| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0384 | 0.00 | — | 0.01 | Jan 1, 1999 | The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. | |||
| CVE-1999-0388 | 0.03 | — | 0.01 | Jan 1, 1999 | DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root. | |||
| CVE-1999-0393 | 0.03 | — | 0.02 | Jan 1, 1999 | Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers. | |||
| CVE-1999-0394 | — | 0.00 | — | 0.02 | Jan 1, 1999 | DPEC Online Courseware allows an attacker to change another user's password without knowing the original password. | ||
| CVE-1999-0395 | 0.00 | — | 0.01 | Jan 1, 1999 | A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server. | |||
| CVE-1999-0397 | 0.00 | — | 0.02 | Jan 1, 1999 | The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext. | |||
| CVE-1999-0398 | 0.00 | — | 0.00 | Jan 1, 1999 | In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login. | |||
| CVE-1999-0399 | 0.00 | — | 0.03 | Jan 1, 1999 | The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands. | |||
| CVE-1999-0401 | 0.00 | — | 0.00 | Jan 1, 1999 | A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files. | |||
| CVE-1999-0448 | 0.05 | — | 0.25 | Jan 1, 1999 | IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. | |||
| CVE-1999-0452 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A service or application has a backdoor password that was placed there by the developer. | ||
| CVE-1999-0453 | 0.00 | — | 0.01 | Jan 1, 1999 | An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP). | |||
| CVE-1999-0454 | — | 0.00 | — | 0.03 | Jan 1, 1999 | A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso. | ||
| CVE-1999-0465 | 0.00 | — | 0.03 | Jan 1, 1999 | Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter. | |||
| CVE-1999-0495 | — | 0.00 | — | 0.03 | Jan 1, 1999 | A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares. | ||
| CVE-1999-0497 | — | 0.04 | — | 0.07 | Jan 1, 1999 | Anonymous FTP is enabled. | ||
| CVE-1999-0512 | — | 0.04 | — | 0.12 | Jan 1, 1999 | A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers. | ||
| CVE-1999-0515 | — | 0.00 | — | 0.02 | Jan 1, 1999 | An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv. | ||
| CVE-1999-0520 | — | 0.00 | — | 0.01 | Jan 1, 1999 | A system-critical NETBIOS/SMB share has inappropriate access control. | ||
| CVE-1999-0523 | — | 0.00 | — | 0.01 | Jan 1, 1999 | ICMP echo (ping) is allowed from arbitrary hosts. | ||
| CVE-1999-0527 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten. | ||
| CVE-1999-0528 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of. | ||
| CVE-1999-0529 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc. | ||
| CVE-1999-0530 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A system is operating in "promiscuous" mode which allows it to perform packet sniffing. | ||
| CVE-1999-0539 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A trust relationship exists between two Unix hosts. | ||
| CVE-1999-0547 | — | 0.00 | — | 0.02 | Jan 1, 1999 | An SSH server allows authentication through the .rhosts file. | ||
| CVE-1999-0548 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A superfluous NFS server is running, but it is not importing or exporting any file systems. | ||
| CVE-1999-0549 | 0.00 | — | 0.02 | Jan 1, 1999 | Windows NT automatically logs in an administrator upon rebooting. | |||
| CVE-1999-0554 | — | 0.04 | — | 0.11 | Jan 1, 1999 | NFS exports system-critical data to the world, e.g. / or a password file. | ||
| CVE-1999-0555 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A Unix account with a name other than "root" has UID 0, i.e. root privileges. | ||
| CVE-1999-0556 | — | 0.00 | — | 0.02 | Jan 1, 1999 | Two or more Unix accounts have the same UID. | ||
| CVE-1999-0559 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A system-critical Unix file or directory has inappropriate permissions. | ||
| CVE-1999-0560 | 0.00 | — | 0.06 | Jan 1, 1999 | A system-critical Windows NT file or directory has inappropriate permissions. | |||
| CVE-1999-0561 | 0.01 | — | 0.08 | Jan 1, 1999 | IIS has the #exec function enabled for Server Side Include (SSI) files. | |||
| CVE-1999-0564 | — | 0.00 | — | 0.02 | Jan 1, 1999 | An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled. | ||
| CVE-1999-0565 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A Sendmail alias allows input to be piped to a program. | ||
| CVE-1999-0568 | 0.00 | — | 0.02 | Jan 1, 1999 | rpc.admind in Solaris is not running in a secure mode. | |||
| CVE-1999-0569 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file. | ||
| CVE-1999-0570 | 0.00 | — | 0.06 | Jan 1, 1999 | Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. | |||
| CVE-1999-0571 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts. | ||
| CVE-1999-0577 | 0.00 | — | 0.06 | Jan 1, 1999 | A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. | |||
| CVE-1999-0578 | 0.00 | — | 0.02 | Jan 1, 1999 | A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. | |||
| CVE-1999-0579 | 0.00 | — | 0.06 | Jan 1, 1999 | A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys. | |||
| CVE-1999-0580 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions. | ||
| CVE-1999-0581 | 0.01 | — | 0.07 | Jan 1, 1999 | The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions. | |||
| CVE-1999-0583 | — | 0.00 | — | 0.02 | Jan 1, 1999 | There is a one-way or two-way trust relationship between Windows NT domains. | ||
| CVE-1999-0584 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A Windows NT file system is not NTFS. | ||
| CVE-1999-0586 | — | 0.00 | — | 0.01 | Jan 1, 1999 | A network service is running on a nonstandard port. | ||
| CVE-1999-0587 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data. | ||
| CVE-1999-0588 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A filter in a router or firewall allows unusual fragmented packets. |
- CVE-1999-0384Jan 1, 1999risk 0.00cvss —epss 0.01
The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content.
- CVE-1999-0388Jan 1, 1999risk 0.03cvss —epss 0.01
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute commands as root.
- CVE-1999-0393Jan 1, 1999risk 0.03cvss —epss 0.02
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of headers.
- CVE-1999-0394Jan 1, 1999risk 0.00cvss —epss 0.02
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.
- CVE-1999-0395Jan 1, 1999risk 0.00cvss —epss 0.01
A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.
- CVE-1999-0397Jan 1, 1999risk 0.00cvss —epss 0.02
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
- CVE-1999-0398Jan 1, 1999risk 0.00cvss —epss 0.00
In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.
- CVE-1999-0399Jan 1, 1999risk 0.00cvss —epss 0.03
The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.
- CVE-1999-0401Jan 1, 1999risk 0.00cvss —epss 0.00
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.
- CVE-1999-0448Jan 1, 1999risk 0.05cvss —epss 0.25
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
- CVE-1999-0452Jan 1, 1999risk 0.00cvss —epss 0.02
A service or application has a backdoor password that was placed there by the developer.
- CVE-1999-0453Jan 1, 1999risk 0.00cvss —epss 0.01
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Discovery Protocol (CDP).
- CVE-1999-0454Jan 1, 1999risk 0.00cvss —epss 0.03
A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.
- CVE-1999-0465Jan 1, 1999risk 0.00cvss —epss 0.03
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.
- CVE-1999-0495Jan 1, 1999risk 0.00cvss —epss 0.03
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.
- CVE-1999-0497Jan 1, 1999risk 0.04cvss —epss 0.07
Anonymous FTP is enabled.
- CVE-1999-0512Jan 1, 1999risk 0.04cvss —epss 0.12
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.
- CVE-1999-0515Jan 1, 1999risk 0.00cvss —epss 0.02
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.
- CVE-1999-0520Jan 1, 1999risk 0.00cvss —epss 0.01
A system-critical NETBIOS/SMB share has inappropriate access control.
- CVE-1999-0523Jan 1, 1999risk 0.00cvss —epss 0.01
ICMP echo (ping) is allowed from arbitrary hosts.
- CVE-1999-0527Jan 1, 1999risk 0.00cvss —epss 0.02
The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.
- CVE-1999-0528Jan 1, 1999risk 0.00cvss —epss 0.02
A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.
- CVE-1999-0529Jan 1, 1999risk 0.00cvss —epss 0.02
A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.
- CVE-1999-0530Jan 1, 1999risk 0.00cvss —epss 0.02
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.
- CVE-1999-0539Jan 1, 1999risk 0.00cvss —epss 0.02
A trust relationship exists between two Unix hosts.
- CVE-1999-0547Jan 1, 1999risk 0.00cvss —epss 0.02
An SSH server allows authentication through the .rhosts file.
- CVE-1999-0548Jan 1, 1999risk 0.00cvss —epss 0.02
A superfluous NFS server is running, but it is not importing or exporting any file systems.
- CVE-1999-0549Jan 1, 1999risk 0.00cvss —epss 0.02
Windows NT automatically logs in an administrator upon rebooting.
- CVE-1999-0554Jan 1, 1999risk 0.04cvss —epss 0.11
NFS exports system-critical data to the world, e.g. / or a password file.
- CVE-1999-0555Jan 1, 1999risk 0.00cvss —epss 0.02
A Unix account with a name other than "root" has UID 0, i.e. root privileges.
- CVE-1999-0556Jan 1, 1999risk 0.00cvss —epss 0.02
Two or more Unix accounts have the same UID.
- CVE-1999-0559Jan 1, 1999risk 0.00cvss —epss 0.02
A system-critical Unix file or directory has inappropriate permissions.
- CVE-1999-0560Jan 1, 1999risk 0.00cvss —epss 0.06
A system-critical Windows NT file or directory has inappropriate permissions.
- CVE-1999-0561Jan 1, 1999risk 0.01cvss —epss 0.08
IIS has the #exec function enabled for Server Side Include (SSI) files.
- CVE-1999-0564Jan 1, 1999risk 0.00cvss —epss 0.02
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.
- CVE-1999-0565Jan 1, 1999risk 0.00cvss —epss 0.02
A Sendmail alias allows input to be piped to a program.
- CVE-1999-0568Jan 1, 1999risk 0.00cvss —epss 0.02
rpc.admind in Solaris is not running in a secure mode.
- CVE-1999-0569Jan 1, 1999risk 0.00cvss —epss 0.02
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.
- CVE-1999-0570Jan 1, 1999risk 0.00cvss —epss 0.06
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.
- CVE-1999-0571Jan 1, 1999risk 0.00cvss —epss 0.02
A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.
- CVE-1999-0577Jan 1, 1999risk 0.00cvss —epss 0.06
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.
- CVE-1999-0578Jan 1, 1999risk 0.00cvss —epss 0.02
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.
- CVE-1999-0579Jan 1, 1999risk 0.00cvss —epss 0.06
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.
- CVE-1999-0580Jan 1, 1999risk 0.00cvss —epss 0.02
The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.
- CVE-1999-0581Jan 1, 1999risk 0.01cvss —epss 0.07
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.
- CVE-1999-0583Jan 1, 1999risk 0.00cvss —epss 0.02
There is a one-way or two-way trust relationship between Windows NT domains.
- CVE-1999-0584Jan 1, 1999risk 0.00cvss —epss 0.02
A Windows NT file system is not NTFS.
- CVE-1999-0586Jan 1, 1999risk 0.00cvss —epss 0.01
A network service is running on a nonstandard port.
- CVE-1999-0587Jan 1, 1999risk 0.00cvss —epss 0.02
A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.
- CVE-1999-0588Jan 1, 1999risk 0.00cvss —epss 0.02
A filter in a router or firewall allows unusual fragmented packets.