| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0375 | 0.00 | — | 0.01 | Feb 16, 1999 | Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands. | |||
| CVE-1999-1180 | 0.00 | — | 0.02 | Feb 16, 1999 | O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat. | |||
| CVE-1999-0714 | 0.00 | — | 0.00 | Feb 15, 1999 | Vulnerability in Compaq Tru64 UNIX edauth command. | |||
| CVE-1999-1260 | 0.00 | — | 0.01 | Feb 15, 1999 | mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query. | |||
| CVE-1999-0404 | 0.03 | — | 0.06 | Feb 14, 1999 | Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution. | |||
| CVE-1999-0372 | 0.04 | — | 0.06 | Feb 12, 1999 | The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. | |||
| CVE-1999-1203 | 0.00 | — | 0.01 | Feb 12, 1999 | Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier. | |||
| CVE-1999-0371 | 0.00 | — | 0.00 | Feb 11, 1999 | Lynx allows a local user to overwrite sensitive files through /tmp symlinks. | |||
| CVE-1999-1375 | 0.09 | — | 0.74 | Feb 11, 1999 | FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. | |||
| CVE-1999-0353 | 0.00 | — | 0.00 | Feb 10, 1999 | rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory. | |||
| CVE-1999-0370 | 0.00 | — | 0.00 | Feb 10, 1999 | In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files. | |||
| CVE-1999-0367 | 0.00 | — | 0.00 | Feb 9, 1999 | NetBSD netstat command allows local users to access kernel memory. | |||
| CVE-1999-0368 | 0.07 | — | 0.48 | Feb 9, 1999 | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | |||
| CVE-1999-0407 | 0.02 | — | 0.30 | Feb 9, 1999 | By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. | |||
| CVE-1999-0350 | 0.03 | — | 0.00 | Feb 8, 1999 | Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits. | |||
| CVE-1999-0366 | 0.00 | — | 0.06 | Feb 8, 1999 | In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value. | |||
| CVE-1999-1201 | 0.02 | — | 0.19 | Feb 6, 1999 | Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing. | |||
| CVE-1999-0365 | 0.00 | — | 0.01 | Feb 4, 1999 | The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry. | |||
| CVE-1999-1169 | 0.00 | — | 0.01 | Feb 4, 1999 | nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets. | |||
| CVE-1999-0362 | 0.00 | — | 0.00 | Feb 2, 1999 | WS_FTP server remote denial of service through cwd command. | |||
| CVE-1999-0363 | 0.03 | — | 0.01 | Feb 2, 1999 | SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise. | |||
| CVE-1999-0383 | 0.00 | — | 0.00 | Feb 2, 1999 | ACC Tigris allows public access without a login. | |||
| CVE-1999-1171 | 0.03 | — | 0.00 | Feb 2, 1999 | IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920. | |||
| CVE-1999-1453 | 0.07 | — | 0.50 | Feb 2, 1999 | Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. | |||
| CVE-1999-0291 | 0.00 | — | 0.01 | Feb 1, 1999 | The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication. | |||
| CVE-1999-0351 | 0.00 | — | 0.01 | Feb 1, 1999 | FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client. | |||
| CVE-1999-0358 | 0.00 | — | 0.00 | Feb 1, 1999 | Digital Unix 4.0 has a buffer overflow in the inc program of the mh package. | |||
| CVE-1999-0373 | 0.00 | — | 0.00 | Feb 1, 1999 | Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root. | |||
| CVE-1999-0403 | 0.00 | — | 0.00 | Feb 1, 1999 | A bug in Cyrix CPUs on Linux allows local users to perform a denial of service. | |||
| CVE-1999-0459 | — | 0.00 | — | 0.00 | Feb 1, 1999 | Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot. | ||
| CVE-1999-0360 | 0.04 | — | 0.08 | Jan 30, 1999 | MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely. | |||
| CVE-1999-1546 | 0.00 | — | 0.01 | Jan 29, 1999 | netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable. | |||
| CVE-2000-0370 | 0.00 | — | 0.02 | Jan 29, 1999 | The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command. | |||
| CVE-1999-0461 | 0.00 | — | 0.01 | Jan 28, 1999 | Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address. | |||
| CVE-1999-0952 | 0.00 | — | 0.00 | Jan 28, 1999 | Buffer overflow in Solaris lpstat via class argument allows local users to gain root access. | |||
| CVE-1999-0348 | 0.01 | — | 0.10 | Jan 27, 1999 | IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. | |||
| CVE-1999-0349 | 0.01 | — | 0.11 | Jan 27, 1999 | A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. | |||
| CVE-1999-1450 | 0.00 | — | 0.01 | Jan 27, 1999 | Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges. | |||
| CVE-1999-0347 | — | 0.03 | — | 0.03 | Jan 26, 1999 | Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character. | ||
| CVE-1999-0400 | 0.03 | — | 0.01 | Jan 26, 1999 | Denial of service in Linux 2.2.0 running the ldd command on a core file. | |||
| CVE-1999-0449 | 0.03 | — | 0.36 | Jan 26, 1999 | The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. | |||
| CVE-1999-0450 | 0.05 | — | 0.25 | Jan 26, 1999 | In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). | |||
| CVE-1999-0352 | — | 0.00 | — | 0.00 | Jan 25, 1999 | ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption. | ||
| CVE-1999-0356 | — | 0.00 | — | 0.00 | Jan 25, 1999 | ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book. | ||
| CVE-1999-0357 | 0.01 | — | 0.07 | Jan 25, 1999 | Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets. | |||
| CVE-1999-1458 | 0.00 | — | 0.00 | Jan 25, 1999 | Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument. | |||
| CVE-1999-1544 | 0.01 | — | 0.07 | Jan 24, 1999 | Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. | |||
| CVE-1999-0121 | — | 0.00 | — | 0.00 | Jan 21, 1999 | Buffer overflow in dtaction command gives root access. | ||
| CVE-1999-1264 | 0.00 | — | 0.01 | Jan 21, 1999 | WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled. | |||
| CVE-1999-0119 | 0.01 | — | 0.09 | Jan 19, 1999 | Windows NT 4.0 beta allows users to read and delete shares. |
- CVE-1999-0375Feb 16, 1999risk 0.00cvss —epss 0.01
Buffer overflow in webd in Network Flight Recorder (NFR) 2.0.2-Research allows remote attackers to execute commands.
- CVE-1999-1180Feb 16, 1999risk 0.00cvss —epss 0.02
O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.
- CVE-1999-0714Feb 15, 1999risk 0.00cvss —epss 0.00
Vulnerability in Compaq Tru64 UNIX edauth command.
- CVE-1999-1260Feb 15, 1999risk 0.00cvss —epss 0.01
mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.
- CVE-1999-0404Feb 14, 1999risk 0.03cvss —epss 0.06
Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.
- CVE-1999-0372Feb 12, 1999risk 0.04cvss —epss 0.06
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.
- CVE-1999-1203Feb 12, 1999risk 0.00cvss —epss 0.01
Multilink PPP for ISDN dialup users in Ascend before 4.6 allows remote attackers to cause a denial of service via a spoofed endpoint identifier.
- CVE-1999-0371Feb 11, 1999risk 0.00cvss —epss 0.00
Lynx allows a local user to overwrite sensitive files through /tmp symlinks.
- CVE-1999-1375Feb 11, 1999risk 0.09cvss —epss 0.74
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.
- CVE-1999-0353Feb 10, 1999risk 0.00cvss —epss 0.00
rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.
- CVE-1999-0370Feb 10, 1999risk 0.00cvss —epss 0.00
In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.
- CVE-1999-0367Feb 9, 1999risk 0.00cvss —epss 0.00
NetBSD netstat command allows local users to access kernel memory.
- CVE-1999-0368Feb 9, 1999risk 0.07cvss —epss 0.48
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
- CVE-1999-0407Feb 9, 1999risk 0.02cvss —epss 0.30
By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system.
- CVE-1999-0350Feb 8, 1999risk 0.03cvss —epss 0.00
Race condition in the db_loader program in ClearCase gives local users root access by setting SUID bits.
- CVE-1999-0366Feb 8, 1999risk 0.00cvss —epss 0.06
In some cases, Service Pack 4 for Windows NT 4.0 can allow access to network shares using a blank password, through a problem with a null NT hash value.
- CVE-1999-1201Feb 6, 1999risk 0.02cvss —epss 0.19
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.
- CVE-1999-0365Feb 4, 1999risk 0.00cvss —epss 0.01
The metamail package allows remote command execution using shell metacharacters that are not quoted in a mailcap entry.
- CVE-1999-1169Feb 4, 1999risk 0.00cvss —epss 0.01
nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.
- CVE-1999-0362Feb 2, 1999risk 0.00cvss —epss 0.00
WS_FTP server remote denial of service through cwd command.
- CVE-1999-0363Feb 2, 1999risk 0.03cvss —epss 0.01
SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.
- CVE-1999-0383Feb 2, 1999risk 0.00cvss —epss 0.00
ACC Tigris allows public access without a login.
- CVE-1999-1171Feb 2, 1999risk 0.03cvss —epss 0.00
IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
- CVE-1999-1453Feb 2, 1999risk 0.07cvss —epss 0.50
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.
- CVE-1999-0291Feb 1, 1999risk 0.00cvss —epss 0.01
The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.
- CVE-1999-0351Feb 1, 1999risk 0.00cvss —epss 0.01
FTP PASV "Pizza Thief" denial of service and unauthorized data access. Attackers can steal data by connecting to a port that was intended for use by a client.
- CVE-1999-0358Feb 1, 1999risk 0.00cvss —epss 0.00
Digital Unix 4.0 has a buffer overflow in the inc program of the mh package.
- CVE-1999-0373Feb 1, 1999risk 0.00cvss —epss 0.00
Buffer overflow in the "Super" utility in Debian GNU/Linux, and other operating systems, allows local users to execute commands as root.
- CVE-1999-0403Feb 1, 1999risk 0.00cvss —epss 0.00
A bug in Cyrix CPUs on Linux allows local users to perform a denial of service.
- CVE-1999-0459Feb 1, 1999risk 0.00cvss —epss 0.00
Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.
- CVE-1999-0360Jan 30, 1999risk 0.04cvss —epss 0.08
MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.
- CVE-1999-1546Jan 29, 1999risk 0.00cvss —epss 0.01
netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.
- CVE-2000-0370Jan 29, 1999risk 0.00cvss —epss 0.02
The debug option in Caldera Linux smail allows remote attackers to execute commands via shell metacharacters in the -D option for the rmail command.
- CVE-1999-0461Jan 28, 1999risk 0.00cvss —epss 0.01
Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.
- CVE-1999-0952Jan 28, 1999risk 0.00cvss —epss 0.00
Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.
- CVE-1999-0348Jan 27, 1999risk 0.01cvss —epss 0.10
IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory.
- CVE-1999-0349Jan 27, 1999risk 0.01cvss —epss 0.11
A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands.
- CVE-1999-1450Jan 27, 1999risk 0.00cvss —epss 0.01
Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.
- CVE-1999-0347Jan 26, 1999risk 0.03cvss —epss 0.03
Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "about:" Javascript URL, which causes Internet Explorer to use the domain specified after the character.
- CVE-1999-0400Jan 26, 1999risk 0.03cvss —epss 0.01
Denial of service in Linux 2.2.0 running the ldd command on a core file.
- CVE-1999-0449Jan 26, 1999risk 0.03cvss —epss 0.36
The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.
- CVE-1999-0450Jan 26, 1999risk 0.05cvss —epss 0.25
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).
- CVE-1999-0352Jan 25, 1999risk 0.00cvss —epss 0.00
ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.
- CVE-1999-0356Jan 25, 1999risk 0.00cvss —epss 0.00
ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.
- CVE-1999-0357Jan 25, 1999risk 0.01cvss —epss 0.07
Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.
- CVE-1999-1458Jan 25, 1999risk 0.00cvss —epss 0.00
Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.
- CVE-1999-1544Jan 24, 1999risk 0.01cvss —epss 0.07
Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.
- CVE-1999-0121Jan 21, 1999risk 0.00cvss —epss 0.00
Buffer overflow in dtaction command gives root access.
- CVE-1999-1264Jan 21, 1999risk 0.00cvss —epss 0.01
WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been explicitly disabled.
- CVE-1999-0119Jan 19, 1999risk 0.01cvss —epss 0.09
Windows NT 4.0 beta allows users to read and delete shares.