- EPSS 0.73%
- Veröffentlicht 01.02.1998 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The system configuration control (sysctl) facility in BSD based operating systems OpenBSD 2.2 and earlier, and FreeBSD 2.2.5 and earlier, does not properly restrict source routed packets even when the (1) dosourceroute or (2) forwarding variables are...
- EPSS 25.58%
- Veröffentlicht 05.01.1998 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.
CVE-1999-0017
- EPSS 0.55%
- Veröffentlicht 10.12.1997 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
CVE-1999-0322
- EPSS 0.11%
- Veröffentlicht 29.10.1997 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The open() function in FreeBSD allows local attackers to write to arbitrary files.
CVE-1999-0061
- EPSS 1.66%
- Veröffentlicht 02.10.1997 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).
CVE-1999-1214
- EPSS 0.08%
- Veröffentlicht 15.09.1997 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sen...
CVE-1999-0074
- EPSS 5.88%
- Veröffentlicht 01.07.1997 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Listening TCP ports are sequentially allocated, allowing spoofing attacks.
- EPSS 0.61%
- Veröffentlicht 01.07.1997 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The rwho/rwhod service is running, which exposes machine status and user information.
CVE-1999-0037
- EPSS 0.78%
- Veröffentlicht 21.05.1997 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.
CVE-1999-1402
- EPSS 0.27%
- Veröffentlicht 17.05.1997 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the p...