CVE-1999-1020 – Novell Netware 4.1/4.11 - SP5B NDS Default Rights
https://notcve.org/view.php?id=CVE-1999-1020
The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE. • https://www.exploit-db.com/exploits/19365 http://marc.info/?l=bugtraq&m=90613355902262&w=2 http://www.securityfocus.com/bid/484 https://exchange.xforce.ibmcloud.com/vulnerabilities/1364 •
CVE-1999-0524
https://notcve.org/view.php?id=CVE-1999-0524
ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts. Información ICMP como (1) máscara de red y (2) marca de tiempo está permitida desde hosts arbitrarios. • http://descriptions.securescout.com/tc/11010 http://descriptions.securescout.com/tc/11011 http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&externalId=1434 http://www.osvdb.org/95 https://exchange.xforce.ibmcloud.com/vulnerabilities/306 https://exchange.xforce.ibmcloud.com/vulnerabilities/322 https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-1999-0265
https://notcve.org/view.php?id=CVE-1999-0265
ICMP redirect messages may crash or lock up a host. • http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3BQ154174 • CWE-20: Improper Input Validation •
CVE-1999-1215
https://notcve.org/view.php?id=CVE-1999-1215
LOGIN.EXE program in Novell Netware 4.0 and 4.01 temporarily writes user name and password information to disk, which could allow local users to gain privileges. • http://ciac.llnl.gov/ciac/bulletins/d-21.shtml http://www.cert.org/advisories/CA-1993-12.html https://exchange.xforce.ibmcloud.com/vulnerabilities/545 •