Monthly Archive: September 1999

CVE-1999-0260

The jj CGI program allows command execution via shell metacharacters. Date published : 1999-09-29

CVE-1999-0252

Buffer overflow in listserv allows arbitrary command execution. Date published : 1999-09-29

CVE-1999-0251

Denial of service in talk program allows remote attackers to disrupt a user’s display. Date published : 1999-09-29

CVE-1999-0245

Some configurations of NIS+ in Linux allowed attackers to log in as the user "+". Date published : 1999-09-29

CVE-1999-0244

Livingston RADIUS code has a buffer overflow which can allow remote execution of commands as root. Date published : 1999-09-29

CVE-1999-0239

Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET. Date published : 1999-09-29 http://www.osvdb.org/122

CVE-1999-0237

Remote execution of arbitrary commands through Guestbook CGI program. Date published : 1999-09-29

CVE-1999-0236

ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. Date published : 1999-09-29

CVE-1999-0234

Bash treats any character with a value of 255 as a command separator. Date published : 1999-09-29