| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0599 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers. | ||
| CVE-1999-0394 | — | 0.00 | — | 0.02 | Jan 1, 1999 | DPEC Online Courseware allows an attacker to change another user's password without knowing the original password. | ||
| CVE-1999-0587 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data. | ||
| CVE-1999-0465 | 0.00 | — | 0.03 | Jan 1, 1999 | Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter. | |||
| CVE-1999-0571 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. | ||
| CVE-1999-0640 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The Gopher service is running. | ||
| CVE-1999-0355 | 0.00 | — | 0.02 | Jan 1, 1999 | Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service. | |||
| CVE-1999-0243 | 0.00 | — | 0.02 | Jan 1, 1999 | Linux cfingerd could be exploited to gain root access. | |||
| CVE-1999-0555 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A Unix account with a name other than "root" has UID 0, i.e. root privileges. | ||
| CVE-1999-0395 | 0.00 | — | 0.01 | Jan 1, 1999 | A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server. | |||
| CVE-1999-0388 | 0.03 | — | 0.01 | Jan 1, 1999 | DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root. | |||
| CVE-1999-0591 | — | 0.00 | — | 0.02 | Jan 1, 1999 | An event log in Windows NT has inappropriate access permissions. | ||
| CVE-1999-0401 | 0.00 | — | 0.00 | Jan 1, 1999 | A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files. | |||
| CVE-1999-0205 | 0.00 | — | 0.01 | Jan 1, 1999 | Denial of service in Sendmail 8.6.11 and 8.6.12. | |||
| CVE-1999-0639 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The chargen service is running. | ||
| CVE-1999-0636 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The discard service is running. | ||
| CVE-1999-0625 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The rpc.rquotad service is running. | ||
| CVE-1999-0583 | — | 0.00 | — | 0.02 | Jan 1, 1999 | There is a one-way or two-way trust relationship between Windows NT domains. | ||
| CVE-1999-0592 | 0.00 | — | 0.02 | Jan 1, 1999 | The Logon box of a Windows NT system displays the name of the last user who logged in. | |||
| CVE-1999-0656 | 0.00 | — | 0.02 | Jan 1, 1999 | The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names. | |||
| CVE-1999-0662 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete. | ||
| CVE-1999-0611 | 0.00 | — | 0.02 | Jan 1, 1999 | A system-critical Windows NT registry key has an inappropriate value. | |||
| CVE-1999-0596 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A Windows NT log file has an inappropriate maximum size or retention period. | ||
| CVE-1999-0665 | 0.00 | — | 0.02 | Jan 1, 1999 | An application-critical Windows NT registry key has an inappropriate value. | |||
| CVE-1999-0641 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The UUCP service is running. | ||
| CVE-1999-0600 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A network intrusion detection system (IDS) does not verify the checksum on a packet. | ||
| CVE-1999-0577 | 0.00 | — | 0.06 | Jan 1, 1999 | A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. | |||
| CVE-1999-0598 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection. | ||
| CVE-1999-0651 | — | 0.04 | — | 0.12 | Jan 1, 1999 | The rsh/rlogin service is running. | ||
| CVE-1999-0452 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A service or application has a backdoor password that was placed there by the developer. | ||
| CVE-1999-0393 | 0.03 | — | 0.02 | Jan 1, 1999 | Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers. | |||
| CVE-1999-0198 | — | 0.00 | — | 0.02 | Jan 1, 1999 | finger .@host on some systems may print information on some user accounts. | ||
| CVE-1999-0398 | 0.00 | — | 0.00 | Jan 1, 1999 | In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login. | |||
| CVE-1999-0399 | 0.00 | — | 0.03 | Jan 1, 1999 | The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands. | |||
| CVE-1999-0629 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The ident/identd service is running. | ||
| CVE-1999-0657 | — | 0.00 | — | 0.01 | Jan 1, 1999 | WinGate is being used. | ||
| CVE-1999-1159 | 0.00 | — | 0.00 | Dec 29, 1998 | SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root. | |||
| CVE-1999-1285 | 0.00 | — | 0.00 | Dec 27, 1998 | Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed. | |||
| CVE-1999-1188 | 0.00 | — | 0.01 | Dec 27, 1998 | mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database. | |||
| CVE-1999-0968 | 0.03 | — | 0.03 | Dec 26, 1998 | Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges. | |||
| CVE-1999-1281 | 0.00 | — | 0.01 | Dec 26, 1998 | Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program. | |||
| CVE-1999-1278 | 0.00 | — | 0.02 | Dec 25, 1998 | nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl. | |||
| CVE-1999-1277 | 0.00 | — | 0.00 | Dec 24, 1998 | BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password. | |||
| CVE-1999-1173 | 0.00 | — | 0.02 | Dec 18, 1998 | Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack. | |||
| CVE-1999-0188 | 0.00 | — | 0.00 | Dec 17, 1998 | The passwd command in Solaris can be subjected to a denial of service. | |||
| CVE-1999-0139 | 0.00 | — | 0.00 | Dec 12, 1998 | Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access. | |||
| CVE-1999-1282 | 0.00 | — | 0.01 | Dec 10, 1998 | RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges. | |||
| CVE-1999-1276 | 0.00 | — | 0.00 | Dec 7, 1998 | fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device. | |||
| CVE-1999-0798 | 0.00 | — | 0.02 | Dec 4, 1998 | Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type. | |||
| CVE-1999-1147 | 0.00 | — | 0.02 | Dec 4, 1998 | Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe. |
- CVE-1999-0599Jan 1, 1999risk 0.00cvss —epss 0.02
A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.
- CVE-1999-0394Jan 1, 1999risk 0.00cvss —epss 0.02
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
- CVE-1999-0587Jan 1, 1999risk 0.00cvss —epss 0.02
A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.
- CVE-1999-0465Jan 1, 1999risk 0.00cvss —epss 0.03
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
- CVE-1999-0571Jan 1, 1999risk 0.00cvss —epss 0.02
A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.
- CVE-1999-0640Jan 1, 1999risk 0.00cvss —epss 0.02
The Gopher service is running.
- CVE-1999-0355Jan 1, 1999risk 0.00cvss —epss 0.02
Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.
- CVE-1999-0243Jan 1, 1999risk 0.00cvss —epss 0.02
Linux cfingerd could be exploited to gain root access.
- CVE-1999-0555Jan 1, 1999risk 0.00cvss —epss 0.02
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
- CVE-1999-0395Jan 1, 1999risk 0.00cvss —epss 0.01
A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.
- CVE-1999-0388Jan 1, 1999risk 0.03cvss —epss 0.01
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
- CVE-1999-0591Jan 1, 1999risk 0.00cvss —epss 0.02
An event log in Windows NT has inappropriate access permissions.
- CVE-1999-0401Jan 1, 1999risk 0.00cvss —epss 0.00
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
- CVE-1999-0205Jan 1, 1999risk 0.00cvss —epss 0.01
Denial of service in Sendmail 8.6.11 and 8.6.12.
- CVE-1999-0639Jan 1, 1999risk 0.00cvss —epss 0.01
The chargen service is running.
- CVE-1999-0636Jan 1, 1999risk 0.00cvss —epss 0.02
The discard service is running.
- CVE-1999-0625Jan 1, 1999risk 0.00cvss —epss 0.01
The rpc.rquotad service is running.
- CVE-1999-0583Jan 1, 1999risk 0.00cvss —epss 0.02
There is a one-way or two-way trust relationship between Windows NT domains.
- CVE-1999-0592Jan 1, 1999risk 0.00cvss —epss 0.02
The Logon box of a Windows NT system displays the name of the last user who logged in.
- CVE-1999-0656Jan 1, 1999risk 0.00cvss —epss 0.02
The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.
- CVE-1999-0662Jan 1, 1999risk 0.00cvss —epss 0.02
A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete.
- CVE-1999-0611Jan 1, 1999risk 0.00cvss —epss 0.02
A system-critical Windows NT registry key has an inappropriate value.
- CVE-1999-0596Jan 1, 1999risk 0.00cvss —epss 0.02
A Windows NT log file has an inappropriate maximum size or retention period.
- CVE-1999-0665Jan 1, 1999risk 0.00cvss —epss 0.02
An application-critical Windows NT registry key has an inappropriate value.
- CVE-1999-0641Jan 1, 1999risk 0.00cvss —epss 0.01
The UUCP service is running.
- CVE-1999-0600Jan 1, 1999risk 0.00cvss —epss 0.02
A network intrusion detection system (IDS) does not verify the checksum on a packet.
- CVE-1999-0577Jan 1, 1999risk 0.00cvss —epss 0.06
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
- CVE-1999-0598Jan 1, 1999risk 0.00cvss —epss 0.02
A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.
- CVE-1999-0651Jan 1, 1999risk 0.04cvss —epss 0.12
The rsh/rlogin service is running.
- CVE-1999-0452Jan 1, 1999risk 0.00cvss —epss 0.02
A service or application has a backdoor password that was placed there by the developer.
- CVE-1999-0393Jan 1, 1999risk 0.03cvss —epss 0.02
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
- CVE-1999-0198Jan 1, 1999risk 0.00cvss —epss 0.02
finger .@host on some systems may print information on some user accounts.
- CVE-1999-0398Jan 1, 1999risk 0.00cvss —epss 0.00
In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
- CVE-1999-0399Jan 1, 1999risk 0.00cvss —epss 0.03
The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.
- CVE-1999-0629Jan 1, 1999risk 0.00cvss —epss 0.01
The ident/identd service is running.
- CVE-1999-0657Jan 1, 1999risk 0.00cvss —epss 0.01
WinGate is being used.
- CVE-1999-1159Dec 29, 1998risk 0.00cvss —epss 0.00
SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.
- CVE-1999-1285Dec 27, 1998risk 0.00cvss —epss 0.00
Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.
- CVE-1999-1188Dec 27, 1998risk 0.00cvss —epss 0.01
mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.
- CVE-1999-0968Dec 26, 1998risk 0.03cvss —epss 0.03
Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
- CVE-1999-1281Dec 26, 1998risk 0.00cvss —epss 0.01
Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.
- CVE-1999-1278Dec 25, 1998risk 0.00cvss —epss 0.02
nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.
- CVE-1999-1277Dec 24, 1998risk 0.00cvss —epss 0.00
BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.
- CVE-1999-1173Dec 18, 1998risk 0.00cvss —epss 0.02
Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.
- CVE-1999-0188Dec 17, 1998risk 0.00cvss —epss 0.00
The passwd command in Solaris can be subjected to a denial of service.
- CVE-1999-0139Dec 12, 1998risk 0.00cvss —epss 0.00
Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.
- CVE-1999-1282Dec 10, 1998risk 0.00cvss —epss 0.01
RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.
- CVE-1999-1276Dec 7, 1998risk 0.00cvss —epss 0.00
fte-console in the fte package before 0.46b-4.1 does not drop root privileges, which allows local users to gain root access via the virtual console device.
- CVE-1999-0798Dec 4, 1998risk 0.00cvss —epss 0.02
Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.
- CVE-1999-1147Dec 4, 1998risk 0.00cvss —epss 0.02
Buffer overflow in Platinum Policy Compliance Manager (PCM) 7.0 allows remote attackers to execute arbitrary commands via a long string to the Agent port (1827), which is handled by smaxagent.exe.