| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0743 | 0.00 | — | 0.00 | Aug 20, 1999 | Trn allows local users to overwrite other users' files via symlinks. | |||
| CVE-1999-1561 | 0.00 | — | 0.00 | Aug 20, 1999 | Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server. | |||
| CVE-1999-1565 | 0.00 | — | 0.00 | Aug 20, 1999 | Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | |||
| CVE-2000-0325 | 0.04 | — | 0.07 | Aug 20, 1999 | The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability. | |||
| CVE-2000-1206 | 0.00 | — | 0.03 | Aug 20, 1999 | Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files. | |||
| CVE-1999-0725 | 0.06 | — | 0.36 | Aug 19, 1999 | When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page". | |||
| CVE-1999-0732 | 0.00 | — | 0.00 | Aug 19, 1999 | The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links. | |||
| CVE-1999-0734 | 0.00 | — | 0.01 | Aug 19, 1999 | A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication. | |||
| CVE-1999-0740 | 0.00 | — | 0.01 | Aug 19, 1999 | Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable. | |||
| CVE-1999-0741 | 0.00 | — | 0.01 | Aug 19, 1999 | QMS CrownNet Unix Utilities for 2060 allows root to log on without a password. | |||
| CVE-1999-0745 | 0.05 | — | 0.26 | Aug 18, 1999 | Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler. | |||
| CVE-1999-0747 | 0.00 | — | 0.00 | Aug 18, 1999 | Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load. | |||
| CVE-1999-0753 | 0.03 | — | 0.03 | Aug 17, 1999 | The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories. | |||
| CVE-1999-0746 | 0.03 | — | 0.06 | Aug 16, 1999 | A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service. | |||
| CVE-1999-0749 | 0.05 | — | 0.21 | Aug 16, 1999 | Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. | |||
| CVE-1999-0888 | 0.03 | — | 0.00 | Aug 16, 1999 | dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script. | |||
| CVE-1999-0679 | 0.04 | — | 0.08 | Aug 13, 1999 | Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option. | |||
| CVE-1999-0724 | 0.00 | — | 0.00 | Aug 12, 1999 | Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function. | |||
| CVE-1999-1336 | — | 0.00 | — | 0.01 | Aug 12, 1999 | 3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port. | ||
| CVE-1999-0694 | 0.00 | — | 0.00 | Aug 11, 1999 | Denial of service in AIX ptrace system call allows local users to crash the system. | |||
| CVE-1999-0814 | 0.00 | — | 0.01 | Aug 11, 1999 | Red Hat pump DHCP client allows remote attackers to gain root access in some configurations. | |||
| CVE-1999-0861 | 0.00 | — | 0.05 | Aug 11, 1999 | Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. | |||
| CVE-1999-0867 | 0.05 | — | 0.19 | Aug 11, 1999 | Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers. | |||
| CVE-1999-0875 | 0.06 | — | 0.39 | Aug 11, 1999 | DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes. | |||
| CVE-1999-0813 | 0.00 | — | 0.00 | Aug 10, 1999 | Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges. | |||
| CVE-1999-0674 | 0.03 | — | 0.00 | Aug 9, 1999 | The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve. | |||
| CVE-1999-0675 | 0.00 | — | 0.01 | Aug 9, 1999 | Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host. | |||
| CVE-1999-0676 | 0.00 | — | 0.00 | Aug 9, 1999 | sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack. | |||
| CVE-1999-0680 | 0.00 | — | 0.04 | Aug 9, 1999 | Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service. | |||
| CVE-1999-0673 | 0.03 | — | 0.06 | Aug 8, 1999 | Buffer overflow in ALMail32 POP3 client via From: or To: headers. | |||
| CVE-1999-0722 | 0.00 | — | 0.01 | Aug 8, 1999 | The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages. | |||
| CVE-1999-1524 | 0.00 | — | 0.01 | Aug 7, 1999 | FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port. | |||
| CVE-1999-0682 | 0.01 | — | 0.14 | Aug 6, 1999 | Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled. | |||
| CVE-1999-0727 | 0.00 | — | 0.01 | Aug 6, 1999 | A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted. | |||
| CVE-1999-0719 | 0.00 | — | 0.00 | Aug 5, 1999 | The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code. | |||
| CVE-1999-0913 | 0.03 | — | 0.04 | Aug 5, 1999 | dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters. | |||
| CVE-1999-0671 | 0.03 | — | 0.06 | Aug 3, 1999 | Buffer overflow in ToxSoft NextFTP client through CWD command. | |||
| CVE-1999-0677 | 0.00 | — | 0.00 | Aug 3, 1999 | The WebRamp web administration utility has a default password. | |||
| CVE-1999-0703 | 0.00 | — | 0.00 | Aug 3, 1999 | OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices. | |||
| CVE-1999-0672 | 0.03 | — | 0.06 | Aug 1, 1999 | Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics. | |||
| CVE-1999-1337 | 0.00 | — | 0.00 | Aug 1, 1999 | FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges. | |||
| CVE-1999-0683 | 0.03 | — | 0.06 | Jul 30, 1999 | Denial of service in Gauntlet Firewall via a malformed ICMP packet. | |||
| CVE-1999-1130 | 0.04 | — | 0.07 | Jul 30, 1999 | Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file. | |||
| CVE-1999-1227 | 0.00 | — | 0.00 | Jul 30, 1999 | Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file. | |||
| CVE-1999-1536 | 0.00 | — | 0.00 | Jul 30, 1999 | .sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file. | |||
| CVE-1999-0700 | 0.03 | — | 0.06 | Jul 29, 1999 | Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. | |||
| CVE-1999-0770 | 0.03 | — | 0.01 | Jul 29, 1999 | Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems. | |||
| CVE-1999-1078 | 0.00 | — | 0.01 | Jul 29, 1999 | WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges. | |||
| CVE-1999-1017 | 0.00 | — | 0.00 | Jul 28, 1999 | Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message. | |||
| CVE-2000-0323 | 0.01 | — | 0.13 | Jul 28, 1999 | The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability. |
- CVE-1999-0743Aug 20, 1999risk 0.00cvss —epss 0.00
Trn allows local users to overwrite other users' files via symlinks.
- CVE-1999-1561Aug 20, 1999risk 0.00cvss —epss 0.00
Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.
- CVE-1999-1565Aug 20, 1999risk 0.00cvss —epss 0.00
Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
- CVE-2000-0325Aug 20, 1999risk 0.04cvss —epss 0.07
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.
- CVE-2000-1206Aug 20, 1999risk 0.00cvss —epss 0.03
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.
- CVE-1999-0725Aug 19, 1999risk 0.06cvss —epss 0.36
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source code of certain files, a.k.a. "Double Byte Code Page".
- CVE-1999-0732Aug 19, 1999risk 0.00cvss —epss 0.00
The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.
- CVE-1999-0734Aug 19, 1999risk 0.00cvss —epss 0.01
A default configuration of CiscoSecure Access Control Server (ACS) allows remote users to modify the server database without authentication.
- CVE-1999-0740Aug 19, 1999risk 0.00cvss —epss 0.01
Remote attackers can cause a denial of service on Linux in.telnetd telnet daemon through a malformed TERM environmental variable.
- CVE-1999-0741Aug 19, 1999risk 0.00cvss —epss 0.01
QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.
- CVE-1999-0745Aug 18, 1999risk 0.05cvss —epss 0.26
Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
- CVE-1999-0747Aug 18, 1999risk 0.00cvss —epss 0.00
Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.
- CVE-1999-0753Aug 17, 1999risk 0.03cvss —epss 0.03
The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.
- CVE-1999-0746Aug 16, 1999risk 0.03cvss —epss 0.06
A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to conduct a denial of service.
- CVE-1999-0749Aug 16, 1999risk 0.05cvss —epss 0.21
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
- CVE-1999-0888Aug 16, 1999risk 0.03cvss —epss 0.00
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
- CVE-1999-0679Aug 13, 1999risk 0.04cvss —epss 0.08
Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite invite option.
- CVE-1999-0724Aug 12, 1999risk 0.00cvss —epss 0.00
Buffer overflow in OpenBSD procfs and fdescfs file systems via uio_offset in the readdir() function.
- CVE-1999-1336Aug 12, 1999risk 0.00cvss —epss 0.01
3Com HiPer Access Router Card (HiperARC) 4.0 through 4.2.29 allows remote attackers to cause a denial of service (reboot) via a flood of IAC packets to the telnet port.
- CVE-1999-0694Aug 11, 1999risk 0.00cvss —epss 0.00
Denial of service in AIX ptrace system call allows local users to crash the system.
- CVE-1999-0814Aug 11, 1999risk 0.00cvss —epss 0.01
Red Hat pump DHCP client allows remote attackers to gain root access in some configurations.
- CVE-1999-0861Aug 11, 1999risk 0.00cvss —epss 0.05
Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext.
- CVE-1999-0867Aug 11, 1999risk 0.05cvss —epss 0.19
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
- CVE-1999-0875Aug 11, 1999risk 0.06cvss —epss 0.39
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
- CVE-1999-0813Aug 10, 1999risk 0.00cvss —epss 0.00
Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
- CVE-1999-0674Aug 9, 1999risk 0.03cvss —epss 0.00
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
- CVE-1999-0675Aug 9, 1999risk 0.00cvss —epss 0.01
Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.
- CVE-1999-0676Aug 9, 1999risk 0.00cvss —epss 0.00
sdtcm_convert in Solaris 2.6 allows a local user to overwrite sensitive files via a symlink attack.
- CVE-1999-0680Aug 9, 1999risk 0.00cvss —epss 0.04
Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service.
- CVE-1999-0673Aug 8, 1999risk 0.03cvss —epss 0.06
Buffer overflow in ALMail32 POP3 client via From: or To: headers.
- CVE-1999-0722Aug 8, 1999risk 0.00cvss —epss 0.01
The default configuration of Cobalt RaQ2 servers allows remote users to install arbitrary software packages.
- CVE-1999-1524Aug 7, 1999risk 0.00cvss —epss 0.01
FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.
- CVE-1999-0682Aug 6, 1999risk 0.01cvss —epss 0.14
Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
- CVE-1999-0727Aug 6, 1999risk 0.00cvss —epss 0.01
A kernel leak in the OpenBSD kernel allows IPsec packets to be sent unencrypted.
- CVE-1999-0719Aug 5, 1999risk 0.00cvss —epss 0.00
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
- CVE-1999-0913Aug 5, 1999risk 0.03cvss —epss 0.04
dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.
- CVE-1999-0671Aug 3, 1999risk 0.03cvss —epss 0.06
Buffer overflow in ToxSoft NextFTP client through CWD command.
- CVE-1999-0677Aug 3, 1999risk 0.00cvss —epss 0.00
The WebRamp web administration utility has a default password.
- CVE-1999-0703Aug 3, 1999risk 0.00cvss —epss 0.00
OpenBSD, BSDI, and other Unix operating systems allow users to set chflags and fchflags on character and block devices.
- CVE-1999-0672Aug 1, 1999risk 0.03cvss —epss 0.06
Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.
- CVE-1999-1337Aug 1, 1999risk 0.00cvss —epss 0.00
FTP client in Midnight Commander (mc) before 4.5.11 stores usernames and passwords for visited sites in plaintext in the world-readable history file, which allows other local users to gain privileges.
- CVE-1999-0683Jul 30, 1999risk 0.03cvss —epss 0.06
Denial of service in Gauntlet Firewall via a malformed ICMP packet.
- CVE-1999-1130Jul 30, 1999risk 0.04cvss —epss 0.07
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.
- CVE-1999-1227Jul 30, 1999risk 0.00cvss —epss 0.00
Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.
- CVE-1999-1536Jul 30, 1999risk 0.00cvss —epss 0.00
.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.
- CVE-1999-0700Jul 29, 1999risk 0.03cvss —epss 0.06
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
- CVE-1999-0770Jul 29, 1999risk 0.03cvss —epss 0.01
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.
- CVE-1999-1078Jul 29, 1999risk 0.00cvss —epss 0.01
WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.
- CVE-1999-1017Jul 28, 1999risk 0.00cvss —epss 0.00
Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.
- CVE-2000-0323Jul 28, 1999risk 0.01cvss —epss 0.13
The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.