| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-1172 | 0.00 | — | 0.01 | Jan 14, 1999 | By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared. | |||
| CVE-1999-1376 | 0.04 | — | 0.47 | Jan 14, 1999 | Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. | |||
| CVE-1999-1538 | 0.07 | — | 0.50 | Jan 14, 1999 | When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password. | |||
| CVE-1999-0063 | 0.04 | — | 0.12 | Jan 11, 1999 | Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port. | |||
| CVE-1999-0392 | 0.00 | — | 0.01 | Jan 10, 1999 | Buffer overflow in Thomas Boutell's cgic library version up to 1.05. | |||
| CVE-1999-0442 | 0.03 | — | 0.00 | Jan 7, 1999 | Solaris ff.core allows local users to modify files. | |||
| CVE-1999-0458 | — | 0.00 | — | 0.00 | Jan 6, 1999 | L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information. | ||
| CVE-1999-1268 | 0.00 | — | 0.00 | Jan 6, 1999 | Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices. | |||
| CVE-1999-0391 | 0.00 | — | 0.04 | Jan 5, 1999 | The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user. | |||
| CVE-1999-0390 | 0.00 | — | 0.00 | Jan 4, 1999 | Buffer overflow in Dosemu Slang library in Linux. | |||
| CVE-1999-0464 | 0.00 | — | 0.00 | Jan 4, 1999 | Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames. | |||
| CVE-1999-0389 | 0.00 | — | 0.00 | Jan 3, 1999 | Buffer overflow in the bootp server in the Debian Linux netstd package. | |||
| CVE-1999-0914 | 0.03 | — | 0.01 | Jan 3, 1999 | Buffer overflow in the FTP client in the Debian GNU/Linux netstd package. | |||
| CVE-2000-0054 | 0.03 | — | 0.04 | Jan 3, 1999 | search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack. | |||
| CVE-1999-0402 | 0.00 | — | 0.00 | Jan 2, 1999 | wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself. | |||
| CVE-1999-1170 | 0.03 | — | 0.00 | Jan 2, 1999 | IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920. | |||
| CVE-1999-1422 | 0.00 | — | 0.00 | Jan 2, 1999 | The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users. | |||
| CVE-2000-0005 | 0.00 | — | 0.00 | Jan 2, 1999 | HP-UX aserver program allows local users to gain privileges via a symlink attack. | |||
| CVE-1999-0561 | — | 0.00 | — | 0.01 | Jan 1, 1999 | IIS has the #exec function enabled for Server Side Include (SSI) files. | ||
| CVE-1999-0564 | — | 0.00 | — | 0.00 | Jan 1, 1999 | An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled. | ||
| CVE-1999-0565 | — | 0.00 | — | 0.00 | Jan 1, 1999 | A Sendmail alias allows input to be piped to a program. | ||
| CVE-1999-0568 | 0.00 | — | 0.01 | Jan 1, 1999 | rpc.admind in Solaris is not running in a secure mode. | |||
| CVE-1999-0285 | 0.01 | — | 0.13 | Jan 1, 1999 | Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection. | |||
| CVE-1999-0276 | 0.00 | — | 0.02 | Jan 1, 1999 | mSQL v2.0.1 and below allows remote execution through a buffer overflow. | |||
| CVE-1999-0283 | — | 0.03 | — | 0.04 | Jan 1, 1999 | The Java Web Server would allow remote users to obtain the source code for CGI programs. | ||
| CVE-1999-0286 | — | 0.00 | — | 0.00 | Jan 1, 1999 | In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages. | ||
| CVE-1999-0569 | — | 0.00 | — | 0.00 | Jan 1, 1999 | A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. | ||
| CVE-1999-0602 | — | 0.00 | — | 0.00 | Jan 1, 1999 | A network intrusion detection system (IDS) does not properly reassemble fragmented packets. | ||
| CVE-1999-0665 | — | 0.00 | — | 0.00 | Jan 1, 1999 | An application-critical Windows NT registry key has an inappropriate value. | ||
| CVE-1999-0698 | — | 0.00 | — | 0.00 | Jan 1, 1999 | Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux. | ||
| CVE-1999-0549 | 0.00 | — | 0.00 | Jan 1, 1999 | Windows NT automatically logs in an administrator upon rebooting. | |||
| CVE-1999-0554 | — | 0.05 | — | 0.24 | Jan 1, 1999 | NFS exports system-critical data to the world, e.g. / or a password file. | ||
| CVE-1999-0555 | — | 0.00 | — | 0.00 | Jan 1, 1999 | A Unix account with a name other than "root" has UID 0, i.e. root privileges. | ||
| CVE-1999-0556 | — | 0.00 | — | 0.00 | Jan 1, 1999 | Two or more Unix accounts have the same UID. | ||
| CVE-1999-0559 | — | 0.00 | — | 0.00 | Jan 1, 1999 | A system-critical Unix file or directory has inappropriate permissions. | ||
| CVE-1999-0560 | 0.00 | — | 0.03 | Jan 1, 1999 | A system-critical Windows NT file or directory has inappropriate permissions. | |||
| CVE-1999-0657 | — | 0.00 | — | 0.01 | Jan 1, 1999 | WinGate is being used. | ||
| CVE-1999-0197 | — | 0.00 | — | 0.00 | Jan 1, 1999 | finger 0@host on some systems may print information on some user accounts. | ||
| CVE-1999-0198 | — | 0.00 | — | 0.01 | Jan 1, 1999 | finger .@host on some systems may print information on some user accounts. | ||
| CVE-1999-0200 | — | 0.00 | — | 0.00 | Jan 1, 1999 | Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password. | ||
| CVE-1999-0205 | 0.00 | — | 0.01 | Jan 1, 1999 | Denial of service in Sendmail 8.6.11 and 8.6.12. | |||
| CVE-1999-0220 | — | 0.00 | — | 0.00 | Jan 1, 1999 | Attackers can do a denial of service of IRC by crashing the server. | ||
| CVE-1999-0226 | 0.01 | — | 0.12 | Jan 1, 1999 | Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. | |||
| CVE-1999-0231 | 0.00 | — | 0.01 | Jan 1, 1999 | Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access. | |||
| CVE-1999-0240 | — | 0.00 | — | 0.00 | Jan 1, 1999 | Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy. | ||
| CVE-1999-0243 | — | 0.00 | — | 0.00 | Jan 1, 1999 | Linux cfingerd could be exploited to gain root access. | ||
| CVE-1999-0248 | 0.00 | — | 0.00 | Jan 1, 1999 | A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials. | |||
| CVE-1999-0255 | — | 0.00 | — | 0.01 | Jan 1, 1999 | Buffer overflow in ircd allows arbitrary command execution. | ||
| CVE-1999-0268 | 0.03 | — | 0.03 | Jan 1, 1999 | MetaInfo MetaWeb web server allows users to upload, execute, and read scripts. | |||
| CVE-1999-0355 | 0.00 | — | 0.01 | Jan 1, 1999 | Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service. |
- CVE-1999-1172Jan 14, 1999risk 0.00cvss —epss 0.01
By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.
- CVE-1999-1376Jan 14, 1999risk 0.04cvss —epss 0.47
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.
- CVE-1999-1538Jan 14, 1999risk 0.07cvss —epss 0.50
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.
- CVE-1999-0063Jan 11, 1999risk 0.04cvss —epss 0.12
Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.
- CVE-1999-0392Jan 10, 1999risk 0.00cvss —epss 0.01
Buffer overflow in Thomas Boutell's cgic library version up to 1.05.
- CVE-1999-0442Jan 7, 1999risk 0.03cvss —epss 0.00
Solaris ff.core allows local users to modify files.
- CVE-1999-0458Jan 6, 1999risk 0.00cvss —epss 0.00
L0phtcrack 2.5 used temporary files in the system TEMP directory which could contain password information.
- CVE-1999-1268Jan 6, 1999risk 0.00cvss —epss 0.00
Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.
- CVE-1999-0391Jan 5, 1999risk 0.00cvss —epss 0.04
The cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and impersonate a user.
- CVE-1999-0390Jan 4, 1999risk 0.00cvss —epss 0.00
Buffer overflow in Dosemu Slang library in Linux.
- CVE-1999-0464Jan 4, 1999risk 0.00cvss —epss 0.00
Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.
- CVE-1999-0389Jan 3, 1999risk 0.00cvss —epss 0.00
Buffer overflow in the bootp server in the Debian Linux netstd package.
- CVE-1999-0914Jan 3, 1999risk 0.03cvss —epss 0.01
Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
- CVE-2000-0054Jan 3, 1999risk 0.03cvss —epss 0.04
search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.
- CVE-1999-0402Jan 2, 1999risk 0.00cvss —epss 0.00
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
- CVE-1999-1170Jan 2, 1999risk 0.03cvss —epss 0.00
IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
- CVE-1999-1422Jan 2, 1999risk 0.00cvss —epss 0.00
The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.
- CVE-2000-0005Jan 2, 1999risk 0.00cvss —epss 0.00
HP-UX aserver program allows local users to gain privileges via a symlink attack.
- CVE-1999-0561Jan 1, 1999risk 0.00cvss —epss 0.01
IIS has the #exec function enabled for Server Side Include (SSI) files.
- CVE-1999-0564Jan 1, 1999risk 0.00cvss —epss 0.00
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.
- CVE-1999-0565Jan 1, 1999risk 0.00cvss —epss 0.00
A Sendmail alias allows input to be piped to a program.
- CVE-1999-0568Jan 1, 1999risk 0.00cvss —epss 0.01
rpc.admind in Solaris is not running in a secure mode.
- CVE-1999-0285Jan 1, 1999risk 0.01cvss —epss 0.13
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.
- CVE-1999-0276Jan 1, 1999risk 0.00cvss —epss 0.02
mSQL v2.0.1 and below allows remote execution through a buffer overflow.
- CVE-1999-0283Jan 1, 1999risk 0.03cvss —epss 0.04
The Java Web Server would allow remote users to obtain the source code for CGI programs.
- CVE-1999-0286Jan 1, 1999risk 0.00cvss —epss 0.00
In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.
- CVE-1999-0569Jan 1, 1999risk 0.00cvss —epss 0.00
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
- CVE-1999-0602Jan 1, 1999risk 0.00cvss —epss 0.00
A network intrusion detection system (IDS) does not properly reassemble fragmented packets.
- CVE-1999-0665Jan 1, 1999risk 0.00cvss —epss 0.00
An application-critical Windows NT registry key has an inappropriate value.
- CVE-1999-0698Jan 1, 1999risk 0.00cvss —epss 0.00
Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.
- CVE-1999-0549Jan 1, 1999risk 0.00cvss —epss 0.00
Windows NT automatically logs in an administrator upon rebooting.
- CVE-1999-0554Jan 1, 1999risk 0.05cvss —epss 0.24
NFS exports system-critical data to the world, e.g. / or a password file.
- CVE-1999-0555Jan 1, 1999risk 0.00cvss —epss 0.00
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
- CVE-1999-0556Jan 1, 1999risk 0.00cvss —epss 0.00
Two or more Unix accounts have the same UID.
- CVE-1999-0559Jan 1, 1999risk 0.00cvss —epss 0.00
A system-critical Unix file or directory has inappropriate permissions.
- CVE-1999-0560Jan 1, 1999risk 0.00cvss —epss 0.03
A system-critical Windows NT file or directory has inappropriate permissions.
- CVE-1999-0657Jan 1, 1999risk 0.00cvss —epss 0.01
WinGate is being used.
- CVE-1999-0197Jan 1, 1999risk 0.00cvss —epss 0.00
finger 0@host on some systems may print information on some user accounts.
- CVE-1999-0198Jan 1, 1999risk 0.00cvss —epss 0.01
finger .@host on some systems may print information on some user accounts.
- CVE-1999-0200Jan 1, 1999risk 0.00cvss —epss 0.00
Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.
- CVE-1999-0205Jan 1, 1999risk 0.00cvss —epss 0.01
Denial of service in Sendmail 8.6.11 and 8.6.12.
- CVE-1999-0220Jan 1, 1999risk 0.00cvss —epss 0.00
Attackers can do a denial of service of IRC by crashing the server.
- CVE-1999-0226Jan 1, 1999risk 0.01cvss —epss 0.12
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
- CVE-1999-0231Jan 1, 1999risk 0.00cvss —epss 0.01
Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.
- CVE-1999-0240Jan 1, 1999risk 0.00cvss —epss 0.00
Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.
- CVE-1999-0243Jan 1, 1999risk 0.00cvss —epss 0.00
Linux cfingerd could be exploited to gain root access.
- CVE-1999-0248Jan 1, 1999risk 0.00cvss —epss 0.00
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
- CVE-1999-0255Jan 1, 1999risk 0.00cvss —epss 0.01
Buffer overflow in ircd allows arbitrary command execution.
- CVE-1999-0268Jan 1, 1999risk 0.03cvss —epss 0.03
MetaInfo MetaWeb web server allows users to upload, execute, and read scripts.
- CVE-1999-0355Jan 1, 1999risk 0.00cvss —epss 0.01
Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.