CVE-1999-0109 – Solaris 2.5.1 - 'ffbconfig' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-1999-0109
Buffer overflow in ffbconfig in Solaris 2.5.1. • https://www.exploit-db.com/exploits/19159 http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/140 •
CVE-1999-0046 – BSD/OS 2.1 / DG/UX 4.0 / Debian 0.93 / Digital UNIX 4.0 B / FreeBSD 2.1.5 / HP-UX 10.34 / IBM AIX 4.1.5 / NetBSD 1.0/1.1 / NeXTstep 4.0 / SGI IRIX 6.3 / SunOS 4.1.4 - 'rlogin' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-1999-0046
Buffer overflow of rlogin program using TERM environmental variable. • https://www.exploit-db.com/exploits/19203 https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0046 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-1999-0298
https://notcve.org/view.php?id=CVE-1999-0298
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack. • http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp •
CVE-1999-0369 – Sun Solaris 7.0 - '/usr/dt/bin/sdtcm_convert' Local Overflow / Local Privilege Escalation
https://notcve.org/view.php?id=CVE-1999-0369
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access. • https://www.exploit-db.com/exploits/19128 http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/183 •
CVE-1999-0966
https://notcve.org/view.php?id=CVE-1999-0966
Buffer overflow in Solaris getopt in libc allows local users to gain root privileges via a long argv[0]. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0966 •