
CVE-1999-0434
https://notcve.org/view.php?id=CVE-1999-0434
30 Mar 1999 — XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. • http://www.securityfocus.com/bid/359 •

CVE-1999-0303
https://notcve.org/view.php?id=CVE-1999-0303
21 May 1998 — Buffer overflow in BNU UUCP daemon (uucpd) through long hostnames. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0303 •

CVE-1999-0009 – ISC BIND (Linux/BSD) - Remote Buffer Overflow
https://notcve.org/view.php?id=CVE-1999-0009
08 Apr 1998 — Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. • https://www.exploit-db.com/exploits/19111 •

CVE-1999-0010
https://notcve.org/view.php?id=CVE-1999-0010
08 Apr 1998 — Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages. • ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX •

CVE-1999-0011
https://notcve.org/view.php?id=CVE-1999-0011
08 Apr 1998 — Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer. • ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX • CWE-1067: Excessive Execution of Sequential Searches of Data Resource •

CVE-1999-0513 – Linux Kernel 2.0/2.1 (Digital UNIX 4.0 D / FreeBSD 2.2.4 / HP HP-UX 10.20/11.0 / IBM AIX 3.2.5 / NetBSD 1.2 / Solaris 2.5.1) - Smurf Denial of Service
https://notcve.org/view.php?id=CVE-1999-0513
05 Jan 1998 — ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service. • https://www.exploit-db.com/exploits/19117 •

CVE-1999-0017
https://notcve.org/view.php?id=CVE-1999-0017
10 Dec 1997 — FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0017 •

CVE-1999-1214
https://notcve.org/view.php?id=CVE-1999-1214
15 Sep 1997 — The asynchronous I/O facility in 4.4 BSD kernel does not check user credentials when setting the recipient of I/O notification, which allows local users to cause a denial of service by using certain ioctl and fcntl calls to cause the signal to be sent to an arbitrary process ID. • http://www.openbsd.com/advisories/signals.txt • CWE-255: Credentials Management Errors •

CVE-1999-0046 – BSD/OS 2.1 / DG/UX 4.0 / Debian 0.93 / Digital UNIX 4.0 B / FreeBSD 2.1.5 / HP-UX 10.34 / IBM AIX 4.1.5 / NetBSD 1.0/1.1 / NeXTstep 4.0 / SGI IRIX 6.3 / SunOS 4.1.4 - 'rlogin' Local Privilege Escalation
https://notcve.org/view.php?id=CVE-1999-0046
06 Feb 1997 — Buffer overflow of rlogin program using TERM environmental variable. • https://www.exploit-db.com/exploits/19203 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-1999-0297
https://notcve.org/view.php?id=CVE-1999-0297
12 Dec 1996 — Buffer overflow in Vixie Cron library up to version 3.0 allows local users to obtain root access via a long environmental variable. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0297 •