CSV
172,045 results for "vulnerability" Page 4
CVE-1999-0702

Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability.

Sep 10, 1999 2 affected product(s) NVD
10.0
CVSS
42.4%
EPSS
⚡ 52.7
CVE-1999-1199

Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.

Aug 7, 1998 1 affected product(s) NVD
10.0
CVSS
5.1%
EPSS
⚡ 41.5
CVE-2000-0330

The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.

Nov 12, 1999 2 affected product(s) NVD
7.6
CVSS
22.9%
EPSS
⚡ 37.3
CVE-2000-0323

The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.

Jul 28, 1999 3 affected product(s) NVD
7.6
CVSS
13.3%
EPSS
⚡ 34.4
CVE-2000-0025

IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.

Dec 21, 1999 3 affected product(s) NVD
5.0
CVSS
46.0%
EPSS
⚡ 33.8
CVE-2000-0327

Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability.

Oct 21, 1999 2 affected product(s) NVD
7.6
CVSS
6.4%
EPSS
⚡ 32.3
CVE-1999-0909

Multihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed Route Pointer" vulnerability.

Sep 20, 1999 10 affected product(s) NVD
7.5
CVSS
4.3%
EPSS
⚡ 31.3
CVE-1999-0287

Vulnerability in the Wguest CGI program.

Apr 9, 1999 1 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-1999-0488

Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.

Apr 21, 1999 4 affected product(s) NVD
7.5
CVSS
3.3%
EPSS
⚡ 31
CVE-2000-0325

The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.

Aug 20, 1999 2 affected product(s) NVD
7.2
CVSS
7.0%
EPSS
⚡ 30.9
CVE-1999-1417

Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.

Aug 23, 1998 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-1999-1179

Vulnerability in man.sh CGI script, included in May 1998 issue of SysAdmin Magazine, allows remote attackers to execute arbitrary commands.

May 15, 1998 1 affected product(s) NVD
7.5
CVSS
0.8%
EPSS
⚡ 30.2
CVE-1999-1450

Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.

Jan 27, 1999 6 affected product(s) NVD
7.5
CVSS
0.7%
EPSS
⚡ 30.2
CVE-1999-1111

Vulnerability in StackGuard before 1.21 allows remote attackers to bypass the Random and Terminator Canary security mechanisms by using a non-linear attack which directly modifies a pointer to a return address instead of using a buffer overflow to reach the return address entry itself.

Nov 9, 1999 1 affected product(s) NVD
7.5
CVSS
0.7%
EPSS
⚡ 30.2
CVE-1999-1163

Vulnerability in HP Series 800 S/X/V Class servers allows remote attackers to gain access to the S/X/V Class console via the Service Support Processor (SSP) Teststation.

Nov 24, 1999 1 affected product(s) NVD
7.5
CVSS
0.5%
EPSS
⚡ 30.2
CVE-1999-1558

Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled.

Jul 16, 1998 2 affected product(s) NVD
7.5
CVSS
0.5%
EPSS
⚡ 30.1
CVE-2000-0024

IIS does not properly canonicalize URLs, potentially allowing remote attackers to bypass access restrictions in third-party software via escape characters, aka the "Escape Character Parsing" vulnerability.

Dec 21, 1999 3 affected product(s) NVD
6.4
CVSS
12.0%
EPSS
⚡ 29.2
CVE-1999-1039

Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise.

May 27, 1998 1 affected product(s) NVD
7.2
CVSS
0.0%
EPSS
⚡ 28.8
CVE-1999-1492

Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges.

May 27, 1998 1 affected product(s) NVD
7.2
CVSS
0.0%
EPSS
⚡ 28.8
CVE-1999-1181

Vulnerability in On-Line Customer Registration software for IRIX 6.2 through 6.4 allows local users to gain root privileges.

Sep 29, 1998 2 affected product(s) NVD
7.2
CVSS
0.1%
EPSS
⚡ 28.8