{"id":"CVE-1999-1221","title":"dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.","summary":"dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.","severity":"low","cvss":2.1,"cvssVector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","published":"1996-11-17","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1221","references":[{"url":"http://marc.info/?l=bugtraq&m=87602167420141&w=2","label":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/399","label":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=87602167420141&w=2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/399","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00615,"epssPercentile":0.4813,"ingestedAt":"2026-06-22T15:59:08.126Z","slug":"CVE-1999-1221","body":"## Overview\n\ndxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":12,"depthScoreParts":{"impact":11.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}