{"id":"CVE-1999-1295","title":"Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protec…","summary":"Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protec…","severity":"medium","cvss":4.6,"cvssVector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","published":"1996-09-17","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1295","references":[{"url":"http://www.cert.org/vendor_bulletins/VB-96.16.transarc","label":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7154","label":"cve@mitre.org"},{"url":"http://www.cert.org/vendor_bulletins/VB-96.16.transarc","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/7154","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00344,"epssPercentile":0.2793,"ingestedAt":"2026-06-22T15:59:08.101Z","slug":"CVE-1999-1295","body":"## Overview\n\nTransarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}