Monthly Archive: February 2000

CVE-1999-0571

A router’s configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. Date published : 2000-02-04

CVE-1999-0570

Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. Date published : 2000-02-04

CVE-1999-0569

A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. Date published : 2000-02-04

CVE-1999-0568

rpc.admind in Solaris is not running in a secure mode. Date published : 2000-02-04

CVE-1999-0565

A Sendmail alias allows input to be piped to a program. Date published : 2000-02-04

CVE-1999-0564

An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn’t require a password) or to become disabled. Date published : 2000-02-04

CVE-1999-0561

IIS has the #exec function enabled for Server Side Include (SSI) files. Date published : 2000-02-04

CVE-1999-0560

A system-critical Windows NT file or directory has inappropriate permissions. Date published : 2000-02-04

CVE-1999-0559

A system-critical Unix file or directory has inappropriate permissions. Date published : 2000-02-04

CVE-1999-0556

Two or more Unix accounts have the same UID. Date published : 2000-02-04

CVE-1999-0555

A Unix account with a name other than "root" has UID 0, i.e. root privileges. Date published : 2000-02-04

CVE-1999-0554

NFS exports system-critical data to the world, e.g. / or a password file. Date published : 2000-02-04

CVE-1999-0550

A router’s routing tables can be obtained from arbitrary hosts. Date published : 2000-02-04