{"id":"CVE-1999-1301","title":"A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.","summary":"A design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.","severity":"high","cvss":7.5,"cvssVector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","published":"1996-07-16","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1301","references":[{"url":"ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc","label":"cve@mitre.org"},{"url":"http://ciac.llnl.gov/ciac/bulletins/g-31.shtml","label":"cve@mitre.org"},{"url":"http://www.iss.net/security_center/static/7540.php","label":"cve@mitre.org"},{"url":"ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:17.rzsz.asc","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://ciac.llnl.gov/ciac/bulletins/g-31.shtml","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.iss.net/security_center/static/7540.php","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01316,"epssPercentile":0.69066,"ingestedAt":"2026-06-22T15:59:08.083Z","slug":"CVE-1999-1301","body":"## Overview\n\nA design flaw in the Z-Modem protocol allows the remote sender of a file to execute arbitrary programs on the client, as implemented in rz in the rzsz module of FreeBSD before 2.1.5, and possibly other programs.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}