CVE-1999-0248
Published Jan 1, 1999A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
351,728 results · Sorted by Highest Buzz score first
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
Buffer overflow in ircd allows arbitrary command execution.
MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
mSQL v2.0.1 and below allows remote execution through a buffer overflow.
The Java Web Server would allow remote users to obtain the source code for CGI programs.
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.
Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, poss…
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
A service or application has a backdoor password that was placed there by the developer.
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
A system-critical NETBIOS/SMB share has inappropriate access control.
A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.