
CVE-1999-1191 – Solaris 2.5.0/2.5.1 ps / chkey - Data Buffer
https://notcve.org/view.php?id=CVE-1999-1191
19 May 1997 — Buffer overflow in chkey in Solaris 2.5.1 and earlier allows local users to gain root privileges via a long command line argument. • https://www.exploit-db.com/exploits/332 •

CVE-1999-1402 – FreeBSD 3.1 / Solaris 2.6 - Domain Socket
https://notcve.org/view.php?id=CVE-1999-1402
17 May 1997 — The access permissions for a UNIX domain socket are ignored in Solaris 2.x and SunOS 4.x, and other BSD-based operating systems before 4.4, which could allow local users to connect to the socket and possibly disrupt or control the operations of the program using that socket. • https://www.exploit-db.com/exploits/19346 •

CVE-1999-0165
https://notcve.org/view.php?id=CVE-1999-0165
01 Mar 1997 — NFS cache poisoning. • https://www.cve.org/CVERecord?id=CVE-1999-0165 •

CVE-1999-0046 – BSD/OS 2.1 / DG/UX 4.0 / Debian 0.93 / Digital UNIX 4.0 B / FreeBSD 2.1.5 / HP-UX 10.34 / IBM AIX 4.1.5 / NetBSD 1.0/1.1 / NeXTstep 4.0 / SGI IRIX 6.3 / SunOS 4.1.4 - 'rlogin' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-1999-0046
06 Feb 1997 — Buffer overflow of rlogin program using TERM environmental variable. • https://www.exploit-db.com/exploits/19203 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-1999-0051 – SGI IRIX 5.3/6.2 / SGI license_oeo 1.0 LicenseManager - 'NETLS_LICENSE_FILE' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-1999-0051
06 Jan 1997 — Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX. • https://www.exploit-db.com/exploits/19066 •

CVE-1999-0217
https://notcve.org/view.php?id=CVE-1999-0217
01 Jan 1997 — Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0217 •

CVE-1999-0132
https://notcve.org/view.php?id=CVE-1999-0132
15 Aug 1996 — Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access. • http://www.cert.org/advisories/CA-1996-19.html •

CVE-1999-0022
https://notcve.org/view.php?id=CVE-1999-0022
03 Jul 1996 — Local user gains root privileges via buffer overflow in rdist, via expstr() function. • http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/179 • CWE-125: Out-of-bounds Read •

CVE-1999-0078
https://notcve.org/view.php?id=CVE-1999-0078
18 Apr 1996 — pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0078 •

CVE-1999-1580
https://notcve.org/view.php?id=CVE-1999-1580
23 Aug 1995 — SunOS sendmail 5.59 through 5.65 uses popen to process a forwarding host argument, which allows local users to gain root privileges by modifying the IFS (Internal Field Separator) variable and passing crafted values to the -oR option. • http://www.alw.nih.gov/Security/8lgm/8lgm-Advisory-21.html •