| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0625 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The rpc.rquotad service is running. | ||
| CVE-1999-0629 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The ident/identd service is running. | ||
| CVE-1999-0630 | — | 0.00 | — | 0.00 | Jan 1, 1999 | The NT Alerter and Messenger services are running. | ||
| CVE-1999-0632 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The RPC portmapper service is running. | ||
| CVE-1999-0635 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The echo service is running. | ||
| CVE-1999-0636 | — | 0.00 | — | 0.00 | Jan 1, 1999 | The discard service is running. | ||
| CVE-1999-0637 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The systat service is running. | ||
| CVE-1999-0638 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The daytime service is running. | ||
| CVE-1999-0639 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The chargen service is running. | ||
| CVE-1999-0640 | — | 0.00 | — | 0.00 | Jan 1, 1999 | The Gopher service is running. | ||
| CVE-1999-0641 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The UUCP service is running. | ||
| CVE-1999-0650 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The netstat service is running, which provides sensitive information to remote attackers. | ||
| CVE-1999-0651 | — | 0.07 | — | 0.50 | Jan 1, 1999 | The rsh/rlogin service is running. | ||
| CVE-1999-0653 | — | 0.00 | — | 0.00 | Jan 1, 1999 | A component service related to NIS+ is running. | ||
| CVE-1999-0654 | — | 0.00 | — | 0.00 | Jan 1, 1999 | The OS/2 or POSIX subsystem in NT is enabled. | ||
| CVE-1999-0656 | 0.00 | — | 0.00 | Jan 1, 1999 | The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names. | |||
| CVE-1999-0661 | — | 0.04 | — | 0.06 | Jan 1, 1999 | A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6. | ||
| CVE-1999-0662 | — | 0.00 | — | 0.00 | Jan 1, 1999 | A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete. | ||
| CVE-1999-0663 | — | 0.00 | — | 0.00 | Jan 1, 1999 | A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified. | ||
| CVE-1999-0664 | — | 0.00 | — | 0.00 | Jan 1, 1999 | An application-critical Windows NT registry key has inappropriate permissions. | ||
| CVE-1999-1430 | 0.00 | — | 0.00 | Jan 1, 1999 | PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access. | |||
| CVE-1999-1440 | 0.00 | — | 0.01 | Jan 1, 1999 | Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client. | |||
| CVE-1999-1568 | Hig | 0.49 | 7.5 | 0.02 | Jan 1, 1999 | Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command. | ||
| CVE-1999-1159 | 0.00 | — | 0.00 | Dec 29, 1998 | SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root. | |||
| CVE-1999-1188 | 0.00 | — | 0.00 | Dec 27, 1998 | mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database. | |||
| CVE-1999-1285 | 0.00 | — | 0.00 | Dec 27, 1998 | Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed. | |||
| CVE-1999-0968 | 0.04 | — | 0.08 | Dec 26, 1998 | Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges. | |||
| CVE-1999-1281 | 0.00 | — | 0.01 | Dec 26, 1998 | Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program. | |||
| CVE-1999-1278 | 0.00 | — | 0.01 | Dec 25, 1998 | nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl. | |||
| CVE-1999-1277 | 0.00 | — | 0.00 | Dec 24, 1998 | BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password. | |||
| CVE-1999-1173 | 0.00 | — | 0.00 | Dec 18, 1998 | Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack. | |||
| CVE-1999-0188 | 0.00 | — | 0.00 | Dec 17, 1998 | The passwd command in Solaris can be subjected to a denial of service. | |||
| CVE-1999-0139 | 0.00 | — | 0.00 | Dec 12, 1998 | Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access. | |||
| CVE-1999-1282 | 0.00 | — | 0.00 | Dec 10, 1998 | RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges. | |||
| CVE-1999-1276 | 0.00 | — | 0.00 | Dec 7, 1998 | fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device. | |||
| CVE-1999-0798 | 0.00 | — | 0.01 | Dec 4, 1998 | Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type. | |||
| CVE-1999-1147 | 0.00 | — | 0.01 | Dec 4, 1998 | Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe. | |||
| CVE-1999-0936 | — | 0.00 | — | 0.02 | Dec 3, 1998 | BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters. | ||
| CVE-1999-0937 | — | 0.00 | — | 0.01 | Dec 3, 1998 | BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable. | ||
| CVE-1999-1280 | 0.00 | — | 0.00 | Dec 3, 1998 | Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file. | |||
| CVE-1999-0836 | 0.03 | — | 0.02 | Dec 2, 1998 | UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack. | |||
| CVE-1999-0321 | 0.03 | — | 0.00 | Dec 1, 1998 | Buffer overflow in Solaris kcms_configure command allows local users to gain root access. | |||
| CVE-1999-0332 | 0.00 | — | 0.04 | Dec 1, 1998 | Buffer overflow in NetMeeting allows denial of service and remote command execution. | |||
| CVE-1999-0342 | 0.00 | — | 0.00 | Dec 1, 1998 | Linux PAM modules allow local users to gain root access using temporary files. | |||
| CVE-1999-0385 | 0.01 | — | 0.09 | Dec 1, 1998 | The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands. | |||
| CVE-1999-0463 | — | 0.00 | — | 0.01 | Dec 1, 1998 | Remote attackers can perform a denial of service using IRIX fcagent. | ||
| CVE-1999-0478 | 0.00 | — | 0.01 | Dec 1, 1998 | Denial of service in HP-UX sendmail 8.8.6 related to accepting connections. | |||
| CVE-1999-0869 | 0.04 | — | 0.19 | Dec 1, 1998 | Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. | |||
| CVE-1999-1071 | 0.00 | — | 0.00 | Nov 30, 1998 | Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file. | |||
| CVE-1999-1072 | 0.00 | — | 0.00 | Nov 30, 1998 | Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi. |
- CVE-1999-0625Jan 1, 1999risk 0.00cvss —epss 0.01
The rpc.rquotad service is running.
- CVE-1999-0629Jan 1, 1999risk 0.00cvss —epss 0.01
The ident/identd service is running.
- CVE-1999-0630Jan 1, 1999risk 0.00cvss —epss 0.00
The NT Alerter and Messenger services are running.
- CVE-1999-0632Jan 1, 1999risk 0.00cvss —epss 0.01
The RPC portmapper service is running.
- CVE-1999-0635Jan 1, 1999risk 0.00cvss —epss 0.01
The echo service is running.
- CVE-1999-0636Jan 1, 1999risk 0.00cvss —epss 0.00
The discard service is running.
- CVE-1999-0637Jan 1, 1999risk 0.00cvss —epss 0.01
The systat service is running.
- CVE-1999-0638Jan 1, 1999risk 0.00cvss —epss 0.01
The daytime service is running.
- CVE-1999-0639Jan 1, 1999risk 0.00cvss —epss 0.01
The chargen service is running.
- CVE-1999-0640Jan 1, 1999risk 0.00cvss —epss 0.00
The Gopher service is running.
- CVE-1999-0641Jan 1, 1999risk 0.00cvss —epss 0.01
The UUCP service is running.
- CVE-1999-0650Jan 1, 1999risk 0.00cvss —epss 0.01
The netstat service is running, which provides sensitive information to remote attackers.
- CVE-1999-0651Jan 1, 1999risk 0.07cvss —epss 0.50
The rsh/rlogin service is running.
- CVE-1999-0653Jan 1, 1999risk 0.00cvss —epss 0.00
A component service related to NIS+ is running.
- CVE-1999-0654Jan 1, 1999risk 0.00cvss —epss 0.00
The OS/2 or POSIX subsystem in NT is enabled.
- CVE-1999-0656Jan 1, 1999risk 0.00cvss —epss 0.00
The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.
- CVE-1999-0661Jan 1, 1999risk 0.04cvss —epss 0.06
A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.
- CVE-1999-0662Jan 1, 1999risk 0.00cvss —epss 0.00
A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete.
- CVE-1999-0663Jan 1, 1999risk 0.00cvss —epss 0.00
A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.
- CVE-1999-0664Jan 1, 1999risk 0.00cvss —epss 0.00
An application-critical Windows NT registry key has inappropriate permissions.
- CVE-1999-1430Jan 1, 1999risk 0.00cvss —epss 0.00
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.
- CVE-1999-1440Jan 1, 1999risk 0.00cvss —epss 0.01
Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.
- risk 0.49cvss 7.5epss 0.02
Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.
- CVE-1999-1159Dec 29, 1998risk 0.00cvss —epss 0.00
SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.
- CVE-1999-1188Dec 27, 1998risk 0.00cvss —epss 0.00
mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.
- CVE-1999-1285Dec 27, 1998risk 0.00cvss —epss 0.00
Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.
- CVE-1999-0968Dec 26, 1998risk 0.04cvss —epss 0.08
Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
- CVE-1999-1281Dec 26, 1998risk 0.00cvss —epss 0.01
Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.
- CVE-1999-1278Dec 25, 1998risk 0.00cvss —epss 0.01
nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.
- CVE-1999-1277Dec 24, 1998risk 0.00cvss —epss 0.00
BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.
- CVE-1999-1173Dec 18, 1998risk 0.00cvss —epss 0.00
Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.
- CVE-1999-0188Dec 17, 1998risk 0.00cvss —epss 0.00
The passwd command in Solaris can be subjected to a denial of service.
- CVE-1999-0139Dec 12, 1998risk 0.00cvss —epss 0.00
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
- CVE-1999-1282Dec 10, 1998risk 0.00cvss —epss 0.00
RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.
- CVE-1999-1276Dec 7, 1998risk 0.00cvss —epss 0.00
fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.
- CVE-1999-0798Dec 4, 1998risk 0.00cvss —epss 0.01
Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.
- CVE-1999-1147Dec 4, 1998risk 0.00cvss —epss 0.01
Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe.
- CVE-1999-0936Dec 3, 1998risk 0.00cvss —epss 0.02
BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters.
- CVE-1999-0937Dec 3, 1998risk 0.00cvss —epss 0.01
BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.
- CVE-1999-1280Dec 3, 1998risk 0.00cvss —epss 0.00
Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.
- CVE-1999-0836Dec 2, 1998risk 0.03cvss —epss 0.02
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
- CVE-1999-0321Dec 1, 1998risk 0.03cvss —epss 0.00
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
- CVE-1999-0332Dec 1, 1998risk 0.00cvss —epss 0.04
Buffer overflow in NetMeeting allows denial of service and remote command execution.
- CVE-1999-0342Dec 1, 1998risk 0.00cvss —epss 0.00
Linux PAM modules allow local users to gain root access using temporary files.
- CVE-1999-0385Dec 1, 1998risk 0.01cvss —epss 0.09
The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.
- CVE-1999-0463Dec 1, 1998risk 0.00cvss —epss 0.01
Remote attackers can perform a denial of service using IRIX fcagent.
- CVE-1999-0478Dec 1, 1998risk 0.00cvss —epss 0.01
Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.
- CVE-1999-0869Dec 1, 1998risk 0.04cvss —epss 0.19
Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.
- CVE-1999-1071Nov 30, 1998risk 0.00cvss —epss 0.00
Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.
- CVE-1999-1072Nov 30, 1998risk 0.00cvss —epss 0.00
Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.