity="High" type="CVE"><desc><descript source="cve">Versions of rpcbind including Linux, IRIX, and Wietse Venema&apos;s rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2308.php">pmap-sset(2308)</ref><ref adv="1" patch="1" source="Netspace" url="http://www.netspace.org/cgi-bin/wa?A2=ind9901E&amp;L=bugtraq&amp;P=R125"></ref></refs><vuln_soft><prod name="Kernel" vendor="Linux"><vers num=""/></prod><prod name="IRIX" vendor="SGI"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0462" published="1999-03-17" seq="1999-0462" severity="High" type="CVE"><desc><descript source="cve">suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/339">Perl suidmount Vulnerability</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3544.php">perl-suidperl-bo(3544)</ref></refs><vuln_soft><prod name="SuSE Linux" vendor="SuSE"><vers num="5.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0463" published="1998-12-01" seq="1999-0463" severity="Medium" type="CVE"><desc><descript source="cve">Remote attackers can perform a denial of service using IRIX fcagent.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/144">bugtraq id 144</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1443.php">sgi-fcagent-dos(1443)</ref><ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981201-01-PX">19981201-01-PX</ref></refs><vuln_soft><prod name="L0phtCrack" vendor="L0pht"><vers num="2.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0464" published="1999-01-04" seq="1999-0464" severity="Low" type="CVE"><desc><descript source="cve">Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.</descript></desc><loss_types><avail/></loss_types><vuln_types><input bound="1"/></vuln_types><range><local/></range><refs><ref adv="1" source="MARC" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91592136122066&amp;w=2"></ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91553066310826&amp;w=2">19990104 Tripwire mess..</ref><ref source="OSVDB" url="http://www.osvdb.org/6609">6609</ref></refs><vuln_soft><prod name="Tripwire" vendor="Tripwire"><vers num="1.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0465" published="1999-01-01" seq="1999-0465" severity="High" type="CVE"><desc><descript source="cve">Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0466" published="1999-04-21" seq="1999-0466" severity="High" type="CVE"><desc><descript source="cve">The SVR4 /dev/wabi special device file in NetBSD 1.3.3 and earlier allows a local user to read or write arbitrary files on the disk associated with that device.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><access/><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/114">bugtraq id 114</ref><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/templates/advisory.html?id=328">NetBSD-SA1999-009</ref><ref source="OSVDB" url="http://www.osvdb.org/905">905</ref></refs><vuln_soft><prod name="NetBSD" vendor="NetBSD"><vers num="1.3.3"/><vers num="1.3.2"/><vers num="1.3.1"/><vers num="1.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0467" published="1999-04-01" seq="1999-0467" severity="Medium" type="CVE"><desc><descript source="cve">The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the &quot;template&quot; parameter.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2072.php">http-cgi-webcom-guestbook(2072)</ref></refs><vuln_soft><prod name="CGI Guestbook" vendor="Webcom"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0468" published="1999-04-09" seq="1999-0468" severity="Low" type="CVE"><desc><descript source="cve">Internet Explorer 5.0 allows a remote server to read arbitrary files on the client&apos;s file system using the Microsoft Scriptlet Component.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2070.php">ie-scriplet-fileread(2070)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904b&amp;L=bugtraq&amp;F=&amp;S=&amp;P=1504"></ref><ref patch="1" source="Microsoft" url="http://support.microsoft.com/support/kb/articles/q226/3/25.asp"></ref><ref adv="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS99-012</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/windows/ie/security/mshtml.asp">MSHTML</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0469" published="1999-04-01" seq="1999-0469" severity="Medium" type="CVE"><desc><descript source="cve">Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.</descript></desc><loss_types><conf/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2069.php">ie-window-spoof</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-07-27" name="CVE-1999-0470" published="1999-04-09" seq="1999-0470" severity="Medium" type="CVE"><desc><descript source="cve">A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.</descript></desc><loss_types><conf/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2081.php">netware-remotenlm-passwords(2081)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904B&amp;L=bugtraq&amp;P=R1516"></ref><ref source="BID" url="http://www.securityfocus.com/bid/482">482</ref></refs><vuln_soft><prod name="NetWare" vendor="Novell"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0471" published="1999-04-09" seq="1999-0471" severity="Medium" type="CVE"><desc><descript source="cve">The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the &quot;cancel&quot; button.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2079.php">winroute-config(2079)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904B&amp;L=bugtraq&amp;P=R1283"></ref><ref patch="1" source="TINY Software" url="http://www.winroute.com/"></ref></refs><vuln_soft><prod name="WinRoute" vendor="WinRoute"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2006-09-21" name="CVE-1999-0472" published="1999-04-07" seq="1999-0472" severity="Medium" type="CVE"><desc><descript source="cve">The SNMP default community name &quot;public&quot; is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2080.php">netcache-snmp(2080)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904A&amp;L=bugtraq&amp;P=R4014"></ref></refs><vuln_soft><prod name="SNMP" vendor="SNMP"><vers num=""/></prod><prod name="NetCache" vendor="Network Appliance"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0473" published="1999-04-07" seq="1999-0473" severity="Low" type="CVE"><desc><descript source="cve">The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client&apos;s working directory to the permissions of the directory being transferred.</descript></desc><loss_types><int/></loss_types><vuln_types><env/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2074.php">rsync-permissions(2074)</ref><ref adv="1" patch="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904A&amp;L=bugtraq&amp;P=R3834"></ref><ref adv="1" patch="1" source="Debian" url="http://www.debian.org/security/1999/19990823">19990823</ref><ref source="BID" url="http://www.securityfocus.com/bid/145">145</ref></refs><vuln_soft><prod name="rsync" vendor="Andrew Tridgell"><vers num="2.3.1" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0474" published="1999-04-05" seq="1999-0474" severity="Medium" type="CVE"><desc><descript source="cve">The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user&apos;s personal directory.</descript></desc><loss_types><conf/></loss_types><vuln_types><access/><config/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2085.php">icq-webserver-read(2085)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904a&amp;L=bugtraq&amp;F=&amp;S=&amp;P=3795"></ref><ref patch="1" source="Mirabilis ICQ" url="http://www.icq.com/download/"></ref></refs><vuln_soft><prod name="ICQ" vendor="Mirabilis"><vers num="99a 2.13Build1700"/></prod></vuln_soft></entry><entry CVSS_base_score="1.2" CVSS_exploit_subscore="1.9" CVSS_impact_subscore="2.9" CVSS_score="1.2" CVSS_vector="(AV:L/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-09-08" name="CVE-1999-0475" published="1999-04-05" seq="1999-0475" severity="Low" type="CVE"><desc><descript source="cve">A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.</descript></desc><loss_types><conf/></loss_types><vuln_types><race/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2083.php">procmail-race(2083)</ref><ref adv="1" source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9904a&amp;L=bugtraq&amp;F=&amp;S=&amp;P=4470"></ref></refs><vuln_soft><prod name="procmail" vendor="procmail"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0476" published="1999-03-01" seq="1999-0476" severity="High" type="CVE"><desc><descript source="cve">A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2063.php">sco-termvision-password(2063)</ref></refs><vuln_soft><prod name="OpenServer" vendor="SCO"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0477" published="1999-12-25" seq="1999-0477" severity="High" type="CVE"><desc><descript source="cve">The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://www.securityfocus.com/bid/115">Allaire ColdFusion Remote File Display, Deletion, Upload and Execution Vulnerability</ref></refs><vuln_soft><prod name="ColdFusion Server" vendor="Allaire"><vers num="2.0"/><vers num="3.0"/><vers num="3.01"/><vers num="3.11"/><vers num="3.12"/><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0478" published="1998-12-01" seq="1999-0478" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2300.php">sendmail-headers-dos(2300)</ref><ref adv="1" source="Bugtraq" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1998-12-08&amp;msg=Pine.LNX.4.05.9812121913580.294-200000@nimue.ids.pl"></ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9904-097">HPSBUX9904-097</ref></refs><vuln_soft><prod name="Sendmail" vendor="Sendmail Consortium"><vers num="8.9.2" prev="1"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-09-05" name="CVE-1999-0479" published="1999-03-01" seq="1999-0479" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1964.php">netscape-server-dos(1964)</ref><ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9903-092">HPSBUX9903-092</ref></refs><vuln_soft><prod name="Netscape Enterprise Server" vendor="Netscape"><vers num="3.6"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.24"/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0480" published="1999-04-01" seq="1999-0480" severity="Low" type="CVE"><desc><descript source="cve">Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3505.php">midnight-commander-symlink-dos(3505)</ref></refs><vuln_soft><prod name="Midnight Commander" vendor="Midnight Commander"><vers num="4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-12" name="CVE-1999-0481" published="1999-03-22" seq="1999-0481" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in &quot;poll&quot; in OpenBSD.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.htmlpoll"></ref><ref source="OSVDB" url="http://www.osvdb.org/7556">7556</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0482" published="1999-03-21" seq="1999-0482" severity="Medium" type="CVE"><desc><descript source="cve">OpenBSD kernel crash through TSS handling, as caused by the crashme program.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.htmltss"></ref><ref source="OSVDB" url="http://www.osvdb.org/7557">7557</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0483" published="1999-02-25" seq="1999-0483" severity="Low" type="CVE"><desc><descript source="cve">OpenBSD crash using nlink value in FFS and EXT2FS filesystems.</descript></desc><loss_types><avail/></loss_types><range><local/></range><refs><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.htmltss"></ref><ref source="OSVDB" url="http://www.osvdb.org/6129">6129</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.1" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="2.9" CVSS_score="2.1" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0484" published="1999-02-23" seq="1999-0484" severity="Low" type="CVE"><desc><descript source="cve">Buffer overflow in OpenBSD ping.</descript></desc><loss_types><int/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><local/></range><refs><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.html"></ref><ref source="OSVDB" url="http://www.osvdb.org/6130">6130</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0485" published="1999-02-19" seq="1999-0485" severity="Low" type="CVE"><desc><descript source="cve">Remote attackers can cause a system crash through ipintr() in ipq in OpenBSD.</descript></desc><loss_types><avail/></loss_types><vuln_types><race/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1829.php">openbsd-ipintr-race(1829)</ref><ref patch="1" source="OpenBSD" url="http://www.openbsd.org/errata24.htmltss"></ref><ref source="OSVDB" url="http://www.osvdb.org/7558">7558</ref></refs><vuln_soft><prod name="OpenBSD" vendor="OpenBSD"><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0486" published="1998-02-01" seq="1999-0486" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash.</descript></desc><loss_types><avail/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/4877.php">aolim-malformed-ascii-dos(4877)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/819.php">aol-im(819)</ref></refs><vuln_soft><prod name="Instant Messenger" vendor="AOL"><vers num="3.5"/></prod></vuln_soft></entry><entry CVSS_base_score="2.6" CVSS_exploit_subscore="4.9" CVSS_impact_subscore="2.9" CVSS_score="2.6" CVSS_vector="(AV:N/AC:H/Au:N/C:P/I:N/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0487" published="1999-05-01" seq="1999-0487" severity="Low" type="CVE"><desc><descript source="cve">The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files.</descript></desc><loss_types><conf/></loss_types><vuln_types><env/></vuln_types><range><network/><user_init/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/116">bugtraq id 116</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-011.asp">MS99-011</ref><ref source="Cuartango" url="http://pages.whowhere.com/computers/cuartangojc/dhtmle1.html"></ref><ref adv="1" patch="1" source="Microsoft Knowledge Base" url="http://support.microsoft.com/support/kb/articles/q226/3/26.asp">q226326</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2161.php">ie-dhtml-control(2161)</ref><ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-011.mspx">MS99-011</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="5.0"/><vers num="4.0.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0488" published="1999-04-21" seq="1999-0488" severity="High" type="CVE"><desc><descript source="cve">Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the &quot;cross frame&quot; vulnerability.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2216.php">ie-mshtml-crossframe(2216)</ref><ref adv="1" patch="1" source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS99-012</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/><vers num="4.0.0.1"/><vers num="4.0.0.1SP1"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0489" published="1999-05-17" seq="1999-0489" severity="High" type="CVE"><desc><descript source="cve">MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of &quot;untrusted scripted paste&quot; as described in MS:MS98-013.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-015.asp">MS:MS99-015</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0490" published="1999-04-21" seq="1999-0490" severity="High" type="CVE"><desc><descript source="cve">MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user&apos;s files via an IMG SRC tag.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2070.php">ie-scriplet-fileread</ref><ref adv="1" patch="1" source="Microsoft" url="http://www.microsoft.com/technet/security/bulletin/ms99-012.asp">MS:MS99-012</ref></refs><vuln_soft><prod name="Internet Explorer" vendor="Microsoft"><vers num="4.0.0"/><vers num="5.0"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2006-08-23" name="CVE-1999-0491" published="1999-04-20" seq="1999-0491" severity="Medium" type="CVE"><desc><descript source="cve">The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><input/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/119">bugtraq id 119</ref><ref adv="1" patch="1" source="Caldera" url="ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-008.0.txt">CSSA-1999:008.0</ref><ref source="BUGTRAQ" url="http://www.securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.4.10.9904202114070.6623-100000@smooth.Operator.org">19990420 Bash Bug</ref><ref source="BID" url="http://www.securityfocus.com/bid/119">119</ref></refs><vuln_soft><prod name="bash" vendor="bash"><vers num="1.14"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0492" published="1999-04-23" seq="1999-0492" severity="High" type="CVE"><desc><descript source="cve">The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0493" published="1999-06-07" seq="1999-0493" severity="High" type="CVE"><desc><descript source="cve">rpc.statd allows remote attackers to forward RPC calls to the local operating system via the SM_MON and SM_NOTIFY commands, which in turn could be used to remotely exploit other bugs such as in automountd.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><access/><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="Security Focus" url="http://securityfocus.com/bid/450">BID 450</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05-statd-automountd</ref><ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/186&amp;type=0&amp;nav=sec.sba">00186</ref><ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-045.shtml">J-045</ref><ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref><ref source="BID" url="http://www.securityfocus.com/bid/450">450</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/><vers num="2.3"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0494" published="1998-07-01" seq="1999-0494" severity="Medium" type="CVE"><desc><descript source="cve">Denial of service in WinGate proxy through a buffer overflow in POP3.</descript></desc><loss_types><avail/></loss_types><vuln_types><input buffer="1"/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1847.php">wingate-pop3-user-bo(1847)</ref><ref source="NETSPACE.ORG" url="http://www.netspace.org/cgi-bin/wa?A2=ind9807A&amp;L=bugtraq&amp;F=&amp;S=&amp;P=4317"></ref></refs><vuln_soft><prod name="WinGate" vendor="WinGate"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0495" published="1999-01-01" seq="1999-0495" severity="High" type="CVE"><desc><descript source="cve">A remote attacker can gain access to a file system using ..  (dot dot) when accessing SMB shares.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0496" published="1997-01-01" seq="1999-0496" severity="Medium" type="CVE"><desc><descript source="cve">A Windows NT 4.0 user can gain administrative rights by forcing NtOpenProcessToken to succeed regardless of the user&apos;s permissions, aka GetAdmin.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="Microsoft Knowledge Base" url="http://support.microsoft.com/support/kb/articles/q146/9/65.ASP">q146965</ref><ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;Q146965">Q146965</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num="4.0"/></prod></vuln_soft></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2007-07-13" name="CVE-1999-0497" published="1999-01-01" seq="1999-0497" severity="Low" type="CVE"><desc><descript source="cve">Anonymous FTP is enabled.</descript></desc><impacts><impact source="nvd">This Common Vulnerabilities and Exposures (CVE) entry is a configuration issue and not a software flaw. As such, it doesn’t fit in the CVE software flaw list. The Common Vulnerability Scoring System (CVSS) base score for this CVE entry has been set to 0 because this CVE entry has no impact as a software flaw according to CVSS. This does not mean that the configuration issue is not important and there may be security implications relative to computers having this configuration.</impact></impacts><sols><sol source="nvd">Anonymous FTP is an unsecured protocol for Internet facing systems and should only be used on a limited basis to provide a specific functional requirement, otherwise disabled.  The software should be patched and configured properly.</sol></sols><vuln_types><other/></vuln_types><range><network/></range><refs/></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0498" published="1991-09-27" seq="1999-0498" severity="High" type="CVE"><desc><descript source="cve">TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/308.php">linux-tftp(308)</ref><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1991-18.html">CERT:CA-91.18.Active.Internet.tftp.Attacks</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0499" published="1997-01-01" seq="1999-0499" severity="High" type="CVE"><desc><descript source="cve">NETBIOS share information may be published through SNMP registry keys in NT.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/215.php">snmp-netbios</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0501" published="1998-06-01" seq="1999-0501" severity="Medium" type="CVE"><desc><descript source="cve">A Unix account has a guessable password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><config/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1005.php">default-unix-lp(1005)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0502" published="1998-03-01" seq="1999-0502" severity="High" type="CVE"><desc><descript source="cve">A Unix account has a default, null, blank, or missing password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/774.php">passwd-blank(774)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2941.php">passwd-blank-lines(2941)</ref></refs><vuln_soft><prod name="Linux" vendor="Red Hat"><vers num="6.0"/></prod><prod name="Solaris" vendor="Sun"><vers num="2.5.1"/><vers num="2.6"/><vers num="7.0"/><vers num="8.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="10.20"/><vers num="11"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0503" published="1997-01-01" seq="1999-0503" severity="High" type="CVE"><desc><descript source="cve">A Windows NT local user or administrator account has a guessable password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/282.php">nt-guess-admin(282)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1328.php">nt-guessed-powerwd(1328)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0504" published="1997-01-01" seq="1999-0504" severity="High" type="CVE"><desc><descript source="cve">A Windows NT local user or administrator account has a default, null, blank, or missing password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot user="1"/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/159.php">nt-guestblankpw(159)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/163.php">nt-guestnopw</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0505" published="1998-10-01" seq="1999-0505" severity="High" type="CVE"><desc><descript source="cve">A Windows NT domain user or administrator account has a guessable password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1329.php">nt-guessed-domain-userpwd(1329)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3421.php">win2k-certpub-usrpwd(3421)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0506" published="1998-10-01" seq="1999-0506" severity="High" type="CVE"><desc><descript source="cve">A Windows NT domain user or administrator account has a default, null, blank, or missing password.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1"/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1355.php">nt-domain-admin-blankpwd(1355)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/3422.php">win2k-dhcpadm-blnkpwd(3422)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0507" published="1998-04-01" seq="1999-0507" severity="High" type="CVE"><desc><descript source="cve">An account on a router, firewall, or other network device has a guessable password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/388.php">firewall-tisopen(388)</ref></refs></entry><entry CVSS_base_score="4.6" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="6.4" CVSS_score="4.6" CVSS_vector="(AV:L/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0508" published="1998-06-01" seq="1999-0508" severity="Medium" type="CVE"><desc><descript source="cve">An account on a router, firewall, or other network device has a default, null, blank, or missing password.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/><other/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/980.php">default-netranger(980)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/2002.php">motorola-cable-default-pass</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/1816.php">cayman-gatorbox</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0509" published="1996-05-29" seq="1999-0509" severity="High" type="CVE"><desc><descript source="cve">Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-1996-11.html">CERT:CA-96.11</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0510" published="1997-01-01" seq="1999-0510" severity="High" type="CVE"><desc><descript source="cve">A router or firewall allows source routed packets from arbitrary hosts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><other/></vuln_types><range><network/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/639.php">source-routing(639)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/3577.php">source-routing-disable(3577)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0511" published="1997-01-01" seq="1999-0511" severity="High" type="CVE"><desc><descript source="cve">IP forwarding is enabled on a machine which is not a router or firewall.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/193.php">ip-forwarding(193)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0512" published="1999-01-01" seq="1999-0512" severity="High" type="CVE"><desc><descript source="cve">A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0513" published="1998-01-05" seq="1999-0513" severity="Medium" type="CVE"><desc><descript source="cve">ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.</descript></desc><loss_types><avail/></loss_types><range><network/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-98.01.smurf.html">CA-98.01</ref><ref adv="1" patch="1" source="Bugtraq" url="http://securityfocus.com/templates/archive.pike?list=1&amp;msg=Pine.LNX.3.91.971012142256.3522B-100000@tap.net"></ref><ref adv="1" source="Security Focus" url="http://securityfocus.com/bid/147">BID 147</ref><ref adv="1" source="Craig Huegen" url="http://users.quadrunner.com/chuegen/smurf.txt"></ref></refs><vuln_soft><prod name="FreeBSD" vendor="FreeBSD"><vers num="2.2.4"/><vers num="2.2.3"/><vers num="2.2.2"/><vers num="2.1.7.1"/><vers num="2.1.6"/><vers num="2.1.5"/><vers num="2.1.0"/><vers num="2.0.5"/><vers num="1.1.5.1"/></prod><prod name="AIX" vendor="IBM"><vers num="3.2.5"/><vers num="3.2.4"/><vers num="3.2"/><vers num="3.1"/></prod><prod name="Kernel" vendor="Linux"><vers num="2.1"/><vers num="2.0"/></prod><prod name="UNIX" vendor="Digital"><vers num="4.0D"/><vers num="4.0C"/><vers num="4.0B"/><vers num="4.0A"/><vers num="4.0"/><vers num="3.2G"/></prod><prod name="NetBSD" vendor="NetBSD"><vers num="1.2"/></prod><prod name="HP-UX" vendor="HP"><vers num="11.0"/><vers num="10.20"/></prod><prod name="Solaris" vendor="Sun"><vers edition="x86" num="2.6"/><vers num="2.6"/><vers edition="x86" num="2.5.1"/><vers edition="ppc" num="2.5.1"/><vers num="2.5.1"/><vers edition="x86" num="2.5"/><vers num="2.5"/><vers edition="x86" num="2.4"/><vers num="2.4"/></prod></vuln_soft></entry><entry CVSS_base_score="5.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="2.9" CVSS_score="5.0" CVSS_vector="(AV:N/AC:L/Au:N/C:N/I:N/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-05-02" name="CVE-1999-0514" published="1998-03-01" seq="1999-0514" severity="Medium" type="CVE"><desc><descript source="cve">UDP messages to broadcast addresses are allowed, allowing for a Fraggle attack that can cause a denial of service by flooding the target.</descript></desc><loss_types><avail/></loss_types><vuln_types><input/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/815.php">fraggle(815)</ref><ref adv="1" source="Craig Huegen" url="http://users.quadrunner.com/chuegen/smurf.txt"></ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0515" published="1999-01-01" seq="1999-0515" severity="High" type="CVE"><desc><descript source="cve">An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0516" published="1998-08-01" seq="1999-0516" severity="High" type="CVE"><desc><descript source="cve">An SNMP community name is guessable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1241.php">snmp-get-guess(1241)</ref></refs></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0517" published="1997-01-01" seq="1999-0517" severity="High" type="CVE"><desc><descript source="cve">An SNMP community name is the default (e.g. public), null, or missing.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1387.php">hpov-hidden-snmp-comm(1387)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/133.php">snmp-comm(133)</ref></refs><vuln_soft><prod name="Solaris" vendor="Sun"><vers num="2.0"/></prod><prod name="HP-UX" vendor="HP"><vers num="10"/><vers num="11.0"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0518" published="1997-01-01" seq="1999-0518" severity="High" type="CVE"><desc><descript source="cve">A NETBIOS/SMB share password is guessable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/182.php">nt-netbios-perm(182)</ref></refs><vuln_soft><prod name="Windows 95" vendor="Microsoft"><vers num="a"/></prod></vuln_soft></entry><entry CVSS_base_score="7.5" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="6.4" CVSS_score="7.5" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:P)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0519" published="1997-01-01" seq="1999-0519" severity="High" type="CVE"><desc><descript source="cve">A NETBIOS/SMB share password is the default, null, or missing.</descript></desc><loss_types><avail/><conf/><int/><sec_prot other="1"/></loss_types><vuln_types><design/><config/></vuln_types><range><network/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/1.php">nt-netbios-everyoneaccess(1)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/2.php">nt-netbios-guestaccess(2)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/19.php">nt-netbios-write(19)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/12.php">nt-netbios-share(12)</ref><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/20.php">nt-netbios-shareguest(20)</ref></refs><vuln_soft><prod name="Windows NT" vendor="Microsoft"><vers num=""/></prod><prod name="Windows 95" vendor="Microsoft"><vers num=""/></prod><prod name="Outlook" vendor="Microsoft"><vers num="2000"/></prod><prod name="Windows 2000" vendor="Microsoft"><vers num=""/></prod></vuln_soft></entry><entry CVSS_base_score="6.4" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="4.9" CVSS_score="6.4" CVSS_vector="(AV:N/AC:L/Au:N/C:P/I:P/A:N)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0520" published="1999-01-01" seq="1999-0520" severity="Medium" type="CVE"><desc><descript source="cve">A system-critical NETBIOS/SMB share has inappropriate access control.</descript></desc><loss_types><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0521" published="1997-01-01" seq="1999-0521" severity="High" type="CVE"><desc><descript source="cve">An NIS domain name is easily guessable.</descript></desc><loss_types><avail/><conf/><int/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="ISS X-Force" url="http://xforce.iss.net/static/85.php">nis-dom(85)</ref></refs></entry><entry CVSS_base_score="7.2" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="10.0" CVSS_score="7.2" CVSS_vector="(AV:L/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0522" published="1996-05-28" seq="1999-0522" severity="High" type="CVE"><desc><descript source="cve">The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.</descript></desc><loss_types><avail/><conf/><int/><sec_prot admin="1" user="1"/></loss_types><vuln_types><design/></vuln_types><range><local/></range><refs><ref adv="1" patch="1" source="CERT" url="http://www.cert.org/advisories/CA-96.10.nis+_configuration.html">NIS+ Configuration Vulnerability</ref></refs></entry><entry CVSS_base_score="10.0" CVSS_exploit_subscore="10.0" CVSS_impact_subscore="10.0" CVSS_score="10.0" CVSS_vector="(AV:N/AC:L/Au:N/C:C/I:C/A:C)" CVSS_version="2.0 incomplete approximation" modified="2005-10-20" name="CVE-1999-0523" published="1999-01-01" seq="1999-0523" severity="High" type="CVE"><desc><descript source="cve">ICMP echo (ping) is allowed from arbitrary hosts.</descript></desc><loss_types><avail/><conf/><int/></loss_types><range><network/></range><refs/></entry><entry CVSS_base_score="0.0" CVSS_exploit_subscore="3.9" CVSS_impact_subscore="0.0" CVSS_score="0.0" CVSS_vector="(AV:L/AC:L/Au:N/C:N/I:N/A:N)" CVSS_version="2.0" modified="2008-04-10" name="CVE-1999-0524" published="1997-08-01" seq="1999-0524" severity="Low" type="CVE"><desc><descript source="cve">ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.</descript></desc><vuln_types><other/></vuln_types><range><local/></range><refs><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/306.php">icmp-netmask(306)</ref><ref adv="1" source="ISS X-Force" url="http://xforce.iss.net/static/322.php">icmp-timestamp(322)</ref><ref source="" url="http://descriptions.securescout.com/tc/11010"></ref><ref source="" url="http://d