| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-1412 | 0.05 | — | 0.30 | Jun 3, 1999 | A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes. | |||
| CVE-1999-0772 | 0.00 | — | 0.01 | Jun 1, 1999 | Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301. | |||
| CVE-1999-0804 | 0.03 | — | 0.05 | Jun 1, 1999 | Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths. | |||
| CVE-1999-1063 | 0.03 | — | 0.04 | Jun 1, 1999 | CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter. | |||
| CVE-2000-0364 | 0.00 | — | 0.00 | Jun 1, 1999 | screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys. | |||
| CVE-2000-0365 | 0.00 | — | 0.00 | Jun 1, 1999 | Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices. | |||
| CVE-2000-0373 | 0.00 | — | 0.00 | Jun 1, 1999 | Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges. | |||
| CVE-2000-0481 | 0.00 | — | 0.01 | Jun 1, 1999 | Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name. | |||
| CVE-1999-1485 | 0.04 | — | 0.09 | May 31, 1999 | nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system. | |||
| CVE-2000-0333 | 0.04 | — | 0.07 | May 31, 1999 | tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet. | |||
| CVE-1999-1028 | 0.04 | — | 0.08 | May 28, 1999 | Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631. | |||
| CVE-1999-0755 | 0.08 | — | 0.65 | May 27, 1999 | Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option. | |||
| CVE-1999-0802 | 0.01 | — | 0.18 | May 27, 1999 | Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. | |||
| CVE-1999-0917 | 0.01 | — | 0.07 | May 27, 1999 | The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. | |||
| CVE-1999-0771 | 0.03 | — | 0.05 | May 26, 1999 | The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack. | |||
| CVE-1999-0920 | 0.09 | — | 0.74 | May 26, 1999 | Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command. | |||
| CVE-1999-0927 | 0.03 | — | 0.04 | May 26, 1999 | NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||
| CVE-1999-0803 | 0.03 | — | 0.03 | May 25, 1999 | The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack. | |||
| CVE-1999-1414 | 0.03 | — | 0.03 | May 25, 1999 | IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges. | |||
| CVE-1999-0762 | 0.00 | — | 0.00 | May 24, 1999 | When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information. | |||
| CVE-1999-0928 | 0.03 | — | 0.04 | May 23, 1999 | Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL. | |||
| CVE-1999-1393 | 0.00 | — | 0.00 | May 21, 1999 | Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible. | |||
| CVE-1999-0715 | 0.03 | — | 0.02 | May 20, 1999 | Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry. | |||
| CVE-1999-0765 | 0.03 | — | 0.02 | May 19, 1999 | SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor. | |||
| CVE-1999-1030 | 0.03 | — | 0.05 | May 19, 1999 | counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation. | |||
| CVE-1999-1031 | 0.00 | — | 0.01 | May 19, 1999 | counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument. | |||
| CVE-1999-0489 | 0.01 | — | 0.17 | May 17, 1999 | MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013. | |||
| CVE-1999-0716 | 0.04 | — | 0.06 | May 17, 1999 | Buffer overflow in Windows NT 4.0 help file utility via a malformed help file. | |||
| CVE-1999-1156 | 0.00 | — | 0.01 | May 17, 1999 | BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns. | |||
| CVE-1999-1510 | 0.10 | — | 0.83 | May 17, 1999 | Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands. | |||
| CVE-1999-1366 | 0.00 | — | 0.00 | May 15, 1999 | Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail. | |||
| CVE-1999-1029 | 0.00 | — | 0.01 | May 13, 1999 | SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs. | |||
| CVE-1999-0229 | 0.00 | — | 0.05 | May 12, 1999 | Denial of service in Windows NT IIS server using ..\.. | |||
| CVE-1999-0776 | 0.00 | — | 0.01 | May 12, 1999 | Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack. | |||
| CVE-1999-1368 | 0.00 | — | 0.00 | May 12, 1999 | AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox. | |||
| CVE-1999-0754 | 0.00 | — | 0.01 | May 11, 1999 | The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable. | |||
| CVE-1999-0773 | 0.03 | — | 0.00 | May 11, 1999 | Buffer overflow in Solaris lpset program allows local users to gain root access. | |||
| CVE-1999-0785 | 0.00 | — | 0.00 | May 11, 1999 | The INN inndstart program allows local users to gain root privileges via the "pathrun" parameter in the inn.conf file. | |||
| CVE-1999-1033 | 0.04 | — | 0.08 | May 11, 1999 | Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang. | |||
| CVE-1999-1520 | 0.06 | — | 0.43 | May 11, 1999 | A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information. | |||
| CVE-1999-0806 | 0.03 | — | 0.01 | May 10, 1999 | Buffer overflow in Solaris dtprintinfo program. | |||
| CVE-1999-1566 | 0.03 | — | 0.03 | May 8, 1999 | Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters. | |||
| CVE-1999-0686 | 0.00 | — | 0.01 | May 7, 1999 | Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL. | |||
| CVE-1999-0717 | 0.01 | — | 0.10 | May 7, 1999 | A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. | |||
| CVE-1999-0736 | 0.09 | — | 0.77 | May 7, 1999 | The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |||
| CVE-1999-0737 | 0.04 | — | 0.53 | May 7, 1999 | The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |||
| CVE-1999-0738 | 0.04 | — | 0.46 | May 7, 1999 | The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |||
| CVE-1999-0739 | 0.04 | — | 0.46 | May 7, 1999 | The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files. | |||
| CVE-1999-1079 | 0.00 | — | 0.00 | May 6, 1999 | Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program. | |||
| CVE-1999-1241 | 0.02 | — | 0.30 | May 6, 1999 | Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object. |
- CVE-1999-1412Jun 3, 1999risk 0.05cvss —epss 0.30
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.
- CVE-1999-0772Jun 1, 1999risk 0.00cvss —epss 0.01
Denial of service in Compaq Management Agents and the Compaq Survey Utility via a long string sent to port 2301.
- CVE-1999-0804Jun 1, 1999risk 0.03cvss —epss 0.05
Denial of service in Linux 2.2.x kernels via malformed ICMP packets containing unusual types, codes, and IP header lengths.
- CVE-1999-1063Jun 1, 1999risk 0.03cvss —epss 0.04
CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.
- CVE-2000-0364Jun 1, 1999risk 0.00cvss —epss 0.00
screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.
- CVE-2000-0365Jun 1, 1999risk 0.00cvss —epss 0.00
Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.
- CVE-2000-0373Jun 1, 1999risk 0.00cvss —epss 0.00
Vulnerabilities in the KDE kvt terminal program allow local users to gain root privileges.
- CVE-2000-0481Jun 1, 1999risk 0.00cvss —epss 0.01
Buffer overflow in KDE Kmail allows a remote attacker to cause a denial of service via an attachment with a long file name.
- CVE-1999-1485May 31, 1999risk 0.04cvss —epss 0.09
nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system.
- CVE-2000-0333May 31, 1999risk 0.04cvss —epss 0.07
tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.
- CVE-1999-1028May 28, 1999risk 0.04cvss —epss 0.08
Symantec pcAnywhere 8.0 allows remote attackers to cause a denial of service (CPU utilization) via a large amount of data to port 5631.
- CVE-1999-0755May 27, 1999risk 0.08cvss —epss 0.65
Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.
- CVE-1999-0802May 27, 1999risk 0.01cvss —epss 0.18
Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon.
- CVE-1999-0917May 27, 1999risk 0.01cvss —epss 0.07
The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files.
- CVE-1999-0771May 26, 1999risk 0.03cvss —epss 0.05
The web components of Compaq Management Agents and the Compaq Survey Utility allow a remote attacker to read arbitrary files via a .. (dot dot) attack.
- CVE-1999-0920May 26, 1999risk 0.09cvss —epss 0.74
Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.
- CVE-1999-0927May 26, 1999risk 0.03cvss —epss 0.04
NTMail allows remote attackers to read arbitrary files via a .. (dot dot) attack.
- CVE-1999-0803May 25, 1999risk 0.03cvss —epss 0.03
The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.
- CVE-1999-1414May 25, 1999risk 0.03cvss —epss 0.03
IBM Netfinity Remote Control allows local users to gain administrator privileges by starting programs from the process manager, which runs with system level privileges.
- CVE-1999-0762May 24, 1999risk 0.00cvss —epss 0.00
When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.
- CVE-1999-0928May 23, 1999risk 0.03cvss —epss 0.04
Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.
- CVE-1999-1393May 21, 1999risk 0.00cvss —epss 0.00
Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible.
- CVE-1999-0715May 20, 1999risk 0.03cvss —epss 0.02
Buffer overflow in Remote Access Service (RAS) client allows an attacker to execute commands or cause a denial of service via a malformed phonebook entry.
- CVE-1999-0765May 19, 1999risk 0.03cvss —epss 0.02
SGI IRIX midikeys program allows local users to modify arbitrary files via a text editor.
- CVE-1999-1030May 19, 1999risk 0.03cvss —epss 0.05
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.
- CVE-1999-1031May 19, 1999risk 0.00cvss —epss 0.01
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.
- CVE-1999-0489May 17, 1999risk 0.01cvss —epss 0.17
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.
- CVE-1999-0716May 17, 1999risk 0.04cvss —epss 0.06
Buffer overflow in Windows NT 4.0 help file utility via a malformed help file.
- CVE-1999-1156May 17, 1999risk 0.00cvss —epss 0.01
BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns.
- CVE-1999-1510May 17, 1999risk 0.10cvss —epss 0.83
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.
- CVE-1999-1366May 15, 1999risk 0.00cvss —epss 0.00
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.
- CVE-1999-1029May 13, 1999risk 0.00cvss —epss 0.01
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.
- CVE-1999-0229May 12, 1999risk 0.00cvss —epss 0.05
Denial of service in Windows NT IIS server using ..\..
- CVE-1999-0776May 12, 1999risk 0.00cvss —epss 0.01
Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.
- CVE-1999-1368May 12, 1999risk 0.00cvss —epss 0.00
AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.
- CVE-1999-0754May 11, 1999risk 0.00cvss —epss 0.01
The INN inndstart program allows local users to gain privileges by specifying an alternate configuration file using the INNCONF environmental variable.
- CVE-1999-0773May 11, 1999risk 0.03cvss —epss 0.00
Buffer overflow in Solaris lpset program allows local users to gain root access.
- CVE-1999-0785May 11, 1999risk 0.00cvss —epss 0.00
The INN inndstart program allows local users to gain root privileges via the "pathrun" parameter in the inn.conf file.
- CVE-1999-1033May 11, 1999risk 0.04cvss —epss 0.08
Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.
- CVE-1999-1520May 11, 1999risk 0.06cvss —epss 0.43
A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.
- CVE-1999-0806May 10, 1999risk 0.03cvss —epss 0.01
Buffer overflow in Solaris dtprintinfo program.
- CVE-1999-1566May 8, 1999risk 0.03cvss —epss 0.03
Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters.
- CVE-1999-0686May 7, 1999risk 0.00cvss —epss 0.01
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.
- CVE-1999-0717May 7, 1999risk 0.01cvss —epss 0.10
A remote attacker can disable the virus warning mechanism in Microsoft Excel 97.
- CVE-1999-0736May 7, 1999risk 0.09cvss —epss 0.77
The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
- CVE-1999-0737May 7, 1999risk 0.04cvss —epss 0.53
The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
- CVE-1999-0738May 7, 1999risk 0.04cvss —epss 0.46
The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
- CVE-1999-0739May 7, 1999risk 0.04cvss —epss 0.46
The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.
- CVE-1999-1079May 6, 1999risk 0.00cvss —epss 0.00
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.
- CVE-1999-1241May 6, 1999risk 0.02cvss —epss 0.30
Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.