| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-1999-0591 | — | 0.00 | — | 0.02 | Jan 1, 1999 | An event log in Windows NT has inappropriate access permissions. | ||
| CVE-1999-0592 | 0.00 | — | 0.02 | Jan 1, 1999 | The Logon box of a Windows NT system displays the name of the last user who logged in. | |||
| CVE-1999-0593 | 0.00 | — | 0.02 | Jan 1, 1999 | The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. | |||
| CVE-1999-0594 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive. | ||
| CVE-1999-0596 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A Windows NT log file has an inappropriate maximum size or retention period. | ||
| CVE-1999-0597 | — | 0.00 | — | 0.03 | Jan 1, 1999 | A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire. | ||
| CVE-1999-0598 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection. | ||
| CVE-1999-0599 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers. | ||
| CVE-1999-0600 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A network intrusion detection system (IDS) does not verify the checksum on a packet. | ||
| CVE-1999-0601 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets. | ||
| CVE-1999-0602 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A network intrusion detection system (IDS) does not properly reassemble fragmented packets. | ||
| CVE-1999-0603 | — | 0.00 | — | 0.02 | Jan 1, 1999 | In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc. | ||
| CVE-1999-0611 | 0.00 | — | 0.02 | Jan 1, 1999 | A system-critical Windows NT registry key has an inappropriate value. | |||
| CVE-1999-0613 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The rpc.sprayd service is running. | ||
| CVE-1999-0618 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The rexec service is running. | ||
| CVE-1999-0624 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The rstat/rstatd service is running. | ||
| CVE-1999-0625 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The rpc.rquotad service is running. | ||
| CVE-1999-0629 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The ident/identd service is running. | ||
| CVE-1999-0630 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The NT Alerter and Messenger services are running. | ||
| CVE-1999-0632 | — | Hig | 0.48 | 7.3 | 0.01 | Jan 1, 1999 | The RPC portmapper service is running. | |
| CVE-1999-0635 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The echo service is running. | ||
| CVE-1999-0636 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The discard service is running. | ||
| CVE-1999-0637 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The systat service is running. | ||
| CVE-1999-0638 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The daytime service is running. | ||
| CVE-1999-0639 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The chargen service is running. | ||
| CVE-1999-0640 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The Gopher service is running. | ||
| CVE-1999-0641 | — | 0.00 | — | 0.01 | Jan 1, 1999 | The UUCP service is running. | ||
| CVE-1999-0650 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The netstat service is running, which provides sensitive information to remote attackers. | ||
| CVE-1999-0651 | — | 0.04 | — | 0.12 | Jan 1, 1999 | The rsh/rlogin service is running. | ||
| CVE-1999-0653 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A component service related to NIS+ is running. | ||
| CVE-1999-0654 | — | 0.00 | — | 0.02 | Jan 1, 1999 | The OS/2 or POSIX subsystem in NT is enabled. | ||
| CVE-1999-0656 | 0.00 | — | 0.02 | Jan 1, 1999 | The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names. | |||
| CVE-1999-0657 | — | 0.00 | — | 0.01 | Jan 1, 1999 | WinGate is being used. | ||
| CVE-1999-0661 | 0.07 | — | 0.54 | Jan 1, 1999 | A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail… | |||
| CVE-1999-0662 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete. | ||
| CVE-1999-0663 | — | 0.00 | — | 0.02 | Jan 1, 1999 | A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified. | ||
| CVE-1999-0664 | — | 0.00 | — | 0.02 | Jan 1, 1999 | An application-critical Windows NT registry key has inappropriate permissions. | ||
| CVE-1999-0665 | 0.00 | — | 0.02 | Jan 1, 1999 | An application-critical Windows NT registry key has an inappropriate value. | |||
| CVE-1999-0698 | — | 0.00 | — | 0.02 | Jan 1, 1999 | Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux. | ||
| CVE-1999-1430 | 0.00 | — | 0.00 | Jan 1, 1999 | PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access. | |||
| CVE-1999-1440 | 0.00 | — | 0.01 | Jan 1, 1999 | Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user… | |||
| CVE-1999-1568 | Hig | 0.49 | 7.5 | 0.02 | Jan 1, 1999 | Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command. | ||
| CVE-1999-1159 | 0.00 | — | 0.00 | Dec 29, 1998 | SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root. | |||
| CVE-1999-1188 | 0.00 | — | 0.01 | Dec 27, 1998 | mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database. | |||
| CVE-1999-1285 | 0.00 | — | 0.00 | Dec 27, 1998 | Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed. | |||
| CVE-1999-0968 | 0.03 | — | 0.03 | Dec 26, 1998 | Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges. | |||
| CVE-1999-1281 | 0.00 | — | 0.01 | Dec 26, 1998 | Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program. | |||
| CVE-1999-1278 | 0.00 | — | 0.02 | Dec 25, 1998 | nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl. | |||
| CVE-1999-1277 | 0.00 | — | 0.00 | Dec 24, 1998 | BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password. | |||
| CVE-1999-1173 | 0.00 | — | 0.02 | Dec 18, 1998 | Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack. |
- CVE-1999-0591Jan 1, 1999risk 0.00cvss —epss 0.02
An event log in Windows NT has inappropriate access permissions.
- CVE-1999-0592Jan 1, 1999risk 0.00cvss —epss 0.02
The Logon box of a Windows NT system displays the name of the last user who logged in.
- CVE-1999-0593Jan 1, 1999risk 0.00cvss —epss 0.02
The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in.
- CVE-1999-0594Jan 1, 1999risk 0.00cvss —epss 0.02
A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.
- CVE-1999-0596Jan 1, 1999risk 0.00cvss —epss 0.02
A Windows NT log file has an inappropriate maximum size or retention period.
- CVE-1999-0597Jan 1, 1999risk 0.00cvss —epss 0.03
A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.
- CVE-1999-0598Jan 1, 1999risk 0.00cvss —epss 0.02
A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.
- CVE-1999-0599Jan 1, 1999risk 0.00cvss —epss 0.02
A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.
- CVE-1999-0600Jan 1, 1999risk 0.00cvss —epss 0.02
A network intrusion detection system (IDS) does not verify the checksum on a packet.
- CVE-1999-0601Jan 1, 1999risk 0.00cvss —epss 0.02
A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.
- CVE-1999-0602Jan 1, 1999risk 0.00cvss —epss 0.02
A network intrusion detection system (IDS) does not properly reassemble fragmented packets.
- CVE-1999-0603Jan 1, 1999risk 0.00cvss —epss 0.02
In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.
- CVE-1999-0611Jan 1, 1999risk 0.00cvss —epss 0.02
A system-critical Windows NT registry key has an inappropriate value.
- CVE-1999-0613Jan 1, 1999risk 0.00cvss —epss 0.01
The rpc.sprayd service is running.
- CVE-1999-0618Jan 1, 1999risk 0.00cvss —epss 0.02
The rexec service is running.
- CVE-1999-0624Jan 1, 1999risk 0.00cvss —epss 0.01
The rstat/rstatd service is running.
- CVE-1999-0625Jan 1, 1999risk 0.00cvss —epss 0.01
The rpc.rquotad service is running.
- CVE-1999-0629Jan 1, 1999risk 0.00cvss —epss 0.01
The ident/identd service is running.
- CVE-1999-0630Jan 1, 1999risk 0.00cvss —epss 0.02
The NT Alerter and Messenger services are running.
- risk 0.48cvss 7.3epss 0.01
The RPC portmapper service is running.
- CVE-1999-0635Jan 1, 1999risk 0.00cvss —epss 0.01
The echo service is running.
- CVE-1999-0636Jan 1, 1999risk 0.00cvss —epss 0.02
The discard service is running.
- CVE-1999-0637Jan 1, 1999risk 0.00cvss —epss 0.01
The systat service is running.
- CVE-1999-0638Jan 1, 1999risk 0.00cvss —epss 0.01
The daytime service is running.
- CVE-1999-0639Jan 1, 1999risk 0.00cvss —epss 0.01
The chargen service is running.
- CVE-1999-0640Jan 1, 1999risk 0.00cvss —epss 0.02
The Gopher service is running.
- CVE-1999-0641Jan 1, 1999risk 0.00cvss —epss 0.01
The UUCP service is running.
- CVE-1999-0650Jan 1, 1999risk 0.00cvss —epss 0.02
The netstat service is running, which provides sensitive information to remote attackers.
- CVE-1999-0651Jan 1, 1999risk 0.04cvss —epss 0.12
The rsh/rlogin service is running.
- CVE-1999-0653Jan 1, 1999risk 0.00cvss —epss 0.02
A component service related to NIS+ is running.
- CVE-1999-0654Jan 1, 1999risk 0.00cvss —epss 0.02
The OS/2 or POSIX subsystem in NT is enabled.
- CVE-1999-0656Jan 1, 1999risk 0.00cvss —epss 0.02
The ugidd RPC interface, by design, allows remote attackers to enumerate valid usernames by specifying arbitrary UIDs that ugidd maps to local user and group names.
- CVE-1999-0657Jan 1, 1999risk 0.00cvss —epss 0.01
WinGate is being used.
- CVE-1999-0661Jan 1, 1999risk 0.07cvss —epss 0.54
A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail…
- CVE-1999-0662Jan 1, 1999risk 0.00cvss —epss 0.02
A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete.
- CVE-1999-0663Jan 1, 1999risk 0.00cvss —epss 0.02
A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.
- CVE-1999-0664Jan 1, 1999risk 0.00cvss —epss 0.02
An application-critical Windows NT registry key has inappropriate permissions.
- CVE-1999-0665Jan 1, 1999risk 0.00cvss —epss 0.02
An application-critical Windows NT registry key has an inappropriate value.
- CVE-1999-0698Jan 1, 1999risk 0.00cvss —epss 0.02
Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.
- CVE-1999-1430Jan 1, 1999risk 0.00cvss —epss 0.00
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.
- CVE-1999-1440Jan 1, 1999risk 0.00cvss —epss 0.01
Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user…
- risk 0.49cvss 7.5epss 0.02
Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.
- CVE-1999-1159Dec 29, 1998risk 0.00cvss —epss 0.00
SSH 2.0.11 and earlier allows local users to request remote forwarding from privileged ports without being root.
- CVE-1999-1188Dec 27, 1998risk 0.00cvss —epss 0.01
mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.
- CVE-1999-1285Dec 27, 1998risk 0.00cvss —epss 0.00
Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.
- CVE-1999-0968Dec 26, 1998risk 0.03cvss —epss 0.03
Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
- CVE-1999-1281Dec 26, 1998risk 0.00cvss —epss 0.01
Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.
- CVE-1999-1278Dec 25, 1998risk 0.00cvss —epss 0.02
nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.
- CVE-1999-1277Dec 24, 1998risk 0.00cvss —epss 0.00
BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.
- CVE-1999-1173Dec 18, 1998risk 0.00cvss —epss 0.02
Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.