Monthly Archive: February 2000

CVE-1999-0419

When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service. Date...

CVE-1999-0411

Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access. Date published : 2000-02-04

CVE-1999-0406

Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege. Date published : 2000-02-04

CVE-1999-0401

A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files. Date published : 2000-02-04

CVE-1999-0399

The DCC server command in the Mirc 5.5 client doesn’t filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute...

CVE-1999-0398

In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login. Date published : 2000-02-04

CVE-1999-0397

The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext. Date published : 2000-02-04

CVE-1999-0394

DPEC Online Courseware allows an attacker to change another user’s password without knowing the original password. Date published : 2000-02-04

CVE-1999-0361

NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging. Date published : 2000-02-04